Security Scan Report: zimupdate-portal.vercel.app

Submitted: Sep 13, 2026, 8:50:18 AMCompleted: Sep 13, 2026, 8:50:57 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 93%

10
Risk Score

Fake Zimbra Web Client login hosted on vercel.app that harvests email/password and exfiltrates them to submit-form.com. Brand impersonation + credential form + phishing threat-intel and IDS hit = confirmed phishing scam.

Risk Factors
Brand impersonation of Zimbra on a domain that is not Zimbra's official site
Credential-harvesting form (email + password) present
Credentials submitted cross-origin to submit-form.com, a form-relay service typical of phishing kits
Threat-intel phishing report on the primary domain
IDS HIGH alert for landing page with form exfiltration
Hosted on an instant free-subdomain platform (.vercel.app) with unknown creation age
Domain age information unavailable

Details

Page Title

Zimbra Web Client Sign In

Scan Type

public

Domain Name Analysis

Domain 'zimupdate-portal.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'zimupdate-portal'. The core label 'vercel' covers 6 characters containing two vowels alongside 4 consonants. Word splitting yields two words: ver, cel. The median word length lands at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zimupdate-portal.vercel.app/

Page Load Overview

0.32s
Total Load Time
2 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:228 chars
Detector Agreement:50%

Website Classification

Primary Category

technology software57% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
57%
corporate business
51%
government public service
40%
adult content
39%
documentation technical
38%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2216.198.79.131United States
AS16509Amazon.com, Inc.
21--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1AE51449695530C10F902B5702FD6CB1235A4C523824ECC793ECDB7ACCF9A9C946A339D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBrlNgOG6P8NFwbAnN5gvxq4M8IGCK4uX9yM3sxl1AHxw7VHf+aj9/mz:TBrlANFJ85qJvW3sxl1T/+w9/4

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2934:RAhMCEAGCQCACAAAAAgQAAAAlCGJASAAQMAAQAhAAAAADCAAQAAQgEAAoBKKAAAAAgAAAgAQSAgQGiCADAIAIAEAAABAIAAI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7e7e7e7ffff
Perceptual Hash:e6cc9933cc8c3366
Difference Hash:304c4d4d4d4d4c30
Wavelet Hash:e0e0c0c0c3c3c3c3
Color Hash:#35931f

Scan History

Scan history not available

Unable to load historical scan data