Security Scan Report: paneexx.vercel.app

Submitted: Oct 1, 2026, 5:50:10 PMCompleted: Oct 1, 2026, 5:51:25 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 72%

6
Risk Score

Full replica of Bolivia's Banco Mercantil Santa Cruz site hosted on a random vercel.app subdomain — bank brand impersonation, though no credential/payment form is present.

Risk Factors (3)
Full replica of Banco Mercantil Santa Cruz's website presented as the bank on a non-official domain (brand impersonation).
Free/shared hosting-tenant subdomain with unknown creation date and no domain reputation.
IDS alerts for actor-abused cloud hosting service (vercel.app).
Safety Factors (3)
No credential or payment form detected — page does not currently harvest data.
No Indicators of Compromise, YARA malware patterns, or Google Safe Browsing hits.
No obfuscated/malicious JavaScript or credential exfiltration observed.
Domain age information unavailable

Details

Page Title

BMSC | Banco Mercantil Santa Cruz S.A.

Scan Type

public

Domain Name Analysis

The domain name 'paneexx.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'paneexx'. Count 6 characters in 'vercel' with two vowels and 4 consonants. Tokenizing the label suggests 2 words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://paneexx.vercel.app

Page Load Overview

8.06s
Total Load Time
5.8 MB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:45%
Script:Latin
Direction:ltr

Detection Details

Text Length:5,343 chars
Detector Agreement:75%

Website Classification

Primary Category

finance banking61% confidence
Type: spa
Method: ml+structural

All Detected Categories

finance banking
61%
government public service
25%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1264.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
435.157.26.135Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
4157.240.0.6Facebook · CDNFrankfurt am Main, Hesse, Germany
AS32934Facebook, Inc.
4142.251.20.97Google · CDNUnited States
AS15169Google LLC
4143.0.101.47Bolivia
AS264612BANCO MERCANTIL SANTA CRUZ S.A.
4142.251.14.95Google · CDNUnited States
AS15169Google LLC
4104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
423.88.105.206Nuremberg, Bavaria, Germany
AS24940Hetzner Online GmbH
4216.239.36.181Google · CDNUnited States
AS15169Google LLC
4142.251.127.156Google · CDNUnited States
AS15169Google LLC
8419--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13CC40FE3F292108A5A73953F9050F7BCB53F568D9B92BD7266067B2583C03DF1B9210A

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:hmF5IL3hF6SAS+ozoQtqrLv2gLjKdSFaZ+:g5Ip+

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:579655:tMEzRknL8BgCM7EhAgFpeQBBQKOohgqQFlgOXBgLBgtYBRlAAQHCgAYIwKJAIAwat4XwERYFgLyDZ4rQlsExhGpgCyQCQnIi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00003c3c3c3c0000
Perceptual Hash:8a8d6ce1cbc9cbc8
Difference Hash:c337717969698f51
Wavelet Hash:e11f3f3d3d3d0101
Color Hash:#d2692d

Scan History

Scan history not available

Unable to load historical scan data