Security Scan Report: 8qot0mzb8mhrkq2iwbs.vercel.app

Redirected to:
https://poyl82f-h20f.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Submitted: Sep 21, 2026, 12:45:19 PMCompleted: Sep 21, 2026, 12:46:00 PMpubliccompleted

This website contacted 6 IPs in 1 country across 5 domains to perform 21 HTTP transactions. The main domain is poyl82f-h20f.vercel.app and was registered 10 years ago.

Submitted URL: https://8qot0mzb8mhrkq2iwbs.vercel.app/sdfn45wstnrefyje5hrtbw

Effective URL:

https://poyl82f-h20f.vercel.app/10003462346989/qsMJa1dvgLlRjLqIBW.html
Redirected

AI Security Verdict

High Risk

Confidence: 75%

7
Risk Score

Hidden password field and credential-style forms on an unknown-age Vercel subdomain, plus an ET PHISHING IDS alert; suspicious phishing infrastructure despite no brand Indicators of Compromise.

Risk Factors (5)
Hidden password field not visible to users
Credential-capture form fields on a free hosting subdomain of unknown age
ET PHISHING network IDS alert
Randomized subdomain and path consistent with phishing kit hosting
Scanner/client content mismatch suggests possible cloaking
Domain age information unavailable

Details

Page Title

Home

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), '8qot0mzb8mhrkq2iwbs.vercel.app' is registered; it also runs on subdomain '8qot0mzb8mhrkq2iwbs'. The core label 'vercel' covers 6 characters with 2 vowels and four consonants. Breaking it apart gives 2 words: ver, cel. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://8qot0mzb8mhrkq2iwbs.vercel.app/sdfn45wstnrefyje5hrtbw

Page Load Overview

0.40s
Total Load Time
548 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:45%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:vi
Text Length:4,015 chars
Detector Agreement:75%
Language mismatch: Declared as vi but detected as en

Website Classification

Primary Category

social media network50% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

social media network
50%
technology software
30%
documentation technical
26%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
364.29.17.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3216.198.79.195Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
3151.101.1.229Fastly · CDNUnited States
AS54113Fastly, Inc.
3172.67.69.226Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
3104.21.31.228Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
216--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115A1377329E221005DEC96F568DC3B0C735EC45F0982DD67D28E283CB72FADAB499554

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:TBI+awslWFmpr/1p6F09k/N9oWUuxRk1BtG8jQ7NBp+44:TBxslWFyRk3dU2R+BtYTc44

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4866:4KwBABgEApJBtgKEkCGAgEBCQIIARoECEAGAAgFSCQEQIIoSAqFAAgsWCAACDCSIlEAQgJokFAAJAwAACAAlo2SFjAFDAoGA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffefffa7a7ffefff
Perceptual Hash:b332ccc93336ccc9
Difference Hash:0008000c0c000800
Wavelet Hash:30303c04043c3c3c
Color Hash:#784f3a

Other Hashes

Crop Resistant:0008000c0c000800

Scan History

Scan history not available

Unable to load historical scan data