Security Scan Report: wfq92.vercel.app

Redirected to:
https://login.joavinlinconindustrlias.com/p/zMe40KY96BmekU4UHRHhSp2-yl...
Submitted: Sep 24, 2026, 12:45:45 PMCompleted: Sep 24, 2026, 12:47:40 PMpubliccompleted

This website contacted 5 IPs in 2 countries across 8 domains to perform 69 HTTP transactions. The main domain is login.joavinlinconindustrlias.com and was registered 6 years ago.

Submitted URL: http://wfq92.vercel.app/

Effective URL:

https://login.joavinlinconindustrlias.com/p/zMe40KY96BmekU4UHRHhSp2-yl...
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Cloned Microsoft login $Config reverse-proxied on a non-Microsoft domain and dressed as an Adobe Acrobat Reader document download — a credential/MFA-harvesting phishing page. Do not enter any credentials.

Risk Factors (6)
Adversary-in-the-middle / cloned Microsoft login schema hosted on non-Microsoft domain
Adobe brand impersonation on unrelated domain
Credential harvesting form (password + email fields)
Unranked domain not in Cisco Umbrella top 1M
DevTools and right-click blocking (anti-analysis)
Scanner saw 'Sign in to your account' while residential client saw a different page (bot-protection/evasion pattern)
Domain age information unavailable

Details

Page Title

Files

Scan Type

public

Domain Name Analysis

The domain name 'wfq92.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'wfq92'. The core label 'vercel' covers 6 characters with two vowels and four consonants. Word splitting yields two words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://wfq92.vercel.app/

Page Load Overview

3.34s
Total Load Time
2.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:276 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software62% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
62%
documentation technical
60%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1764.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
13216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
13172.64.149.246Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1385.11.167.134Amsterdam, North Holland, Netherlands
AS197170TechTies Inc.
1320.184.175.2Azure · CLOUDSan Jose, California, United States
AS8075Microsoft Corporation
695--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C4F19434D556F6BF8523CED5E832737E54CBA2CDD5A1490CB3FC826813A2C998C66C89

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:alVvZuzDn9xaxIQxjyOXOYQOxlLU6+roSMLtRC7PxtJz:4TuP/qIwJeYrxlLUH4LS7PxtJz

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8001:GODaBQggJBJQBOwWgjytASgjIojAkIC4ADAQ2MACsJAANClAJHWhVAhwFooNJFZMSqJER1Ah2RDBtYMQUEAkIIiQzQF4Q0OQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00e3ff8181bfffff
Perceptual Hash:ff60405f4b591b62
Difference Hash:50060e2b2b710421
Wavelet Hash:00c3c7818189ffff
Color Hash:#2d866d

Scan History

Scan history not available

Unable to load historical scan data