Security Scan Report: phuctradanso.io.vn

Redirected to: https://phuctradanso.io.vn/fof/jjj/kop/auto/web/authen.php?web/auth/arub12

Submitted: Oct 22, 2025, 12:57:39 AMCompleted: Oct 22, 2025, 1:00:08 AMpubliccompleted
Loading additional data...

Summary

This website contacted 12 IPs in 3 countries across 4 domains to perform 20 HTTP transactions. The main domain is phuctradanso.io.vn.

Submitted URL: https://phuctradanso.io.vn/fof/jjj/kop/auto/index.php

Effective URL: https://phuctradanso.io.vn/fof/jjj/kop/auto/web/authen.php?web/auth/arub12Redirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Phishing site impersonating Aruba Webmail; confirmed scam.

Risk Factors
URL manipulation (phishing technique)
Brand impersonation on unranked domain
Login form collecting credentials
New/unknown domain age
Mismatched final URL vs displayed URL
Domain age information unavailable

Details

Page Title

Aruba Webmail

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

corporate business

(30%)

Domain Information

The domain name 'phuctradanso.io.vn' uses the Vietnamese country-code top-level domain (.io.vn) while skipping any subdomain. The registrable portion 'phuctradanso' spans 12 characters split between 4 vowels and 8 consonants. Word splitting yields five words: ph, uc, tra, dan, so. Median word length comes out to two characters. 'ph' most strongly signals Indonesian. Secondary signals appear in Malay and Chinese (Pinyin). Net impression: Indonesian phrase.

Screenshot

Security scan screenshot of https://phuctradanso.io.vn/fof/jjj/kop/auto/index.php

Page Load Overview

4.35s
Total Load Time
20
HTTP Requests
4
Domains
1.1 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:470 chars
Detector Agreement:100%

Website Classification

Primary Category

corporate business30% confidence
Type: webapp
Method: ml+structural

All Detected Categories

corporate business
30%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
15210.211.125.205Vietnam
AS38731CHT Compamy Ltd
2104.17.24.14United States
AS13335CLOUDFLARENET
2142.250.186.67United States
AS15169GOOGLE
1104.17.25.14United States
AS13335CLOUDFLARENET
1142.250.181.234United States
AS15169GOOGLE
1172.217.18.10United States
AS15169GOOGLE
1142.250.186.99United States
AS15169GOOGLE
12a00:1450:4001:82b::2003Frankfurt am Main, Hesse, Germany
AS15169GOOGLE
12a00:1450:4001:829::200aFrankfurt am Main, Hesse, Germany
AS15169GOOGLE
12606:4700::6811:180eUnited States
AS13335CLOUDFLARENET
2012--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T186022F2020F14AB7169786A13850FF597ECAF307DA078944B6FC0E961F87D86CD836B9

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:nOfCKYBgfv20i718wSd/6pTjolrmCBqfjkX2gZ6/SiPGEE3vlVYlbcO:OaKYBIeuPr0NGbVY2O

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:8524:yqDQwAmGAoBwyZ4bGBhJEHQRIIAQwkgwVCEAnIxFESNCX4JICmwAgIhKgRACSgUgwAFLZLiohBTBq8CbDBWHoZI9NwAwgCBo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffcf878783ffffff
Perceptual Hash:b938c6cf38926339
Difference Hash:051e1a1b1b13000c
Wavelet Hash:f181818181ff1f07
Color Hash:#6ce096

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data