Security Scan Report: www.american-express-applications.vercel.app

Redirected to:
https://american-express-applications.vercel.app/
Submitted: Sep 20, 2026, 12:45:30 AMCompleted: Sep 20, 2026, 12:46:19 AMpubliccompleted

This website contacted 6 IPs in 3 countries across 3 domains to perform 4 HTTP transactions. The main domain is american-express-applications.vercel.app and was registered 15 years ago.

Submitted URL: https://www.american-express-applications.vercel.app/

Effective URL:

https://american-express-applications.vercel.app/
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Fake American Express login hosted on a vercel.app subdomain, presenting a brand-impersonating credential form to harvest usernames and passwords. Avoid entering any details.

Risk Factors
Impersonation of the American Express brand on a non-official domain
Credential-harvesting login form (username + password fields)
Hosted on a free shared-hosting subdomain (.vercel.app) with unknown creation date
Unranked domain (not in Cisco Umbrella top 1M) despite claiming a major financial brand
Uses official AmEx static assets (aexp-static.com) to mimic the genuine login page
Domain age information unavailable

Details

Page Title

American Express - Login

Scan Type

public

Domain Name Analysis

Domain 'www.american-express-applications.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'www.american-express-applications'. Its registrable label 'vercel' stretches across 6 characters with 2 vowels and 4 consonants. Segmentation suggests 2 words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.american-express-applications.vercel.app/

Page Load Overview

4.37s
Total Load Time
5 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:202 chars
Detector Agreement:100%

Website Classification

Primary Category

news media journalism40% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

news media journalism
40%
corporate business
35%
finance banking
27%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
4216.198.79.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
064.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
092.123.113.152Akamai · CDNMilan, Lombardy, Italy
AS16625Akamai Technologies, Inc.
064.29.17.67Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
023.52.181.182Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
46--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T141C19762AA66001772F6D1A479E3670A7064C003E142DF5D7EE86758CFEBE86D5A334C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:TCrjKLiaPmnaRfPPajVTRyZRWyIwOuNjxnIRZ8Mm6bkGqzHm:GrjKuxnuPajVdyL+uvq8Mm6/IHm

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:5999:UigwwQQAIBILCFiDwAAACIQBgEhgSAAVQRIBgDBaAXgJDdQBlAouIEIexAsAACFABCQggFAjgKUUYIAJAQgMGwiwBIEAQBgI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00ffffffe7ffffff
Perceptual Hash:b33a183a32595977
Difference Hash:3129324c4c300800
Wavelet Hash:0018100003030303
Color Hash:#ac6553

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data