Security Scan Report: valuxlmstevgi-git-main-valuxlmstesting.vercel.app

Submitted: Sep 28, 2026, 8:53:51 PMCompleted: Sep 28, 2026, 8:54:28 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Fake "Webmail Portal Login" on an anonymous vercel.app subdomain that captures email/password and posts them to an external PHP endpoint, with four HIGH ET PHISHING IDS alerts. Do not enter credentials.

Risk Factors (6)
Credential-capturing login form (1 password field, 1 email field) on a free hosting subdomain
ET PHISHING network IDS alerts (x4 HIGH)
Cross-origin POST of form data to external domain enhancednucleus.app (/file/st.php)
Hidden 'hido'/'redirecto' fields consistent with a phishing kit
Mimics a generic webmail portal without being any provider's official domain
Unranked in Cisco Umbrella; vercel.app subdomain creation date unknown
Domain age information unavailable

Details

Page Title

Webmail Portal Login

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'valuxlmstevgi-git-main-valuxlmstesting.vercel.app' is registered, featuring subdomain 'valuxlmstevgi-git-main-valuxlmstesting'. The second-level label 'vercel' is 6 characters long containing 2 vowels alongside 4 consonants. Word splitting yields two words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://valuxlmstevgi-git-main-valuxlmstesting.vercel.app/bgv%20copy.html

Page Load Overview

1.43s
Total Load Time
204 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:152 chars
Detector Agreement:100%

Website Classification

Primary Category

phishing scam38% confidence
Type: webapp
Method: ml+structural

All Detected Categories

phishing scam
38%
news media journalism
35%
adult content
32%
government public service
30%
finance banking
26%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
764.29.17.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2142.250.154.95Google · CDNUnited States
AS15169Google LLC
2104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2192.178.183.95Google · CDNUnited States
AS15169Google LLC
2104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2209.94.90.1United States
AS40680Protocol Labs
2216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
2142.251.20.95Google · CDNUnited States
AS15169Google LLC
2172.64.147.188Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
2142.251.110.95Google · CDNUnited States
AS15169Google LLC
2711--

Detected Technologies7

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A232D88168F55052213390B83AFBA3083AA1C40B9D4ACD6471FC79985FD9F9AB8737CD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:QIZw29UaYSFSFDF3FDFbzFl3FQAw41CU8GIMPbxOq6x7NoLGZ4Cx8Tzgd:QaN1fFSFDF3FDFnFxFzwidDSKCx8vgd

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:11766:hjgxiCBjYBIIBFCDFBNugEG0KFEBBlQLDDIQkgkoBQA8YgpRVEEAJsVFIAROAvTIAARGAQjHAq0xYgEAyhElEQmkTCk6RgCj

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1838381800000000
Perceptual Hash:cccc33333366cc33
Difference Hash:32b2b2b24c300000
Wavelet Hash:383c383800000000
Color Hash:#1f2f93

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data