Security Scan Report: b-b-e.vercel.app

Submitted: Sep 30, 2026, 12:50:03 PMCompleted: Sep 30, 2026, 12:50:37 PMpubliccompleted

AI Security Verdict

Low Risk

Confidence: 85%

3
Risk Score

Fake Microsoft OneDrive page on a vercel.app subdomain using a shared-document lure, exfiltrating data to a Telegram bot and geolocating victims — clear phishing kit.

Risk Factors (6)
Impersonation of Microsoft OneDrive brand on an unrelated vercel.app host
Credential/data exfiltration to api.telegram.org via POST
Victim geolocation lookup via ipapi.co
Honeypot anti-bot field typical of phishing kits
Unranked, instant-provisioning free hosting subdomain (apex age not attributable to this page)
German-language shared-file social-engineering lure
Safety Factors (4)
No password/payment form fields were captured in the DOM snapshot
No YARA/JS malware or Safe Browsing hit reported
Single-source, generic 'known attacker' IP match on a third-party resource address is reputation-only, not content evidence
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 9 to 3
Domain age information unavailable

Details

Page Title

OneDrive – Dokument verfügbar

Scan Type

public

Domain Name Analysis

Domain 'b-b-e.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'b-b-e'. Count 6 characters in 'vercel' holding two vowels versus four consonants. Segmentation suggests 2 words: ver, cel. Expect three characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://b-b-e.vercel.app/

Page Load Overview

0.32s
Total Load Time
2.0 MB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:485 chars
Detector Agreement:50%

Website Classification

Primary Category

download file sharing79% confidence
Type: static
Method: ml+structural

All Detected Categories

download file sharing
79%
documentation technical
64%
technology software
57%
cryptocurrency blockchain
37%
government public service
36%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
664.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2104.18.95.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2104.26.8.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2149.154.166.110Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
2104.18.94.41Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
187--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T130A2565B63A31425BD13E0A95FA753063225E403D80BC96D3FDC5398CFCA589ADA37AC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:BIUOYlCQKgDpmWelzZn+4/JwJbcqXi1hKd+5avHnQQeQWtcnRo1MSmmR+JqF3ZVP:BILMb1k3ZvlJRp9VWFe

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21744:TEjsJACQRGcAQsEMiFQUIYmJl0khAAUEnOmAIAwEFAAEnPyLoQASgorKocb446qGaIiUAljCkpgQ2EAACIGGAMTADZDgikJS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0058582c5c000000
Perceptual Hash:999966669b26c699
Difference Hash:28141058584c1400
Wavelet Hash:030b3f3f2c241c00
Color Hash:#836ce0

Other Hashes

Crop Resistant:28141058584c1400

Scan History

Scan history not available

Unable to load historical scan data