Security Scan Report: paypal-secure.vercel.app

Site favicon
Submitted: Sep 23, 2026, 5:51:20 AMCompleted: Sep 23, 2026, 5:52:05 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 88%

5
Risk Score

PayPal-branded sign-in funnel on paypal-secure.vercel.app, a domain PayPal does not own. Classic brand impersonation with a multi-step credential-harvest form — avoid entering any information.

Risk Factors
Impersonation of PayPal's brand on a non-PayPal domain (paypal-secure.vercel.app)
Email credential harvesting form on a brand-mismatched hosting subdomain
Multi-step ('Step 1 of 3') sign-in funnel consistent with a phishing kit
Domain unranked in Cisco Umbrella despite claiming a major financial brand
Safety Factors
No password, disguised-password, or payment fields in the captured DOM
No cross-origin credential exfiltration or obfuscated JavaScript detected
No Indicators of Compromise, YARA, or Safe Browsing hits
Some legal/terms text present
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 5
Domain age information unavailable

Details

Page Title

Sign in to PayPal

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'paypal-secure.vercel.app' is registered; it also runs on subdomain 'paypal-secure'. The core label 'vercel' covers 6 characters containing 2 vowels alongside four consonants. Segmentation suggests two words: ver, cel. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://paypal-secure.vercel.app/

Page Load Overview

8.25s
Total Load Time
233 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:142 chars
Detector Agreement:100%

Website Classification

Primary Category

e-commerce shopping44% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

e-commerce shopping
44%
technology software
42%
finance banking
36%
social media network
31%
corporate
25%

Detected Features

OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
464.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
82--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F0B1E81521009D3E1EF78AE5F6E8F23863AAE15DE467C154B1AC017B26D7FA0C423AC4

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TGKTSX4+vck+xK55DulRADWicjiciU4FhkhR883e3Itz3qdZTM2:abagG7iciciFhsRXe3w3qM2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5134:SgET4AGAQhAAESMGgAhQEAIBSAABiCAQABChgAAmyQBEAQEAAASIBwCACBABKDABQVKaQAIAKJACJsAJACkgICJGDMFRsAAE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7ff41000000
Perceptual Hash:b3b3999c9c266626
Difference Hash:2a5a4d0841111111
Wavelet Hash:ffefe7ff19000000
Color Hash:#2d866d

Other Hashes

Crop Resistant:2a5a4d0841111111

Scan History

Scan history not available

Unable to load historical scan data