Security Scan Report: poamkiqw.vercel.app

Submitted: Sep 22, 2026, 12:45:15 PMCompleted: Sep 22, 2026, 12:45:37 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 82%

5
Risk Score

Fake Deutsche Telekom login page on an unrelated vercel.app subdomain, collecting usernames with a staged 'wrong password' prompt. Brand impersonation phishing — do not enter credentials.

Risk Factors (4)
Brand impersonation of Deutsche Telekom on an unrelated domain
Credential-collecting login form on a hosting-platform subdomain
Fake authentication error message used to elicit a second credential entry
Unranked, no-reputation domain mismatched with the claimed brand
Safety Factors (5)
No password field detected in the parsed DOM
No Indicators of Compromise, YARA malware matches, or Safe Browsing hits
No cross-origin credential exfiltration detected
IDS alerts are only generic abused-cloud-hosting observations, not phishing/malware signatures
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 5
Domain age information unavailable

Details

Page Title

Telekom Login

Scan Type

public

Domain Name Analysis

Domain 'poamkiqw.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'poamkiqw'. Count 6 characters in 'vercel' holding two vowels versus 4 consonants. Splitting it apart reveals two words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://poamkiqw.vercel.app/makemehapyya.html

Page Load Overview

0.75s
Total Load Time
33 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:231 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
195.217.57.251Helsinki, Uusimaa, Finland
AS24940Hetzner Online GmbH
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
44--

Detected Technologies5

JQueryv3.6.0
100%
40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B7E1CB9B6A6305067D13E9B42FA25B972274E007914ACC793FCC635CCF863D859A279C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:Z2CdK2KGLzl+bNBT2YKPWQrGorVvReoRut58rkyqJfVK:RzsU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:7228:hCBicCwJgSpyQAhEnJcgCCtyiQEtAlgAACgoYDguJQAoVjSwMAAAIACAYgIGIYECqksxGQImBQQhxGFQngKFYIAQiDAvWwAX

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00001c3c3c3c0000
Perceptual Hash:891936269b99dd66
Difference Hash:f9def2f2f2b2cc31
Wavelet Hash:01011f3f3f3f070f
Color Hash:#40931f

Scan History

Scan history not available

Unable to load historical scan data