Security Scan Report: paymentsecurelink.vercel.app

Site favicon
Submitted: Sep 23, 2026, 12:45:37 PMCompleted: Sep 23, 2026, 12:47:11 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed Microsoft phishing page on a free Vercel subdomain: it serves Microsoft's favicon and sign-in copy, captures a password, and exfiltrates it cross-origin to pq.npljlip.net/securepay/linksecure.php. Safe Browsing flags Social Engineering.

Risk Factors (6)
Brand impersonation of Microsoft on a domain that is not Microsoft's
Password field without a corresponding username/email field — signature credential-harvesting pattern
Credentials submitted cross-origin to pq.npljlip.net/securepay/linksecure.php
Microsoft favicon reused on a non-Microsoft host (favicon brand impersonation)
Free hosting-platform subdomain (.vercel.app) with unknown creation date and no domain reputation
Two network IDS alerts for actor-abused cloud hosting service domain (vercel.app)
Domain age information unavailable

Details

Page Title

Microsoft | Login

Scan Type

public

Domain Name Analysis

Domain 'paymentsecurelink.vercel.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'paymentsecurelink'. The core label 'vercel' covers 6 characters containing two vowels alongside 4 consonants. Breaking it apart gives 2 words: ver, cel. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://paymentsecurelink.vercel.app/

Page Load Overview

3.20s
Total Load Time
434 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:329 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software63% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
63%
social media network
44%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
564.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
113.107.246.61Azure · CLOUDUnited States
AS8075Microsoft Corporation
1142.250.154.95Google · CDNUnited States
AS15169Google LLC
1151.101.1.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1142.251.20.95Google · CDNUnited States
AS15169Google LLC
2016--

Detected Technologies11

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T164F0819B16B4101E0600D385B8E4B62DDE43B90FAF54BA40B9DB44686EE4A6704634D8

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:hReae5wHjgEM2dtKzFI2NUawWEZfBrOQ1G:hRSwDhdW9kZ5x1G

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:566:AAAAAAEAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAADAAAAAAIAAQAAAAAAAAACCAAAAAAAIAIAAAAAAAACAAAAAAgAAIAAAAAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:083c7c766e7e0030
Perceptual Hash:c28959b96666e639
Difference Hash:d1d1ece4d8ccd1e0
Wavelet Hash:083c7c766f7f0834
Color Hash:#d2932d

Other Hashes

Crop Resistant:d1d1ece4d8ccd1e0

Scan History

Scan history not available

Unable to load historical scan data