Security Scan Report: nubanksaldo2.vercel.app

Submitted: Oct 1, 2026, 5:50:02 PMCompleted: Oct 1, 2026, 5:50:40 PMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 95%

3
Risk Score

Fake Nubank page on a vercel.app subdomain impersonating the bank, luring users with a bogus R$3.842,50 'NuCoins' balance and harvesting credit-card data via a R$5,90 'authentication fee'.

Risk Factors (5)
Impersonation of Nubank (a different entity's brand) on a domain that is not Nubank's official domain
Collection of credit-card information under the pretext of a small authentication fee
Fake account balance / reward redemption used as bait
Free hosting-platform subdomain (vercel.app) with unknown, potentially brand-new creation date
IDS alerts flagging the abused cloud-hosting service used by the page
Safety Factors (3)
No password field detected in the parsed DOM
No YARA malware patterns or threat-intelligence Indicators of Compromise against the page or its resources
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 10 to 3
Domain age information unavailable

Details

Page Title

Nubank | Resgate de Pontos

Scan Type

public

Domain Name Analysis

Domain 'nubanksaldo2.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'nubanksaldo2'. Count 6 characters in 'vercel' split between 2 vowels and four consonants. Segmentation suggests two words: ver, cel. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nubanksaldo2.vercel.app/

Page Load Overview

0.21s
Total Load Time
7 KB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pt-br
Text Length:706 chars
Detector Agreement:67%

Website Classification

Primary Category

cryptocurrency blockchain97% confidence
Type: static
Method: ml+structural

All Detected Categories

cryptocurrency blockchain
97%
finance banking
86%
adult content
78%
phishing scam
54%
government public service
52%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.110.113Google · CDNUnited States
AS15169Google LLC
1142.251.110.100Google · CDNUnited States
AS15169Google LLC
33--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T18B22B74B62F30456AD53A1B83BFA5B463A55C103894ECDA43ECCA284CF85ED099A378C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:Y8E7O0MtPHGiqAqZB7IamhM9jkaEDZ6MOKPUoOwsJrfDyyYfVZqhIKhZEKyt/rtj:i9p7kOaKUXB5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10586:BmIMUCDoE1EYFKGKACBESkGBQSboB5IA6IaEhAYAoAB7iAJUUByJHIciQEYiECRSGOBAOACEAV3EOyAAyheheChCFgCADBSS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:efefffe7e7e7ffff
Perceptual Hash:f3d98966268ccc66
Difference Hash:884c084c4c4c100c
Wavelet Hash:46c6262626262626
Color Hash:#d2692d

Scan History

Scan history not available

Unable to load historical scan data