Security Scan Report: challenge-3-react.vercel.app

Submitted: Sep 26, 2026, 9:50:22 AMCompleted: Sep 26, 2026, 9:52:07 AMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 55%

3
Risk Score

Student React project (GitHub-linked, team RM IDs) that imitates the Porto Seguro brand on a vercel.app subdomain. No forms, no credential/payment collection, no Indicators of Compromise — brand-theme mismatch only, not phishing.

Risk Factors (3)
Brand mismatch: uses the Porto Seguro name/theme on a domain unrelated to that company
Hosted on vercel.app shared-hosting subdomain with unknown creation date (could be brand new)
Domain not ranked in Cisco Umbrella
Safety Factors (5)
No credential, login, or payment forms present
No Indicators of Compromise, JavaScript YARA, or known-kit matches
Explicit academic attribution (team names, student RM IDs, public GitHub repo) — clearly a class project
No cross-origin credential exfiltration; external domains limited to Google Fonts
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 4 to 3
Domain age information unavailable

Details

Page Title

Porto Seguro

Scan Type

public

Domain Name Analysis

Domain 'challenge-3-react.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'challenge-3-react'. Its registrable label 'vercel' stretches across 6 characters holding 2 vowels versus 4 consonants. It segments into two words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://challenge-3-react.vercel.app/

Page Load Overview

2.39s
Total Load Time
689 KB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:1,047 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as pt

Website Classification

Primary Category

healthcare medical67% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

healthcare medical
67%
government public service
40%
technology software
40%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
5192.178.183.95Google · CDNUnited States
AS15169Google LLC
5142.251.13.94Google · CDNUnited States
AS15169Google LLC
564.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
204--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T100B2D0389847EC67ED9B3D81513DAD3832CE825FC5A1CE7586E4CD240AC2D7A7B62D84

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:idy4zALv8fphf7c8Jy+xStQDfFOQDfFzjEMhuc3mAUV2w/6pMDBAzAH:iBzALAphf7coxIQDfFOQDfFzjEMhuc36

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:23900:vMZUiQQcAIQAkYAiGAscnBI8QUE4wTwAtwUY6wxSAQgkNETghQO0VBBMAQYY9IiSeEkAKKgChiSJqJIOWlIIKSABRDAvMAEB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1f0000cfffffffff
Perceptual Hash:b5088ee0fce39ec8
Difference Hash:fc33739e96cccc70
Wavelet Hash:000000c3c7ffffbf
Color Hash:#78673a

Scan History

Scan history not available

Unable to load historical scan data