Security Scan Report: enterpriseenrollment.weareone.world

Redirected to: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019d2351-9e83-761b-ad27-07d4117a814a&response_mode=fragment&client_info=1&nonce=019d2351-9e84-7c4b-84e6-75878a3c1db6&state=eyJpZCI6IjAxOWQyMzUxLTllODQtNzQ1NS05M2Q3LTVjMWQxMDg5ZTBmZiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=9PvrEPc7b81Q5YfR3uq_TGDEWvuRhk5DZcQMqatZ1Cw&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=true

Submitted: Mar 25, 2026, 4:47:22 AMCompleted: Mar 25, 2026, 4:48:35 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 2 countries across 8 domains to perform 1 HTTP transaction. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://enterpriseenrollment.weareone.world

Effective URL: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019d2351-9e83-761b-ad27-07d4117a814a&response_mode=fragment&client_info=1&nonce=019d2351-9e84-7c4b-84e6-75878a3c1db6&state=eyJpZCI6IjAxOWQyMzUxLTllODQtNzQ1NS05M2Q3LTVjMWQxMDg5ZTBmZiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=9PvrEPc7b81Q5YfR3uq_TGDEWvuRhk5DZcQMqatZ1Cw&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=trueRedirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing login page impersonating Microsoft Azure; do not enter credentials.

Risk Factors
Brand impersonation on an unranked domain
Credential harvesting form (email/phone + password) submitted to a different domain
Highly obfuscated JavaScript (possible attempt to hide malicious behavior)
Domain age information unavailable

Details

Page Title

Sign in to Microsoft Azure

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(77%)

Domain Information

Domain 'enterpriseenrollment.weareone.world' uses the .world top-level domain; it also runs on subdomain 'enterpriseenrollment'. The core label 'weareone' covers 8 characters with five vowels and three consonants. Word splitting yields 3 words: we, are, one. Median word length is 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://enterpriseenrollment.weareone.world

Page Load Overview

0.53s
Total Load Time
27
HTTP Requests
8
Domains
592 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software77% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
77%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
920.42.65.90United States
AS8075Microsoft Corporation
352.236.189.96Amsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
340.126.32.76United StatesUnknown
3150.171.84.26United States
AS8075Microsoft Corporation
313.107.246.44United States
AS8075Microsoft Corporation
313.69.116.105UnknownUnknown
320.190.159.129UnknownUnknown
277--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T168935BEA7EE31937824645B5B5B93E03AA77A903984CCD64F05CCC842FFA75E8627503

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:s/8GLG2Qnrnu6nPnrn60nnv3SoIyEk77gx2xpTvPoMmCfvEfIiK/nq01:W8eL+3SJ32RAgy01

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:89313:BoqFAKKKDWgycZi0Ky5yRyCJYgooQUFDX6CQAIGEQiBiMwYGgWVgIDjWhCAYMUEEwgkrCzTIkQ4VSwlEEhGQRGcwSAfMZYoA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003e3f3f373fff00
Perceptual Hash:85d970f626d919e4
Difference Hash:c8e2d2d2e4cae6e7
Wavelet Hash:003a3b3f373f7700
Color Hash:#592d86

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data