Security Scan Report: nk2184.craftum.io

Site favicon
Submitted: Sep 22, 2026, 3:50:03 AMCompleted: Sep 22, 2026, 3:50:24 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Fake Microsoft Excel login on a craftum.io subdomain that harvests email and password credentials. Brand impersonation plus a credential form, DevTools blocking and a HIGH IDS alert make this a confirmed phishing scam.

Risk Factors
Brand impersonation of Microsoft on a non-Microsoft domain
Credential/password harvesting form
DevTools and right-click blocking (anti-analysis)
Unranked domain hosting a fake brand login
Loader/redirect behavior indicative of phishing scripts
Domain age information unavailable

Details

Page Title

Microsoft Excel 2026 // Document Access

Scan Type

public

Domain Name Analysis

Domain 'nk2184.craftum.io' uses the British Indian Ocean Territory country-code top-level domain (.io) with subdomain 'nk2184'. The core label 'craftum' covers 7 characters containing two vowels alongside 5 consonants. It segments into 2 words: craft, um. Expect 3.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://nk2184.craftum.io/

Page Load Overview

0.51s
Total Load Time
339 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:267 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software47% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
47%
documentation technical
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
292.255.111.71St Petersburg, St.-Petersburg, Russia
AS9123Jsc timeweb
1104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1195.154.239.27Paris, Île-de-France, France
AS12876Scaleway SAS
192.53.68.16St Petersburg, St.-Petersburg, Russia
AS49505JSC Selectel
54--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T10BD2D96654F300651A23D3B96BDBA6053271C003CC49CD28BBEC47585F8AFD8BAA37D9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:wqbMVdiqDPU91vPxmBl8j4jeqvaC/7ZVwaBfllSNVnPiJXxbfq:WbDPU9V2TjeqyENVRs

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:30336:ITkIUlpASQwRMGwFpZVomMgpKoYIPZPASyGQaAKIgAAERMEawwiaZnACYsINAImgEEKKwUAngk4yGmW3hooQYWDYGkojwTCB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:fefeeebb23237f63
Perceptual Hash:a7dcc8278cd86723
Difference Hash:84a82a324e4eb2ca
Wavelet Hash:fcfcaa9b03034743
Color Hash:#784f3a

Other Hashes

Crop Resistant:84a82a324e4eb2ca

Scan History

Scan history not available

Unable to load historical scan data