Security Scan Report: sardineext.vercel.app

Submitted: Sep 26, 2026, 4:50:17 PMCompleted: Sep 26, 2026, 4:51:25 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed Facebook/Meta phishing page on a free vercel.app subdomain: it clones the Facebook login and collects entered email/password, and the domain is corroborated as phishing by two independent threat feeds. Never enter credentials.

Risk Factors (6)
Brand impersonation of Meta/Facebook on a non-Facebook domain
Credential capture form (password + email/username fields)
Multi-source corroborated phishing threat-intel match against the primary domain
Free/instant hosting-platform subdomain (vercel.app) with unknown actual creation date
Unranked domain in Cisco Umbrella top 1M
External IP-lookup callbacks (ipapi.co, ip-api.io) from the page's JavaScript
Domain age information unavailable

Details

Page Title

Facebook Login

Scan Type

public

Domain Name Analysis

You're looking at domain 'sardineext.vercel.app' on the application-focused generic top-level domain (.app), featuring subdomain 'sardineext'. Its registrable label 'vercel' stretches across 6 characters with 2 vowels and 4 consonants. Breaking it apart gives two words: ver, cel. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://sardineext.vercel.app/user/index_facebook.html

Page Load Overview

1.09s
Total Load Time
441 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:80 chars
Detector Agreement:50%

Website Classification

Primary Category

social media network99% confidence
Type: webapp
Method: ml+structural

All Detected Categories

social media network
99%
news media journalism
46%
social media
15%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1185.15.59.240United States
AS14907Wikimedia Foundation Inc.
1172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1136.243.156.168Falkenstein, Saxony, Germany
AS24940Hetzner Online GmbH
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.26.8.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
66--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16812C6AF69A305667EA3D0B9A32BA2053162F0075706DC343E9CD348CF45B79A9767CC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:YKfqjAdjs8ANSBuJRGrzoWjvdsc+LS/fRAs8+LS/xZuFJ0S8cDoKcUjdR:trzoWjvdsVOBAsVOTsVoKcin

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:9062:SeGGrhQgiMABijRMRACGCLDgAgyBCC4EoSowaTVJUAa2gRcYAWvCIAKJAAEgA1mLCAKcGMrHohLCKVRhQhyQAHRgyo4gBwBh

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:031f1f27271f1f27
Perceptual Hash:a2339ccc6733998d
Difference Hash:56abb24daab3b2ae
Wavelet Hash:031b1f07071f1f1f
Color Hash:#86bf40

Other Hashes

Crop Resistant:56abb24daab3b2ae

Scan History

Scan history not available

Unable to load historical scan data