Security Scan Report: prbb6orzjc99kcl60mq.vercel.app

Redirected to:
https://mqkq50c-h22c.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Submitted: Sep 24, 2026, 1:45:03 AMCompleted: Sep 24, 2026, 1:45:42 AMpubliccompleted

This website contacted 7 IPs in 1 country across 5 domains to perform 21 HTTP transactions. The main domain is mqkq50c-h22c.vercel.app and was registered 10 years ago.

Submitted URL: https://prbb6orzjc99kcl60mq.vercel.app/sdfbs53rbsa4erbsdb23bc

Effective URL:

https://mqkq50c-h22c.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Redirected

AI Security Verdict

High Risk

Confidence: 72%

7
Risk Score

Anonymous vercel.app subdomain using rotating randomized hostnames and obfuscated paths, hosting multiple forms including a concealed password field, and triggering an ET PHISHING mirrored-website alert — consistent with a phishing kit. Avoid entering any credentials.

Risk Factors (6)
ET PHISHING Suricata alert (mirrored-website / possible phish)
Credential form (password + multiple email/username fields) on an anonymous free-hosting subdomain
Password field hidden in HTML, not visible to the user
Randomized subdomain rotation and obfuscated URL paths indicating kit-driven infrastructure
Unranked domain (not in Cisco Umbrella top 1M) with no legitimate identity
External geolocation/IP-lookup dependency (ipapi.co)
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

The domain 'prbb6orzjc99kcl60mq.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'prbb6orzjc99kcl60mq'. Count 6 characters in 'vercel' holding two vowels versus four consonants. Breaking it apart gives 2 words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://prbb6orzjc99kcl60mq.vercel.app/sdfbs53rbsa4erbsdb23bc

Page Load Overview

1.62s
Total Load Time
548 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:12 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
364.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
364.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3151.101.65.229Fastly · CDNUnited States
AS54113Fastly, Inc.
3104.26.8.44Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3172.67.180.104Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
217--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T194A167732DF010089FE4184941CE379C7736D82A9D869DB6732B573CDB2B9E1A07A399

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBI+awslWFmpr/1p6F3Wf/wQATC+d3MJhMYLducp+44:TBxslWFyRk3U6TCe3MrFLducc44

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5013:YgABEEwABpAEOpIDgqXAhAICEgICCABmYAAAAiDQCSEgBIoEAAhkBBRESAACQiwAFIADIIAoHEUAAgaMAAEgA3QkhgQKAYAB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffcfcfffffff
Perceptual Hash:b1c6ce3931c6ce31
Difference Hash:0000001010000000
Wavelet Hash:f0f0f0c0c0f0f0f0
Color Hash:#756ce0

Other Hashes

Crop Resistant:0000001010000000

Scan History

Scan history not available

Unable to load historical scan data