Security Scan Report: metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app

Redirected to:
https://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/embedded...
Site favicon
Submitted: Aug 13, 2026, 2:45:24 PMCompleted: Aug 13, 2026, 2:47:57 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 1 country across 4 domains to perform 2 HTTP transactions. The main domain is metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app and was registered NaN years ago.

Submitted URL: http://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/embedded-wallets/sdk

Effective URL: https://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/embedded-wallets/sdk/Redirected

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

The site hosts high‑severity malicious JavaScript (WebSocket C2) and is flagged by Safe Browsing; treat as a high‑risk malware distribution page.

Risk Factors
Malicious JavaScript with command‑and‑control capabilities
Safe Browsing social‑engineering warning
Phishing indicator from OpenPhish (even if unverified)
Very high JS obfuscation score
Hosted on a Vercel sub‑domain with unknown creation date
Domain age information unavailable

Details

Page Title

MetaMask Embedded Wallets | MetaMask developer documentation

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(93%)

Domain Information

The domain 'metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'metamask-docs-l8lvh00ol-consensys-ddffed67'. The core label 'vercel' covers 6 characters containing 2 vowels alongside 4 consonants. Splitting it apart reveals two words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://metamask-docs-l8lvh00ol-consensys-ddffed67.vercel.app/embedded-wallets/sdk

Page Load Overview

10.87s
Total Load Time
21
HTTP Requests
4
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:2,910 chars
Detector Agreement:40%

Website Classification

Primary Category

technology software93% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
93%
documentation technical
82%
cryptocurrency blockchain
47%
corporate
35%
cryptocurrency
30%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
664.239.109.193United States
AS16509Amazon.com, Inc.
518.245.31.100Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
5104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
564.29.17.195United States
AS16509Amazon.com, Inc.
214--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T138E32972E2D0313EA80B439DDB90AB24727BD4EBDA8E23D1B35C465057C36D9686787C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:Eyhv9iNntPosgumqm489R+ri9lOogTsP/Hj99smiSSa9EGrqOuz7tuc:EdNntPosgumqmITsPPj99sic

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:148085:IOSHSAJLxAQggPxigHYGSBRTwoQhUFERSRUESAIwAWjCAFJEQEDYg7BQwHKMIURRuA0Bu1wAYEBIrxAEnBgITAQ4YiDkDBEo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:3e0f8f7e0e4f7f80
Perceptual Hash:9097628057c77add
Difference Hash:ecba38a6b6b6a629
Wavelet Hash:0e0e3f7f0e077b80
Color Hash:#9740bf

Other Hashes

Crop Resistant:ecba38a6b6b6a629

Scan History

Scan history not available

Unable to load historical scan data