Security Scan Report: aumento-teal.vercel.app

Submitted: Sep 14, 2026, 4:50:12 PMCompleted: Sep 14, 2026, 4:50:31 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 92%

9
Risk Score

Fake Nubank credit-limit page on a vercel.app subdomain that harvests CPF and phone numbers and POSTs them to the unrelated domain sempreatualizandoasor.online. Brand impersonation plus personal-data exfiltration — do not enter any data.

Risk Factors
Impersonation of Nubank branding on a non-Nubank, unranked vercel.app subdomain
Collection of CPF and phone number under the false pretext of a credit-limit increase
Cross-origin POST of submitted data to the unrelated domain sempreatualizandoasor.online/save.php
Inline scripts use encoding/decoding functions consistent with obfuscated data handling
Free/instant shared-hosting tenancy with unverifiable creation date
Domain age information unavailable

Details

Page Title

Formulário de CPF e Telefone

Scan Type

public

Domain Name Analysis

Domain 'aumento-teal.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'aumento-teal'. The core label 'vercel' covers 6 characters holding two vowels versus four consonants. Breaking it apart gives 2 words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://aumento-teal.vercel.app/

Page Load Overview

0.70s
Total Load Time
432 KB
Total Size

Language Analysis

Primary Language

🇵🇹Portuguese
Code: pt
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:pt-br
Text Length:362 chars
Detector Agreement:100%

Website Classification

Primary Category

finance banking87% confidence
Type: static
Method: ml+structural

All Detected Categories

finance banking
87%
adult content
62%
government public service
48%
real estate property
36%
healthcare medical
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
264.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
43--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15932825A35F30045A94378BC2BEB91403639E403E84DCE687E5C5365AF9A9C095F7BEC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:o6S9Gbr4S1wqv8ExQ8FBOSYQ93ygJOu+keOpEUnhK8hYequISSz0wNvioMj:u8FAu+keEE+hLhX/dwN6z

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11151:IQCoyBtl4WqgBCIAhWoTIDCmAUCGoIRiC4icCjgF2aTSCBT0ggQIDKAicPUCM4EFB04LiyIMUEMCQBEnSMLXRBlEBgrXJkAi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefee6e6eee6feff
Perceptual Hash:f7dc8c3389662299
Difference Hash:00000c0c1c0c0c00
Wavelet Hash:00fee2e22626243c
Color Hash:#405bbf

Other Hashes

Crop Resistant:00000c0c1c0c0c00

Scan History

Scan history not available

Unable to load historical scan data