Security Scan Report: banco-pichincha.vercel.app

Submitted: Sep 25, 2026, 2:50:41 AMCompleted: Sep 25, 2026, 2:52:54 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 88%

9
Risk Score

Fake Banco Pichincha online banking login hosted on a free vercel.app subdomain, harvesting email and password credentials. Classic phishing impersonating a major bank — do not enter any data.

Risk Factors (5)
Brand impersonation of a major financial institution on a non-official domain
Credential-collecting login form (email + password) on attacker-controllable free hosting
Deceptive hostname mimicking the bank's official name (banco-pichincha)
Unranked domain with unknown actual creation date behind a shared hosting apex
IDS alerts identifying the hosting platform as commonly abused by threat actors
Domain age information unavailable

Details

Page Title

Iniciar Sesión — Mi Banco

Scan Type

public

Domain Name Analysis

The domain name 'banco-pichincha.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'banco-pichincha'. Count 6 characters in 'vercel' split between 2 vowels and 4 consonants. Breaking it apart gives 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://banco-pichincha.vercel.app/

Page Load Overview

0.87s
Total Load Time
283 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es
Text Length:207 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking77% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
77%
adult content
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
4104.17.207.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
464.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
174--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AB51321050F12A7B81A2C0D9B9E96B173CD2C407DBAA541473FC0BD54FDAC47996B228

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:grLw9GH97J3f0hUatNYTHe3pPuse8y+1gIdAFx:grLw9GH9VgUatN82Hx6Fx

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2969:QEAAAAiABAAgAIAQAEAIQEAaQRAAAIECABACCCAgGECBAIAQWgAAAgACAASCIRBAgLECgBhAgYGAAAAAAAkAAAAAIQDAEIAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818181901
Perceptual Hash:8859766633d9cccc
Difference Hash:cff3b3b3b3b3b3cf
Wavelet Hash:01191b1b1f1f1f1f
Color Hash:#406ebf

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data