Security Scan Report: venus-testnet.vercel.app

Site favicon
Submitted: Sep 27, 2026, 9:53:43 PMCompleted: Sep 27, 2026, 9:54:22 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 72%

7
Risk Score

Venus Protocol testnet frontend on a Vercel subdomain with no forms, but network IDS fires 16 critical 'ET MALWARE EtherHiding Exfil' alerts and a loaded BNB resource is flagged as vidar malware; treat as unsafe.

Risk Factors (5)
Critical network IDS malware alerts indicating EtherHiding exfiltration over blockchain infrastructure
Unofficial Vercel subdomain presenting the Venus Protocol brand and DeFi money-market interface
WebSocket traffic to unranked look-alike Binance stream domains
Threat-intel malware (vidar) attribution on an external resource loaded by the page
No verified reputation for the venus-testnet.vercel.app tenant
Domain age information unavailable

Details

Page Title

Venus Protocol

Scan Type

public

Domain Name Analysis

The domain name 'venus-testnet.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'venus-testnet'. Count 6 characters in 'vercel' split between two vowels and 4 consonants. Word splitting yields two words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://venus-testnet.vercel.app/

Page Load Overview

4.37s
Total Load Time
4.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:2,857 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency blockchain56% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
56%
finance banking
54%
adult content
31%
technology software
29%
government public service
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
18216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
876.76.21.21Aws · CLOUDWalnut, California, United States
AS16509Amazon.com, Inc.
852.222.136.58Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
83.33.254.105Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
8188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8172.66.157.155Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
8104.18.19.237Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
864.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
852.222.136.100Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
815.197.206.134Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
11413--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C4642AFC629061E9E003CBEAE6217975F15721FEEF53C948D3ED2A51EB8284D8CD4891

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:zTWj1v6gNV1z1mit1f1N/TVn4TmV0U0Eh6mBcP0INxP4eFg7i3l101H9PvB9WAPU:HO1kmId9T6okjy

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:329188:qgCa2BJQVJjMJRIocSqQCNVhZwRSVpJXIBAxAIHqWSMnABCsDgAYQKgSgBAhgIZIRgjA04SyCVQBpKEmwogwWE8kUDLAJBOq

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff6c6c40404000ff
Perceptual Hash:c193afacac2ca993
Difference Hash:23c8c89c8cc841c0
Wavelet Hash:ff606e60444099ff
Color Hash:#1f6993

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data