Security Scan Report: santander-remaster-whats-fb-kappa.vercel.app

Submitted: Sep 30, 2026, 1:46:06 PMCompleted: Sep 30, 2026, 1:47:36 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 78%

7
Risk Score

Non-official vercel.app page impersonating Santander with a personal-loan lure ('$250,000', 'aprobación en minutos') and WhatsApp funnel naming. No forms, but clear brand impersonation of a bank.

Risk Factors (4)
Impersonation of a different entity's brand (Santander) on a domain that is not Santander's official domain
Unranked domain with an unverifiable hosting-platform subdomain age
Loan/credit lure funnel with WhatsApp-style contact naming
Medium Suricata alerts for actor-abused cloud hosting service (vercel.app)
Domain age information unavailable

Details

Page Title

Préstamo Personal Santander

Scan Type

public

Domain Name Analysis

The domain name 'santander-remaster-whats-fb-kappa.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'santander-remaster-whats-fb-kappa'. Its registrable label 'vercel' stretches across 6 characters split between two vowels and 4 consonants. Tokenizing the label suggests two words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://santander-remaster-whats-fb-kappa.vercel.app/

Page Load Overview

1.25s
Total Load Time
764 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:es-MX
Text Length:652 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking41% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

finance banking
41%
real estate property
34%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.110.157Google · CDNUnited States
AS15169Google LLC
179.127.211.129Datacamp · CDNFrankfurt am Main, Hesse, Germany
AS60068Datacamp Limited
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1192.178.183.97Google · CDNUnited States
AS15169Google LLC
1216.239.34.36Google · CDNUnited States
AS15169Google LLC
1142.251.127.157Google · CDNUnited States
AS15169Google LLC
1142.251.14.94Google · CDNUnited States
AS15169Google LLC
1142.251.110.154Google · CDNUnited States
AS15169Google LLC
1142.251.13.132Google · CDNUnited States
AS15169Google LLC
2421--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E282B76B69A30012B413D4E46FB2975A67A4D403E50AC9783FDC2358CFC6DD69C937AC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:h5lzk98LHG3ZFotzcMMIi6HVmbs9OD9f5:h5xk98LHG3ZFotzcMMIi6HO5

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:18767:EgUFAkEQxAASMTp+DVCkEQAZiNQgUUkYWBUApCmLDAoI7giAdDLAQAiCAQ/NILRgvIoDYQAZKCIPCgbiIBQBImBw/BgAGGIg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:c3c3e7c7c7ffffff
Perceptual Hash:f76683c69bc98988
Difference Hash:8e8e0e0e0e0c0c1c
Wavelet Hash:c2c2c2c2c2e6e7e7
Color Hash:#732d86

Scan History

Scan history not available

Unable to load historical scan data