Security Scan Report: tokikonutbasvurususongun.icu

Redirected to: https://tokikonutbasvurususongun.icu/login_up.php

Site favicon
Submitted: Nov 2, 2025, 1:40:43 PMCompleted: Nov 2, 2025, 1:41:16 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 3 countries across 3 domains to perform 22 HTTP transactions. The main domain is tokikonutbasvurususongun.icu and was registered NaN years ago.

Submitted URL: https://tokikonutbasvurususongun.icu/

Effective URL: https://tokikonutbasvurususongun.icu/login_up.phpRedirected

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed phishing site harvesting credentials; do not use.

Risk Factors
Newly registered domain (<7 days) hosting credential‑harvesting form
Credential collection (username/password) on untrusted domain
Brand impersonation of Plesk on a non‑official domain
Lack of legitimate reputation (UNRANKED in Cisco Umbrella)
Domain age information unavailable

Details

Page Title

Plesk Obsidian 18.0.73

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(49%)

Domain Information

Domain 'tokikonutbasvurususongun.icu' uses the .icu top-level domain without a subdomain. Its registrable label 'tokikonutbasvurususongun' stretches across 24 characters with 10 vowels and 14 consonants. Segmentation suggests 8 words: to, kiko, nut, bas, vu, rusu, song, un. Expect three characters per word on average. 'to' most often appears in Czech. It also appears in Slovak and Polish contexts.

Screenshot

Security scan screenshot of https://tokikonutbasvurususongun.icu/

Page Load Overview

10.54s
Total Load Time
22
HTTP Requests
3
Domains
411 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:445 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software49% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
49%
cryptocurrency blockchain
29%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
7196.251.80.121Seychelles
AS401120CHEAPY-HOST
535.186.247.156United States
AS396982GOOGLE-CLOUD-PLATFORM
554.170.45.74Dublin, Leinster, Ireland
AS16509AMAZON-02
554.72.2.175Dublin, Leinster, Ireland
AS16509AMAZON-02
224--

Detected Technologies3

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T175F2D72564087E3B03872BD27C57670AB3F4A156C1C1580494FD96680FEFFD6AA2B16B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:YN7bCk2YXoktkAJ3jU9AKe8LgADAeA+vCzrYjaNAq7K5IfCjkdj:qSk2YXoktkAJ3jU9AKe8LgADAeA+ArDB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:37081:OniowGBMQcikdBnEBAJZoVkKwclrGAQAkHARdGiTAmHmYrPhA0QgBYTCBIAAQKYgJA8E6YOIFHbgWoFArICQyUgWCAEEs0Ax

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:N/A
Perceptual Hash:N/A
Difference Hash:N/A
Wavelet Hash:N/A
Color Hash:N/A

Other Hashes

Crop Resistant:N/A

Scan History

Scan history not available

Unable to load historical scan data