Security Scan Report: www.ar24-sigma.vercel.app

Redirected to:
https://ar24-sigma.vercel.app/
Submitted: Sep 22, 2026, 4:47:28 AMCompleted: Sep 22, 2026, 4:47:49 AMpubliccompleted

This website contacted 6 IPs in 2 countries across 4 domains to perform 8 HTTP transactions. The main domain is ar24-sigma.vercel.app and was registered 12 years ago.

Submitted URL: https://www.ar24-sigma.vercel.app

Effective URL:

https://ar24-sigma.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed phishing kit impersonating AR24 on a vercel.app subdomain: a fake login form harvests email and password and exfiltrates them to Telegram, with DevTools blocking and corroborated phishing threat-intel. Do not enter credentials.

Risk Factors
Credential exfiltration to external endpoint (Telegram + api64.ipify.org)
Brand impersonation of AR24 on a non-official vercel.app subdomain
Login form harvesting email address and password
DevTools and right-click disabled (phishing-kit anti-analysis)
Actual subdomain creation date unknown — hosted on a free instant-publish platform
Domain age information unavailable

Details

Page Title

Connexion - AR24

Scan Type

public

Domain Name Analysis

Domain 'www.ar24-sigma.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'www.ar24-sigma'. Its registrable label 'vercel' stretches across 6 characters holding 2 vowels versus four consonants. It segments into 2 words: ver, cel. Median word length comes out to three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.ar24-sigma.vercel.app

Page Load Overview

1.04s
Total Load Time
60 KB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr
Text Length:1,386 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical65% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
65%
government public service
62%
download file sharing
53%
corporate business
42%
blog personal website
36%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
364.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1185.183.140.161France
AS211068AR24 SAS
1104.237.62.213El Segundo, California, United States
AS18450WebNX, Inc.
1185.183.140.162France
AS211068AR24 SAS
1173.231.16.77United States
AS18450WebNX, Inc.
86--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1EEB2F91228F31D2659A7D1A63B9353C63021D003A517CA84B6DD33A48FCFE968EA37DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:1d5cNG8u2N/2NzwBikjzgJWBJ1nU1Yae1bSf3ylGIddwypNB5:9/rM/2ZYzgJWhnSYaybSf3yvwg

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24564:W4AAIoDkiASkHAIJIYIxoYCKoZxGAMupAAOkp5EVkyAxCaCcwtgZQUpxSEDcR0hIIaDsBBBIBbdCAwAQgRELSCwFEkJEI8IE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefefefefefefeff
Perceptual Hash:d555aa55aaa855aa
Difference Hash:0202020202020000
Wavelet Hash:0e0e0e0e0c0c0c0d
Color Hash:#2d866d

Other Hashes

Crop Resistant:0202020202020000

Scan History

Scan history not available

Unable to load historical scan data