Security Scan Report: paymentsecurelink.vercel.app

Site favicon
Submitted: Sep 24, 2026, 11:50:03 AMCompleted: Sep 24, 2026, 11:50:37 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Fake Microsoft sign-in on paymentsecurelink.vercel.app using Microsoft's branding and favicon; it harvests passwords and POSTs them to pq.npljlip.net. Flagged by Safe Browsing and OpenPhish. Do not enter credentials.

Risk Factors (6)
Microsoft brand impersonation on a domain that is not Microsoft's (unranked in Cisco Umbrella top 1M).
Microsoft favicon served from a non-Microsoft host — strong brand-impersonation signal.
Password field present with no username field on the same page — staged credential harvesting.
Cross-origin credential POST to pq.npljlip.net/securepay/linksecure.php — credential exfiltration to a third-party backend.
Google Safe Browsing: Social Engineering; OpenPhish lists the domain as phishing.
Free hosting-platform subdomain (vercel.app) with unknown actual creation date — disposable infrastructure.
Domain age information unavailable

Details

Page Title

Microsoft | Login

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'paymentsecurelink.vercel.app' is registered with subdomain 'paymentsecurelink'. Count 6 characters in 'vercel' split between 2 vowels and 4 consonants. It segments into two words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://paymentsecurelink.vercel.app/

Page Load Overview

0.89s
Total Load Time
434 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:329 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software63% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
63%
social media network
44%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.250.154.95Google · CDNUnited States
AS15169Google LLC
1172.64.147.188Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
113.107.246.44Azure · CLOUDUnited States
AS8075Microsoft Corporation
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
164.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2014--

Detected Technologies11

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T164F0819B16B4101E0600D385B8E4B62DDE43B90FAF54BA40B9DB44686EE4A6704634D8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:hReae5wHjgEM2dtKzFI2NUawWEZfBrOQ1G:hRSwDhdW9kZ5x1G

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:566:AAAAAAEAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAADAAAAAAIAAQAAAAAAAAACCAAAAAAAIAIAAAAAAAACAAAAAAgAAIAAAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:083c7c766e7e0030
Perceptual Hash:c28959b96666e639
Difference Hash:d1d1ece4d8ccd1e0
Wavelet Hash:083c7c766f7f0834
Color Hash:#78763a

Other Hashes

Crop Resistant:d1d1ece4d8ccd1e0

Scan History

Scan history not available

Unable to load historical scan data