Security Scan Report: novoempressapo-veriprotocol.vercel.app

Submitted: Sep 25, 2026, 3:50:20 AMCompleted: Sep 25, 2026, 3:51:45 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Fake SAPO webmail login on a Vercel subdomain, collecting email/password. Brand impersonation plus credential form; do not enter credentials.

Risk Factors (4)
Impersonates SAPO webmail on a non-official vercel.app subdomain
Credential harvesting login form with password field
Hosted on a platform where subdomains can be created instantly and anonymously
Network IDS alerts for actor-abused cloud hosting service domain (vercel.app)
Domain age information unavailable

Details

Page Title

Webmail Login

Scan Type

public

Domain Name Analysis

The domain name 'novoempressapo-veriprotocol.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'novoempressapo-veriprotocol'. The core label 'vercel' covers 6 characters containing two vowels alongside four consonants. Splitting it apart reveals two words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://novoempressapo-veriprotocol.vercel.app

Page Load Overview

6.31s
Total Load Time
122 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,453 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business38% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

corporate business
38%
technology software
36%
gambling betting
36%
phishing scam
34%
real estate property
31%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2185.15.59.240United States
AS14907Wikimedia Foundation Inc.
264.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
2104.26.13.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2190.183.195.2Bella Vista, Corrientes, Argentina
AS20207Gigared S.A.
245.43.142.7United Kingdom
AS16276OVH SAS
189--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17264FE7C5D378D9D4B599A2BC0CC33D2D26C5F53E0068993F62A748D9FE3628A1C1B29

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:RINi+dGjac1FsmmqVGqcm6xrKqoUaIXKi+Et8q59fLWPxsBt25Sp9Be7B0Bauney:gpG+pS5S4DpGT

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:333409:FUIwAFCBglABxUookiLktAPCjUkBikQDChMARTIkYkkhEPSguQGLBhLZhAQBIw4vIAhAVbABDCqCaICAgAWhAqDVASRGyGxF

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7e7c7ffffff
Perceptual Hash:b333cccc64639999
Difference Hash:080c0c0c14080000
Wavelet Hash:ffe7e7e700243030
Color Hash:#9387c5

Other Hashes

Crop Resistant:080c0c0c14080000

Scan History

Scan history not available

Unable to load historical scan data