Security Scan Report: rakao-two.vercel.app

Redirected to:
https://rakao-two.vercel.app/
Submitted: Oct 1, 2026, 1:45:24 PMCompleted: Oct 1, 2026, 1:46:28 PMpubliccompleted

This website contacted 7 IPs in 1 country across 5 domains to perform 11 HTTP transactions. The main domain is rakao-two.vercel.app and was registered 12 years ago.

Submitted URL: http://rakao-two.vercel.app/

Effective URL:

https://rakao-two.vercel.app/
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed credential phishing kit on a throwaway Vercel subdomain: the login form's email/password are exfiltrated to Telegram (sendToTelegram) and victims are fingerprinted via api.ipify.org. Never enter credentials.

Risk Factors (5)
JavaScript sends password/email to an external server (Telegram bot) — definitive phishing behavior
Live login form with password field on an anonymous, unranked hosting subdomain
External IP-lookup call (api.ipify.org) used for victim profiling
ML classifier labels the page 'phishing scam' (61%), alongside finance/banking signals
Numeric/random subdomain naming with no reputation, no index, and no verifiable ownership
Domain age information unavailable

Details

Page Title

계정 인증

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'rakao-two.vercel.app' is registered with subdomain 'rakao-two'. Count 6 characters in 'vercel' containing two vowels alongside 4 consonants. It segments into 2 words: ver, cel. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://rakao-two.vercel.app/

Page Load Overview

2.88s
Total Load Time
261 KB
Total Size

Language Analysis

Primary Language

🇰🇷Korean
Code: ko
Confidence:60%
Script:Hangul
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:71 chars
Detector Agreement:100%
Language mismatch: Declared as en but detected as ko

Website Classification

Primary Category

phishing scam61% confidence
Type: static
Method: ml+structural

All Detected Categories

phishing scam
61%
finance banking
37%
adult content
32%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
5216.198.79.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1209.94.90.1United States
AS40680Protocol Labs
1172.217.208.95Google · CDNUnited States
AS15169Google LLC
1142.251.13.94Google · CDNUnited States
AS15169Google LLC
1172.67.74.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
164.29.17.131Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
1104.26.12.205Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
117--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1BF82836B24F720516A93E4BC3BAF53053265E0039A09CD287F9C53498F46B99ACB37DD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:TJ+U3RWl0Kikc+3eVPH1hPRHa4sx8utqqnA65Fk619uY/cQ5uG9Rk4HyfAy+ylJq:TIGaFmIofsiJ6eRCIdrfts3b

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:19166:BYErRAQQ0cCEAQQhBxjI4KAGNCibMQJJEiUqRDIxgOJMKAAYCCoQroEPogFjYDsLAJsDg9CkiUsKfwkAIKKQAAMMBhhwgIFB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1818180018000000
Perceptual Hash:9999cc6666333399
Difference Hash:32b2b24c300c0000
Wavelet Hash:38383c24fcfccccc
Color Hash:#1f931f

Other Hashes

Crop Resistant:32b2b24c300c0000

Scan History

Scan history not available

Unable to load historical scan data