Security Scan Report: internal.prontorecovery.com

Redirected to: https://login.microsoftonline.com/d4df8815-21a8-4138-b587-f539861a5cf3/oauth2/v2.0/authorize?client_id=2e850807-b318-4108-9958-cfac683fab77&redirect_uri=https%3A%2F%2Finternal.prontorecovery.com%2Fapi%2Fauth%2Fcallback&response_type=code&scope=openid+profile+email+User.Read&response_mode=query&prompt=select_account&state=%2Finternal%2F&sso_reload=true

Submitted: Apr 6, 2026, 9:53:09 AMCompleted: Apr 6, 2026, 9:54:21 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 3 countries across 7 domains to perform 1 HTTP transaction. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://internal.prontorecovery.com/

Effective URL: https://login.microsoftonline.com/d4df8815-21a8-4138-b587-f539861a5cf3/oauth2/v2.0/authorize?client_id=2e850807-b318-4108-9958-cfac683fab77&redirect_uri=https%3A%2F%2Finternal.prontorecovery.com%2Fapi%2Fauth%2Fcallback&response_type=code&scope=openid+profile+email+User.Read&response_mode=query&prompt=select_account&state=%2Finternal%2F&sso_reload=trueRedirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing login page impersonating Microsoft; do not enter credentials and report as scam.

Risk Factors
Cross‑origin credential form collecting email and password
Brand impersonation of Microsoft on an unrelated domain
Domain not in Cisco Umbrella top 1 M (low reputation)
Highly obfuscated JavaScript
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

Within the commercial generic top-level domain (.com), 'internal.prontorecovery.com' is registered, featuring subdomain 'internal'. The second-level label 'prontorecovery' is 14 characters long holding 5 vowels versus nine consonants. Splitting it apart reveals 2 words: pronto, recovery. Expect 7 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://internal.prontorecovery.com/

Page Load Overview

1.42s
Total Load Time
32
HTTP Requests
6
Domains
503 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:109 chars
Detector Agreement:67%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
840.126.32.140United States
440.126.32.138Netherlands
423.207.210.141Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
420.190.160.14UnknownUnknown
420.189.173.2UnknownUnknown
413.107.246.44United States
AS8075Microsoft Corporation
476.76.21.21Walnut, California, United States
AS16509Amazon.com, Inc.
327--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T11E734CD97EA31937828681B9B57A6E026F3B5D03884CDD60F19CC9842FFA74D4237647

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:lo8GLG262f5f9OoIyEk77gx2xpTvPoMmCfmEY9i+ieC:28lu59OJ32RAXC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:79194:SJCHtBCaEs6kLPAEUOB7Qhy5AsoWSsCgAoEIfYMEEhAUDKGAMQJIAxDCIAKtIBOABGIQSIYmrBBlDyghJCWaQTmhCahQ4ZaA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0010293b3737373f
Perceptual Hash:845971664e995b6e
Difference Hash:88e4d2d3e5e6e6e6
Wavelet Hash:00003b3b373f373f
Color Hash:#5b862d

Other Hashes

Crop Resistant:88e4d2d3e5e6e6e6

Scan History

Scan history not available

Unable to load historical scan data