Security Scan Report: enterpriseenrollment.ramp.com

Redirected to: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019d212d-020e-721d-97ce-ef638b436bbb&response_mode=fragment&client_info=1&nonce=019d212d-020f-736d-9fa2-94b9d1d71d07&state=eyJpZCI6IjAxOWQyMTJkLTAyMGYtNzM0My1hMThiLWRmMzhiNDVkOWM1YSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=GfhWgVvca_n2FH7dmCaw_tY6bEz-3pQSj1r5bnXNeNk&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=true

Submitted: Mar 24, 2026, 6:48:08 PMCompleted: Mar 24, 2026, 6:49:22 PMpubliccompleted
Loading additional data...

Summary

This website contacted 8 IPs in 2 countries across 9 domains to perform 42 HTTP transactions. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://enterpriseenrollment.ramp.com

Effective URL: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019d212d-020e-721d-97ce-ef638b436bbb&response_mode=fragment&client_info=1&nonce=019d212d-020f-736d-9fa2-94b9d1d71d07&state=eyJpZCI6IjAxOWQyMTJkLTAyMGYtNzM0My1hMThiLWRmMzhiNDVkOWM1YSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=GfhWgVvca_n2FH7dmCaw_tY6bEz-3pQSj1r5bnXNeNk&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=trueRedirected

The Cisco Umbrella rank of the primary domain is #38,805 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 80%

6
Risk Score

Page imitates Microsoft Azure sign‑in on a third‑party domain; likely phishing attempt.

Risk Factors
Credential form hosted on a non‑official Microsoft domain
Brand name misspelling indicating low‑quality impersonation
Cross‑origin credential submission
Safety Factors
Domain age > 30 years (well‑established)
Final URL points to legitimate Microsoft login endpoint
No malicious Indicators of Compromise matches
No JavaScript malware or suspicious behavior detected
Domain ranks within top 100 K in Cisco Umbrella
Domain age information unavailable

Details

Page Title

Sign in to Microsoft Azure

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(77%)

Domain Information

You're looking at domain 'enterpriseenrollment.ramp.com' on the commercial generic top-level domain (.com) and includes subdomain 'enterpriseenrollment'. Count 4 characters in 'ramp' holding one vowel versus three consonants. Breaking it apart gives one word: ramp. The median word length lands at four characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://enterpriseenrollment.ramp.com

Page Load Overview

1.05s
Total Load Time
26
HTTP Requests
8
Domains
497 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software77% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
77%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
513.107.246.44United States
AS8075Microsoft Corporation
313.74.111.192Dublin, Leinster, Ireland
AS8075Microsoft Corporation
3150.171.84.26United States
AS8075Microsoft Corporation
313.69.239.74United StatesUnknown
323.207.210.137UnknownUnknown
320.190.159.129UnknownUnknown
340.126.32.138UnknownUnknown
320.42.65.90United States
AS8075Microsoft Corporation
268--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C5936BDA7FF3293B868685B4B5797D026E7A69074888CDA4B15CC8882FEB74D8133513

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:st8GLG2PWVsWyRADd2fFpnvDoIyEk77gx2xpTvPoMmCfwEfIiK9O1:M8IWKWyRbdDJ32RAR9O1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:90377:Aw0iYQQL4MgCCEsBJABIFVQEYMHaBKEmDrHg+LmnlNCEAUJABg4C3mIoFVgGQQAoUEa1qgCEFAIaSEoAMsCVBRLngCEAgCao

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003e3f3f373fff00
Perceptual Hash:85d970f626d919e4
Difference Hash:c8e2d2d2e4cae6e7
Wavelet Hash:003a3b3f373f7700
Color Hash:#bfa440

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data