Security Scan Report: lasucursal-virtual.vercel.app

Redirected to:
https://lasucursal-virtual.vercel.app/bancolombia/persona
Site favicon
Submitted: Sep 15, 2026, 4:45:01 PMCompleted: Sep 15, 2026, 4:45:24 PMpubliccompleted

This website contacted 7 IPs in 1 country across 4 domains to perform 48 HTTP transactions. The main domain is lasucursal-virtual.vercel.app and was registered 21 years ago.

Submitted URL: http://lasucursal-virtual.vercel.app/manager/4a96168719671042cf3aa58d

Effective URL:

https://lasucursal-virtual.vercel.app/bancolombia/persona
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 96%

10
Risk Score

Phishing page impersonating Bancolombia's 'Sucursal Virtual Personas' login to harvest banking credentials on a Vercel subdomain. Do not enter any credentials.

Risk Factors (4)
Brand impersonation of a major financial institution on an unrelated domain
Credential login form (username + password) collecting bank access data
Free shared hosting subdomain with unknown age and no reputation
Targeted URL path impersonating bank management structure
Domain age information unavailable

Details

Page Title

Bancolombia

Scan Type

public

Domain Name Analysis

Domain 'lasucursal-virtual.vercel.app' uses the application-focused generic top-level domain (.app), featuring subdomain 'lasucursal-virtual'. Count 6 characters in 'vercel' holding 2 vowels versus four consonants. Word splitting yields 2 words: ver, cel. Expect 3 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://lasucursal-virtual.vercel.app/manager/4a96168719671042cf3aa58d

Page Load Overview

1.93s
Total Load Time
516 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:36%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:277 chars
Detector Agreement:50%
Language mismatch: Declared as en but detected as es

Website Classification

Primary Category

finance banking36% confidence
Type: spa
Method: ml+structural+ocr_tiebreaker

All Detected Categories

finance banking
36%
government public service
32%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
12216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
6104.17.208.5Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
664.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
6216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
6142.251.14.95Google · CDNUnited States
AS15169Google LLC
6151.101.1.229Fastly · CDNUnited States
AS54113Fastly, Inc.
6172.67.74.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
487--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16DA1B582FD55CF0B116742FE9A21277CC00BCA0ACF215C49F3CC56C9479AA628EF2891

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:HH6bAqAmA7AyZu9kpnvLmyj+jzeegU4Y/+vmItnRnXrnr5pHz:HHWAqAmA7AyZu9anvLg6FXjNt

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4861:T7EWggIEwIGABAhUIAARMEYGAAAAxCAEIIAAAVGAJISAApwoQgEkKEgGCAIEAhQkkBQAGCiAgYwgDASEAIgCBQFQqAAQInCM

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e7ffe7e7dbe7a5e7
Perceptual Hash:b3b3338c2333331b
Difference Hash:0810084c10044908
Wavelet Hash:e3fbe3e3f80000e3
Color Hash:#23931f

Other Hashes

Crop Resistant:0810084c10044908

Scan History

Scan history not available

Unable to load historical scan data