Security Scan Report: opta-six.vercel.app

Submitted: Oct 1, 2026, 12:45:42 AMCompleted: Oct 1, 2026, 12:47:13 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 88%

5
Risk Score

Phishing page impersonating Deutsche Telekom on an unrelated, unranked vercel.app subdomain, collecting usernames via a fake 'Telekom Login' form with a canned wrong-password lure.

Risk Factors (5)
Impersonation of Deutsche Telekom brand on a domain that is not telekom.de
Credential/username collection form on a shared hosting subdomain of unknown age
Fake 'wrong password' error text used to re-prompt victims for credentials
Unranked, unrelated script host (supremeplastic.pk) loaded by the page
MEDIUM IDS alerts flagging vercel.app as an actor-abused cloud hosting service
Safety Factors (4)
No password field present in the parsed DOM (0 password, 0 disguised-password, 0 payment fields)
No Indicators of Compromise matches against the page or its resources
No JavaScript malware/YARA patterns and no credential exfiltration detected
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 5
Domain age information unavailable

Details

Page Title

Telekom Login

Scan Type

public

Domain Name Analysis

You're looking at domain 'opta-six.vercel.app' on the application-focused generic top-level domain (.app); it also runs on subdomain 'opta-six'. The core label 'vercel' covers 6 characters with 2 vowels and four consonants. Tokenizing the label suggests 2 words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://opta-six.vercel.app/oomhipatmanup.html/

Page Load Overview

3.52s
Total Load Time
35 KB
Total Size

Language Analysis

Primary Language

🇩🇪German
Code: de
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:de
Text Length:231 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
164.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1207.180.254.56Lauterbourg, Grand Est, France
AS51167Contabo GmbH
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
44--

Detected Technologies5

JQueryv3.6.0
100%
40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1472240AA5AB705077803D5B47FE15B871264E103C14ACC687FDC6398CF87AD49AA379C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:Z2CdK2KGLzl+bNBT2YKPWQrGorVvReoRut58rkyqJfVnIFUSUK7H:RzslGTDH

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10313:hCBmNCwJgSpyVghMBJUgyCtyiRUskPgQACoIaCgqJQgAFDSwIADAIECRYkoGBQkCqksxGQIuBQwBzGlQnkKFYIwQmAAue4gX

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00001c3c3c3c0000
Perceptual Hash:891936269b99dd66
Difference Hash:f9def2f2f2b2cc31
Wavelet Hash:01011f3f3f3f070f
Color Hash:#acd279

Scan History

Scan history not available

Unable to load historical scan data