Security Scan Report: mvd.www.h0fdupdate.whm.907583facebook.com-adsmanager-ma.03-120-55-020.plesk.page

Redirected to:
https://login.microsoftonline.com/b34ec9cd-0a78-4623-9e54-2885791429c7...
Site favicon
Submitted: Jul 1, 2026, 9:20:08 PMCompleted: Jul 1, 2026, 9:21:23 PMpubliccompleted
Loading additional data...

Summary

This website contacted 4 IPs in 3 countries across 4 domains to perform 2 HTTP transactions. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://mvd.www.h0fdupdate.whm.907583facebook.com-adsmanager-ma.03-120-55-020.plesk.page/auth/oidc/azure

Effective URL: https://login.microsoftonline.com/b34ec9cd-0a78-4623-9e54-2885791429c7/oauth2/v2.0/authorize?access_type=offline&client_id=86a3041a-a218-4ec6-a019-fe40c6d23389&code_challenge=IcQntIPiWVdduNUnSeJlnPS9CRMBt3UfyOwUv4OQywI&code_challenge_method=S256&redirect_uri=https%3A%2F%2Fvpn.hsag-prod.onpower.cloud%2Fauth%2Foidc%2Fazure%2Fcallback&response_type=code&scope=openid+email+profile&state=eAdxayVqJVRC5vWN&sso_reload=trueRedirected

AI Security Verdict

Low Risk

Confidence: 94%

3
Risk Score

Phishing page impersonating Microsoft/Facebook login, captures credentials via external form – confirmed scam.

Risk Factors
Brand impersonation of a major service
Cross‑origin credential form
Unranked / low‑reputation domain
Heavy JavaScript obfuscation
Suspicious subdomain naming pattern
Safety Factors
No Indicators of Compromise matches
No YARA malware detections
No network IDS alerts
Top-ranked domain (Cisco Umbrella #0, 8758 days old) with no strong malicious indicators — a login form on a household-name site is normal; risk clamped from 10 to 3
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

documentation technical

(26%)

Domain Information

You're looking at domain 'mvd.www.h0fdupdate.whm.907583facebook.com-adsmanager-ma.03-120-55-020.plesk.page' on the .page top-level domain with subdomain 'mvd.www.h0fdupdate.whm.907583facebook.com-adsmanager-ma.03-120-55-020'. Count 5 characters in 'plesk' containing 1 vowel alongside 4 consonants. Splitting it apart reveals 2 words: pl, esk. Expect 2.5 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mvd.www.h0fdupdate.whm.907583facebook.com-adsmanager-ma.03-120-55-020.plesk.page/auth/oidc/azure

Page Load Overview

0.72s
Total Load Time
17
HTTP Requests
6
Domains
1.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:109 chars
Detector Agreement:67%

Website Classification

Primary Category

documentation technical26% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
26%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
53.120.55.20Aws · CLOUDFrankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
420.190.160.22Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
420.190.160.5Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
413.107.246.44Azure · CLOUDUnited States
AS8075Microsoft Corporation
174--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C9835ADABFA32937868A44B4B5763E026E375903888CEDA4F15CCD842FFA74D8127553

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:FMEo8GLG25VWeXHuacoZIZ9Tjuokmap5vPoMLufl0GXZiXC:u8V8Oac1a/AAC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:81294:ICHHAxVAQiPpAgkL5JwTgCKGNBRQgVkGYSUBA0HkAuyjpYMMjKTpkAqJAbCsMKFqQgUHQAYAOUBGhhYqiOBGVgA2DoI7JQDN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000187858180000
Perceptual Hash:c81d2727c8cf9d8c
Difference Hash:3202b2b2b232e585
Wavelet Hash:030018fafe1f75e5
Color Hash:#b240bf

Scan History

Scan history not available

Unable to load historical scan data