Security Scan Report: spotify-login.vercel.app

Site favicon
Submitted: Sep 26, 2026, 3:50:19 AMCompleted: Sep 26, 2026, 3:51:32 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

10
Risk Score

Fake Spotify sign-in on a free vercel.app subdomain harvesting email/password credentials. Brand impersonation plus a live login form and a phishing intel match make this a confirmed scam.

Risk Factors (5)
Brand impersonation of Spotify on a non-official domain
Credential form (email/username + password) collecting login data
Deceptive subdomain name crafted to look like the official Spotify sign-in
Single-source threat-intel phishing report on the primary domain
Hosted on a free platform namespace where content can be published anonymously at any time
Domain age information unavailable

Details

Page Title

Spotify-Login

Scan Type

public

Domain Name Analysis

The domain name 'spotify-login.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'spotify-login'. The second-level label 'vercel' is 6 characters long containing two vowels alongside four consonants. Word splitting yields two words: ver, cel. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://spotify-login.vercel.app/

Page Load Overview

4.78s
Total Load Time
132 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:226 chars
Detector Agreement:100%

Website Classification

Primary Category

social media network99% confidence
Type: static
Method: ml+structural

All Detected Categories

social media network
99%
entertainment media
90%
technology software
81%
e-commerce shopping
48%
news media journalism
33%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.26.3.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
164.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.26.2.143Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
44--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FF62CA693760019C4C93C5EBFF90FA58730DA0D7FA27CAA4BF8E8604A7C7D92A547548

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:2h37JXeS7JXex/27xBEfw+WbQaCsfJWGBnEa2jKTT+9EKdcy9LNT7OQ5b1MXun:23hL73T+WbQaEaGK/UEKdcyPXOc1MXun

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15316:DiSrI0AACRAAQHyhBohEEYHY1FJiWqk/jAAJS2CJAkokEBIMIOiIfAScMKAgFEVB4DMIRKA0gQ4J00+AChAzAIC4wo1RKQJC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7e7e7e7e3e7ff
Perceptual Hash:b33382669933669b
Difference Hash:4a0c0c0c1c040c00
Wavelet Hash:00e7e7e72020243c
Color Hash:#7a2dd2

Other Hashes

Crop Resistant:4a0c0c0c1c040c00

Scan History

Scan history not available

Unable to load historical scan data