Security Scan Report: orange-1.vercel.app

Submitted: Sep 14, 2026, 12:51:40 AMCompleted: Sep 14, 2026, 12:52:06 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed Orange-brand phishing on a free vercel.app subdomain: fake CAPTCHA + Orange login form whose JavaScript exfiltrates email and password to an external Telegram endpoint via sendToTelegram.

Risk Factors
Impersonation of the Orange brand on a non-Orange domain (orange-1.vercel.app)
Login form capturing email/phone plus password
Credential exfiltration via sendToTelegram to an external server
Disguised password field (type=text with password placeholder)
Unicode confusion/evasion characters in form fields
Fake CAPTCHA challenge gate in front of a credential form
Unknown-age subdomain on an abused cloud-hosting platform (vercel.app), unranked in Cisco Umbrella
IDS alerts for actor-abused cloud hosting service (vercel.app)
Domain age information unavailable

Details

Page Title

Vérification Orange

Scan Type

public

Domain Name Analysis

You're looking at domain 'orange-1.vercel.app' on the application-focused generic top-level domain (.app) and includes subdomain 'orange-1'. Count 6 characters in 'vercel' holding two vowels versus 4 consonants. Word splitting yields 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://orange-1.vercel.app/

Page Load Overview

4.96s
Total Load Time
1.2 MB
Total Size

Language Analysis

Primary Language

🇫🇷French
Code: fr
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:fr
Text Length:442 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam43% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

phishing scam
43%
government public service
33%
adult content
30%
technology software
28%
documentation technical
27%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
564.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3142.251.151.119Google · CDNUnited States
AS15169Google LLC
3185.15.59.224United States
AS14907Wikimedia Foundation Inc.
3142.251.110.138Google · CDNUnited States
AS15169Google LLC
3216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3142.251.110.100Google · CDNUnited States
AS15169Google LLC
3142.251.14.94Google · CDNUnited States
AS15169Google LLC
3185.15.59.240United States
AS14907Wikimedia Foundation Inc.
3142.251.157.119Google · CDNUnited States
AS15169Google LLC
3142.251.155.119Google · CDNUnited States
AS15169Google LLC
3511--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15762936321550C3A626386E479A6A74E3019DF17EE5BE08CB2FC939D87C6CD3993178C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:X2f0PDFZ0TeNb76xyeW+zzxeiQn7zZsAL0pWY5fKE:QQDFZ0TCb76zhPE+A4WY5CE

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15475:KpDQmSTLMIQCdUiQV6qllFAqGBAWrE4EwMAiAQEEUClBR4mNEEduuCJYgBQIGAwIUQcUshZKiBQAoTRIkuGAheiSoK/QWzmg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffffffffff
Perceptual Hash:b8384743794f474e
Difference Hash:9818a8b890400000
Wavelet Hash:0000c4c4c4f4fcfc
Color Hash:#d2a079

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data