Security Scan Report: ar24-sigma.vercel.app

Redirected to:
https://ar24-sigma.vercel.app/
Submitted: Sep 26, 2026, 8:50:12 AMCompleted: Sep 26, 2026, 8:50:52 AMpubliccompleted

This website contacted 9 IPs in 3 countries across 5 domains to perform 11 HTTP transactions. The main domain is ar24-sigma.vercel.app and was registered 13 years ago.

Submitted URL: http://ar24-sigma.vercel.app/

Effective URL:

https://ar24-sigma.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Phishing page impersonating AR24 on ar24-sigma.vercel.app: login form harvests email/password, JavaScript exfiltrates them to a Telegram bot, DevTools blocked, and the primary domain is a multi-source phishing IoC. Do not enter credentials.

Risk Factors (5)
Credentials exfiltrated to external channel (Telegram) via JavaScript
Impersonation of AR24 brand on a non-official vercel.app subdomain
Login form with password field on instant, unranked shared-hosting subdomain
DevTools and right-click blocked to obstruct analysis
Multi-source phishing IoC against the primary domain
Domain age information unavailable

Details

Page Title

Connexion - AR24

Scan Type

public

Domain Name Analysis

The domain 'ar24-sigma.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'ar24-sigma'. The core label 'vercel' covers 6 characters containing 2 vowels alongside 4 consonants. It segments into 2 words: ver, cel. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://ar24-sigma.vercel.app/

Page Load Overview

4.80s
Total Load Time
61 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr
Text Length:1,386 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical65% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
65%
government public service
62%
download file sharing
53%
corporate business
42%
blog personal website
36%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1185.183.140.161France
AS211068AR24 SAS
1173.231.16.77United States
AS18450WebNX, Inc.
1149.154.166.110Amsterdam, North Holland, Netherlands
AS62041Telegram Messenger Inc
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
164.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1185.183.140.162France
AS211068AR24 SAS
1104.237.62.213El Segundo, California, United States
AS18450WebNX, Inc.
134.117.59.81Google · CDNKansas City, Missouri, United States
AS396982Google LLC
119--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15FB2F91228F31D2659A7D1A63B9353C63021D003A517CA84B6DD33A58FCFE968E637DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:1d5cNG8u2N/xNzwBikjzgJWBJ1nU1Yae1bSf3ylGIddwypNB5:9/rM/xZYzgJWhnSYaybSf3yvwg

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24593:yJZZ1bmIjaSAKJBYOBChKHQEgRIqAnBAIIiBgFqRDQioHgiaH3ghhAEAYzEBAIEMBZRBo7EAUZAtE6pSQRtAAwihsHEHAlNo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffe6e6fee6e67f3e
Perceptual Hash:f7aa54a2dc88d6a2
Difference Hash:684c0a324a4ad4e0
Wavelet Hash:ff02243c2424fe3e
Color Hash:#79d298

Other Hashes

Crop Resistant:684c0a324a4ad4e0

Scan History

Scan history not available

Unable to load historical scan data