Security Scan Report: tonkeeper-wallet.vercel.app

Redirected to:
https://tonkeeper-wallet.vercel.app/
Submitted: Sep 27, 2026, 6:50:31 AMCompleted: Sep 27, 2026, 6:53:21 AMpubliccompleted

This website contacted 4 IPs in 2 countries across 2 domains to perform 4 HTTP transactions. The main domain is tonkeeper-wallet.vercel.app and was registered 16 years ago.

Submitted URL: http://tonkeeper-wallet.vercel.app

Effective URL:

https://tonkeeper-wallet.vercel.app/
Redirected

AI Security Verdict

High Risk

Confidence: 78%

8
Risk Score

Vercel-subdomain page impersonating the Tonkeeper TON wallet brand and linking out to a domain flagged as a wallet drainer; no forms on-page but crypto-brand impersonation plus phishing IoC make it high risk.

Risk Factors (4)
Impersonation of the Tonkeeper wallet brand on a non-official, free hosting subdomain
Outbound link to a domain flagged as a wallet drainer
Targets cryptocurrency users (TON) — high-value phishing category
IDS alerts for abused cloud hosting namespace
Domain age information unavailable

Details

Page Title

Тонкипер | Кошелек для TON

Scan Type

public

Domain Name Analysis

Domain 'tonkeeper-wallet.vercel.app' uses the application-focused generic top-level domain (.app) with subdomain 'tonkeeper-wallet'. The core label 'vercel' covers 6 characters with two vowels and 4 consonants. Segmentation suggests 2 words: ver, cel. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://tonkeeper-wallet.vercel.app

Page Load Overview

39.63s
Total Load Time
1.3 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:37%
Script:Latin
Direction:ltr

Detection Details

Text Length:3,591 chars
Detector Agreement:50%

Website Classification

Primary Category

technology software74% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
74%
cryptocurrency blockchain
70%
download file sharing
40%
documentation technical
34%
finance banking
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
1216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
145.43.142.8United Kingdom
AS16276OVH SAS
145.43.142.2United Kingdom
AS16276OVH SAS
164.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
44--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11BD1A95B4300135C0752036694225BFE66AE881CF7E352EB22EC95647781CAA8E73FDA

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:HKfTjayVnxlSFDnxl1boKladl9/7GGFXoXxKAmXjC:HuaeyFjVb1Wl9/7zNoXxKvC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:6251:QQQFAFwACEjEg7AIgJAAAAgQCAAFgHQRgIIIUApUaATlEIQFHBpQWAgAQUCIUE0LRMAPIBMIyIMACgCxHhAQSIdBkQhhAUAR

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7f083f0303070fff
Perceptual Hash:a540d233ed2f85c7
Difference Hash:a189e6e7efdf5d00
Wavelet Hash:7f203f03030707ff
Color Hash:#8f1f93

Other Hashes

Crop Resistant:a189e6e7efdf5d00

Scan History

Scan history not available

Unable to load historical scan data