Security Scan Report: doc-mkvelinb.vercel.app

Submitted: Sep 29, 2026, 1:51:14 PMCompleted: Sep 29, 2026, 1:52:13 PMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 82%

9
Risk Score

Anonymous Vercel subdomain hosts a JavaScript-driven email/password login that mimics a failed sign-in and captures credentials, matching a phishing threat-intel report on the same domain. Do not enter credentials.

Risk Factors (6)
Threat-intel match (phishing) on the primary domain of the scanned page
Password/email credential form on an anonymous shared-hosting subdomain
Form action is javascript:void(0) (no visible submission target — typical of phishing kits)
Deceptive 'Invalid password' error used to re-prompt victims for credentials
Hidden input fields consistent with capture-and-forward kit behavior
Not ranked in Cisco Umbrella top 1M
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'doc-mkvelinb.vercel.app' uses the application-focused generic top-level domain (.app) and includes subdomain 'doc-mkvelinb'. The core label 'vercel' covers 6 characters holding 2 vowels versus 4 consonants. Tokenizing the label suggests 2 words: ver, cel. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://doc-mkvelinb.vercel.app/

Page Load Overview

8.59s
Total Load Time
371 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:53%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:已下架
Text Length:219 chars
Detector Agreement:100%
Language mismatch: Declared as 已下架 but detected as en

Website Classification

Primary Category

adult content29% confidence
Type: webapp
Method: ml+structural

All Detected Categories

adult content
29%
news media journalism
29%
finance banking
28%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15216.198.79.3Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
0142.251.14.95Google · CDNUnited States
AS15169Google LLC
0151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
0172.217.208.95Google · CDNUnited States
AS15169Google LLC
0104.18.40.68Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0104.18.10.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0142.251.157.119Google · CDNUnited States
AS15169Google LLC
054.211.176.164Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
0172.67.139.119Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1516--

Detected Technologies10

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13A4484B0E20C20DA7336C44FBF81B6A962B5F369D5514DA6F21F2C5C4EC268611E2F39

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:LIlMIpu80PxXE4YXJgndFTfy9lQOw/71gIuiHlqqm68lDbNBmbfNyHT2Ic7c1+G0:Ji8Px04YXGdFTyHQ/Z6woHzT09Kk

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:260810:ktGKUUqBycABWAIKA5UmwIAWDg1JUaMlkgBiHFIHQ+IHGAA6AAGQnqQIqU5EIOCVKHDSogQWKgWpB7ObCIIhAqKAFIYATYBg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0018181818000000
Perceptual Hash:88cc3333337733cc
Difference Hash:4db3b3b3b34d3101
Wavelet Hash:3f1b1b1b19050f0f
Color Hash:#e06c6c

Scan History

Scan history not available

Unable to load historical scan data