Security Scan Report: rafailkegdfvcnbasdfhdgfsklil.cfolks.pl

Submitted: Dec 16, 2025, 11:40:38 AMCompleted: Dec 16, 2025, 11:41:14 AMpubliccompleted
Loading additional data...

Summary

This website contacted 1 IP in 1 country across 1 domain to perform 31 HTTP transactions. The main domain is rafailkegdfvcnbasdfhdgfsklil.cfolks.pl and was registered NaN years ago.

Submitted URL: https://rafailkegdfvcnbasdfhdgfsklil.cfolks.pl/vmx/tdw/auth/log.php

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Likely phishing site harvesting credentials and impersonating Aruba hosting.

Risk Factors
Hidden password field (credential harvesting technique)
Brand impersonation (Aruba) on a unrelated domain
Login form collecting credentials on a suspicious domain
Unranked domain with brand name increases phishing likelihood
Domain age information unavailable

Details

Page Title

404 Not Found

Scan Type

public

Language

🇮🇹

Italian

(58% confidence)

Category

other

(33%)

Domain Information

Domain 'rafailkegdfvcnbasdfhdgfsklil.cfolks.pl' uses the Polish country-code top-level domain (.pl), featuring subdomain 'rafailkegdfvcnbasdfhdgfsklil'. Its registrable label 'cfolks' stretches across 6 characters with 1 vowel and five consonants. Word splitting yields two words: c, folks. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://rafailkegdfvcnbasdfhdgfsklil.cfolks.pl/vmx/tdw/auth/log.php

Page Load Overview

1.69s
Total Load Time
31
HTTP Requests
1
Domains
202 KB
Total Size

Language Analysis

Primary Language

🇮🇹Italian
Code: it
Confidence:58%
Script:Latin
Direction:ltr

Detection Details

Language Code:it
Detection Confidence:58%
Script Type:Latin
Text Length:824 chars
Detector Agreement:100%

Website Classification

Primary Category

other33% confidence
Type: webapp
Method: ml+structural

All Detected Categories

other
33%
social_media
25%
phishing/scam
20%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
3193.157.100.34Poland
AS34360Cyber_Folks S.A.
311--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BAA2653C9294C2B9DD96C6ECAF3351B4A08ED4AAD1E1C741B77DC57027D28C5F20E899

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:4vMBY3OdRBRTl+LTlM+33li5xYhMXvRpioiFiWiRmvhjPs7plTiGiEihio6:i2Ddm3o5xdmF0nR/7pl2X5oo6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:23023:CkCbOJEiCRCgQASrACzwDUQQIEDaqCBVQEREMWBFYI6iSdUpmxjS6EiVwE2oCogQCEAMxoMOUhWgNHgmBBGVQIEfRgEY4UkJ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00db8fc3c3ffffff
Perceptual Hash:b93d4e4e635b1213
Difference Hash:2636181b1a04000c
Wavelet Hash:0083878183f7fee7
Color Hash:#d22dcd

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data