Security Scan Report: lewokodwqko.icu

Site favicon
Submitted: Aug 24, 2026, 4:48:00 PMCompleted: Aug 24, 2026, 4:49:35 PMpubliccompleted

Summary

This website contacted 1 IP in 1 country across 2 domains to perform 2 HTTP transactions. The main domain is lewokodwqko.icu and was registered 21 years ago.

Submitted URL: https://lewokodwqko.icu

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

High‑risk credential phishing site impersonating MioLab with a login form on a newly registered, unranked domain flagged for malware.

Risk Factors
New domain (<90 days) with credential form
Unranked / low reputation domain
Brand impersonation of a different entity
Primary domain IoC match to malware
Absence of cross‑origin form submission (indicates local credential capture)
Domain age information unavailable

Details

Page Title

MioLab — Вход

Scan Type

public

Language

🇺🇸

English

(50% confidence)

Category

news media journalism

(48%)

Domain Information

The domain 'lewokodwqko.icu' uses the .icu top-level domain and has no subdomain. Count 11 characters in 'lewokodwqko' split between four vowels and seven consonants. Word splitting yields five words: lew, o, kod, wq, ko. The median word length lands at two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lewokodwqko.icu

Page Load Overview

0.63s
Total Load Time
7
HTTP Requests
2
Domains
1.6 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:50%
Script Type:Latin
HTML Lang Attribute:ru
Text Length:50 chars
Detector Agreement:100%
Language mismatch: Declared as ru but detected as en

Website Classification

Primary Category

news media journalism48% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

news media journalism
48%
healthcare medical
42%
technology software
39%
government public service
37%
documentation technical
33%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7104.21.7.202Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
71--

Page Statistics

7
Requests
2
Unique Domains
1.6 MB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A831530060F24C33824392C539A66A0A3CEADA13C557891076BC8B6C0F63FD7C93B55C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:hg+63RGMIm7To4NSehJsAOZVlaRQx5KNaNYuRnV/MedTENRk2NyG0/c3uMFSSUMr:7mnIGTNSehJsAIlaRQx5Aoh3Ww2ZoHi

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1750:AAACYAAAACAAAAAAiAAAAkAABAUAACSAAAEAAQAEAAgAgAAEAEQAIAAACIgCEgCBYAAAAAAAAQAABAAAAABACAAAABAAAACA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0101012c2d058387
Perceptual Hash:b3616c2d93926d6c
Difference Hash:8b871969691b3f3f
Wavelet Hash:c1c3012d3f8f878f
Color Hash:#40aebf

Scan History

Scan history not available

Unable to load historical scan data