Security Scan Report: tonsquare-dapp.vercel.app

Site favicon
Submitted: Oct 4, 2026, 1:54:20 AMCompleted: Oct 4, 2026, 1:55:24 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Vercel-hosted 'TONSquare' crypto access-key dApp flagged as phishing on its own domain, with 10 CRITICAL EtherHiding malware-exfiltration IDS alerts and a wallet-connect/mint flow. Avoid connecting a wallet.

Risk Factors (5)
Content-malware typed threat-intel match (phishing) on the primary domain
Repeated CRITICAL IDS alerts for EtherHiding malware exfiltration over blockchain infrastructure
Wallet-connect (TON/EVM) plus token-mint flow on an unranked, freshly-published vercel.app tenant — classic wallet-drainer surface
Excessive cross-domain redirect chain (5 redirects)
Unranked subdomain on a free shared hosting platform with unknown true creation date
Domain age information unavailable

Details

Page Title

Key Add-on Program | TONSquare

Scan Type

public

Domain Name Analysis

The domain name 'tonsquare-dapp.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'tonsquare-dapp'. The core label 'vercel' covers 6 characters holding 2 vowels versus four consonants. Breaking it apart gives 2 words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://tonsquare-dapp.vercel.app/en/access-key

Page Load Overview

9.11s
Total Load Time
6.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:973 chars
Detector Agreement:100%

Website Classification

Primary Category

cryptocurrency45% confidence
Type: spa
Method: structural

All Detected Categories

cryptocurrency
45%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
17216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3192.178.183.97Google · CDNUnited States
AS15169Google LLC
334.160.81.0Google · CDNKansas City, Missouri, United States
AS396982Google LLC
3185.199.108.133Fastly · CDNUnited States
AS54113Fastly, Inc.
3172.66.147.126Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3216.239.32.36Google · CDNUnited States
AS15169Google LLC
3104.20.35.94Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
345.196.29.102Cloudflare · CDNSeychelles
AS13335Cloudflare, Inc.
3188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.26.2.107Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
17052--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13073E76F7502DD1A69B7CC89203A6F3AD049C977C739C82DE28CC97A12D2C7E4F69944

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:IqGTKam43vwLz08b8FGUDnfuOpZAAyLt01bMFwxf7tvJBVGLMGH+AXAprEA6Afjm:BGTKafu488FbDnfuOpZAAcCVMFwN7txU

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:76762:ogxShDFCvAJEIOICEceIEBVI0FAI6BRbISJQBDKqYQWKdgQAhKKECICsyRSojECfiajCIQQAAHURoD1DhFAViEjWBCKHASkv

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f9e7fff1f0f1f4ff
Perceptual Hash:edb39269699a8a4c
Difference Hash:49cc282327232465
Wavelet Hash:b9e6f680f0d0f0f0
Color Hash:#812d86

Other Hashes

Crop Resistant:49cc282327232465

Scan History

Scan history not available

Unable to load historical scan data