Security Scan Report: reimagined-funicular-ivory.vercel.app

Site favicon
Submitted: Oct 2, 2026, 5:53:45 PMCompleted: Oct 2, 2026, 5:54:25 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Verified phishing page: a fake NAVER login on a vercel.app subdomain, carrying a password field that submits credentials to the attacker's own origin, backed by a 2-feed phishing threat-intel match. Never enter Naver credentials here.

Risk Factors (5)
Impersonation of the NAVER brand on a domain that is not naver.com
Credential login form (password + ID/phone) harvesting data to the attacker-controlled vercel.app origin
Multi-source phishing threat-intel match against the primary domain
Free shared-hosting subdomain with unknown creation date, unranked in Cisco Umbrella
Entire page is a pixel-for-pixel clone of Naver's login UI including its trademark footer
Domain age information unavailable

Details

Page Title

Naver Sign in

Scan Type

public

Domain Name Analysis

Domain 'reimagined-funicular-ivory.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'reimagined-funicular-ivory'. The registrable portion 'vercel' spans 6 characters with two vowels and four consonants. Tokenizing the label suggests 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://reimagined-funicular-ivory.vercel.app/

Page Load Overview

4.24s
Total Load Time
1.7 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:676 chars
Detector Agreement:100%

Website Classification

Primary Category

social media network86% confidence
Type: webapp
Method: ml+structural

All Detected Categories

social media network
86%
corporate business
50%
technology software
32%
corporate
25%

Detected Features

Login Form
OG: website

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2110.93.159.38Navercloud · CLOUDSouth Korea
AS23576NAVER Cloud Corp.
223.209.209.41Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
223.207.210.78Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2202.179.180.82Navercloud · CLOUDSouth Korea
AS23576NAVER Cloud Corp.
2151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
223.48.23.54Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
2203.104.162.225Germany
AS23576NAVER Cloud Corp.
2125.209.233.21Navercloud · CLOUDSouth Korea
AS23576NAVER Cloud Corp.
2125.209.233.29Navercloud · CLOUDSouth Korea
AS23576NAVER Cloud Corp.
2511--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A662936194F98C33414385C8BEE5AF3A6D99C123C70E5904B2FC1BE5AFE7C82A91356D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nfu3BA7cClVOenvd7V+33Lx3rGe+CySpSR8zcSaIUAxl6ZejI42SCKiqXaepqpdO:Y+BgjvYR8zcSaSlljbtigae4n3Ior6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:15801:BGgSkrREQFFlCIIGElpFgMGmgj0GoYARCQQGmQZhqwQl/ZGiooACzgIBSk0AIXWFBQ0gGGGeBALYoDVBgYCgSgIEKTA0AgKT

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7e7ffe7e7efe7e7
Perceptual Hash:b366899966639999
Difference Hash:080c000c0c080808
Wavelet Hash:2327272727272727
Color Hash:#7997d2

Other Hashes

Crop Resistant:080c000c0c080808

Scan History

Scan history not available

Unable to load historical scan data