Security Scan Report: leia-santander.vercel.app

Site favicon
Submitted: Sep 26, 2026, 12:50:43 PMCompleted: Sep 26, 2026, 12:52:41 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Free Vercel subdomain impersonating Banco Santander (LikeU credit card) with phishing threat-intel and a phone-collection form; not the official bank. Avoid interaction.

Risk Factors (4)
Impersonation of a DIFFERENT entity's brand (Bank Santander) on a non-official domain
Phishing indicator on the primary domain (single-source)
Brand-styled content hosted on an instant free subdomain (vercel.app) with unknown real creation date
Elicits personal data (mobile phone number) under a false banking pretense
Domain age information unavailable

Details

Page Title

LikeU

Scan Type

public

Domain Name Analysis

Domain 'leia-santander.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'leia-santander'. Its registrable label 'vercel' stretches across 6 characters split between two vowels and 4 consonants. Breaking it apart gives 2 words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://leia-santander.vercel.app/

Page Load Overview

6.59s
Total Load Time
793 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:5,062 chars
Detector Agreement:50%

Website Classification

Primary Category

e-commerce shopping94% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

e-commerce shopping
94%
corporate business
90%
finance banking
86%
healthcare medical
85%
education learning
84%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
964.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
43.5.244.38Aws · CLOUDCity of London, England, United Kingdom
AS16509Amazon.com, Inc.
4104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
452.95.142.118Aws · CLOUDCity of London, England, United Kingdom
AS16509Amazon.com, Inc.
43.5.245.53Aws · CLOUDCity of London, England, United Kingdom
AS16509Amazon.com, Inc.
43.5.244.12Aws · CLOUDCity of London, England, United Kingdom
AS16509Amazon.com, Inc.
452.95.149.182Aws · CLOUDCity of London, England, United Kingdom
AS16509Amazon.com, Inc.
43.5.246.105Aws · CLOUDCity of London, England, United Kingdom
AS16509Amazon.com, Inc.
43.5.244.104Aws · CLOUDCity of London, England, United Kingdom
AS16509Amazon.com, Inc.
5312--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15733D8202E8047B66AD35FDEF9D1F72FF062910EC317C8A8D6BC5246C3C9D448A69799

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:7YvHXQjlXkfFPeBwGnTkRyieD+9fqCR25As32WWCeXnSq434m4w4KoksmqQp:aslXBy8Z88oNzfBmnp

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:54723:qgMIyrvREAmC4wRiCCkKjCBA8hKo0GAdJJZ1wkQzIMSJAbRW9JgUTkCSJADAIaAAHRGgASKCmlQDEJRV4yESCKJhxABcFBhF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff0123234b0038ff
Perceptual Hash:a126de59b0c6e9a9
Difference Hash:4befebcb9bd3d1c8
Wavelet Hash:ff0123274b0838ff
Color Hash:#4088bf

Scan History

Scan history not available

Unable to load historical scan data