Security Scan Report: cancelcardiffbahora.vercel.app

Site favicon
Submitted: Sep 19, 2026, 6:50:16 PMCompleted: Sep 19, 2026, 6:50:35 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Free .vercel.app page posing as the official Bancolombia/Cardiff insurance portal, with a phishing threat-intel report and an info-collection cancellation funnel — brand impersonation, avoid.

Risk Factors
Impersonation of a different entity's financial brand (Bancolombia / Cardiff BNP Paribas Cardif) on a non-official domain
Single-source phishing threat-intelligence report against the primary domain
Free instant-publish hosting subdomain (vercel.app) with unknown subdomain age
Domain is unranked in Cisco Umbrella while claiming to be a major bank/insurer portal
Data-registration/cancellation funnel designed to collect user information
Domain age information unavailable

Details

Page Title

Seguros Cardiff | Bancolombia

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'cancelcardiffbahora.vercel.app' is registered and includes subdomain 'cancelcardiffbahora'. The second-level label 'vercel' is 6 characters long holding 2 vowels versus 4 consonants. Word splitting yields two words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cancelcardiffbahora.vercel.app/

Page Load Overview

1.27s
Total Load Time
337 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:2,203 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service87% confidence
Type: static
Method: ml+structural

All Detected Categories

government public service
87%
finance banking
86%
corporate business
73%
healthcare medical
70%
news media journalism
65%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3142.251.13.95Google · CDNUnited States
AS15169Google LLC
3216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3142.250.154.95Google · CDNUnited States
AS15169Google LLC
364.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3142.251.14.94Google · CDNUnited States
AS15169Google LLC
236--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T113D29217A1F22137A4139D55B7F26F5E6168C103E40885787A9C12C8CFFADE9DDA3A8C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:gvh+QroRB+HQ+VA2+g9mDM6F+YNdJrfBRWDyQ9lzjKFswL0ibWMlrdKPx5+DVONt:gvhzcyJStFqFXw04uNxyIItj8CgjnAfw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:29063:AgJUCqgAjwcqRIwyLArCgEWGCxwwbAwW2Cg4jIjIChJaUqMJhEgsQAQ85QCLCCQCRAZirs0BUQEQKBQIQQwPVJAY5EgEgkGL

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff002020202200ff
Perceptual Hash:8368bc15fa53c39c
Difference Hash:95d5c5cdc4d4dccc
Wavelet Hash:ff006064347e06ff
Color Hash:#ac7753

Scan History

Scan history not available

Unable to load historical scan data