Security Scan Report: mashrq.vercel.app

Submitted: Sep 28, 2026, 7:50:18 AMCompleted: Sep 28, 2026, 7:50:52 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Fake Mashreq Bank login on a vercel.app subdomain harvesting username, password and SMS verification codes. Impersonation plus credential form — a phishing page. Do not enter any details.

Risk Factors (5)
Impersonation of Mashreq Bank brand on a non-official vercel.app subdomain
Credential form collecting username, password and a phone-delivered verification code
Deceptive hostname: 'mashrq' mimics 'Mashreq' with a missing vowel
Page hosted on an actor-abused free cloud hosting platform (.vercel.app); actual subdomain age unknown and not attributable to the apex registration
Unranked domain with no reputation, used to front a claimed major bank
Domain age information unavailable

Details

Page Title

Mashreq Login

Scan Type

public

Domain Name Analysis

The domain name 'mashrq.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'mashrq'. The second-level label 'vercel' is 6 characters long holding 2 vowels versus four consonants. Tokenizing the label suggests two words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mashrq.vercel.app/

Page Load Overview

1.45s
Total Load Time
124 KB
Total Size

Language Analysis

Primary Language

🇸🇦Arabic
Code: ar
Confidence:80%
Script:Arabic
Direction:rtl

Detection Details

HTML Lang Attribute:ar
Text Length:175 chars
Detector Agreement:67%

Website Classification

Primary Category

phishing scam27% confidence
Type: static
Method: ml+structural

All Detected Categories

phishing scam
27%
adult content
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1135.181.63.70Helsinki, Uusimaa, Finland
AS24940Hetzner Online GmbH
164.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
33--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T174B2969A19F710116953E4B927EB27063239D403D54ACC683F9C97888FC6A51EEB37EC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:U8JrdZwBfUcC3/7bTmGl8a/Ogf14+tpwAa3fOCryH6F8c3mTaoKnyJlOOPjQOOye:Fp/GF8c3FoOOLQOOY23RwVi4g/eJXHG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:24221:rAAoJBLIKIgEFIwGAYgwCAcijCXKJKFAYZAswEsA2gYwhUSqAFINrPKSBFAgYG2hk37IAsARVhgBUEghgFkQgGwYDAIYaREC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefcfce4e0f0f0e0
Perceptual Hash:f7809c8077bb88ce
Difference Hash:0000000808100000
Wavelet Hash:fcfcf8e0e0f0e0c0
Color Hash:#1f937e

Other Hashes

Crop Resistant:0000000808100000

Scan History

Scan history not available

Unable to load historical scan data