Security Scan Report: ecount-update.vercel.app

Site favicon
Submitted: Sep 26, 2026, 6:51:01 AMCompleted: Sep 26, 2026, 6:52:03 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Phishing clone of Ecount WebMail on a free vercel.app subdomain, harvesting email/password via a login form. Flagged as phishing. Do not enter credentials.

Risk Factors
Impersonation of the Ecount WebMail brand on a non-official vercel.app subdomain
Credential-collecting login form on a shared hosting platform subdomain of unknown creation date
Single-source phishing threat-intelligence match on the scanned primary domain
References to legitimate Ecount backend domains used to lend false authenticity
Domain age information unavailable

Details

Page Title

Ecount WebMail - Login

Scan Type

public

Domain Name Analysis

Domain 'ecount-update.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'ecount-update'. Its registrable label 'vercel' stretches across 6 characters split between 2 vowels and four consonants. Breaking it apart gives two words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://ecount-update.vercel.app/

Page Load Overview

1.38s
Total Load Time
383 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:60%
Script:Latin
Direction:ltr

Detection Details

Text Length:888 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical62% confidence
Type: webapp
Method: ml+structural

All Detected Categories

documentation technical
62%
technology software
60%
finance banking
43%
government public service
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
118.66.102.7Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
118.66.102.98Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
118.66.102.84Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
118.66.102.103Cloudfront · CDNUnited States
AS16509Amazon.com, Inc.
1151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
143.200.46.3Aws · CLOUDIncheon, Incheon, South Korea
AS16509Amazon.com, Inc.
88--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T179A2B650A4F91573055381E939A2F6193DA2D117CB0ADE04BAEC4BEA6FC3F828D0779D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:NYD+7Nca26dSpzZIg5eZ9BV9Qq3y3bS3gOv+8qr1hW6bjcIZ/96:NI1a26dS5ZIg52VR3HyrJAZ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21528:EJAoA0gIAQhoYEEAEcDk2eVcEFwhCQ6MMBVEIk4VALFbKsDCEJIxJyACQ4gMAQgCCYSInBB6AqAgUwaQQIIEwciEQCa6y7Fa

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe6fee7e7ffff
Perceptual Hash:f755882276dd5522
Difference Hash:00214e124d0c3000
Wavelet Hash:3f3f060602020f0f
Color Hash:#2d5986

Other Hashes

Crop Resistant:00214e124d0c3000

Scan History

Scan history not available

Unable to load historical scan data