Summary
This website contacted 7 IPs in 3 countries across 4 domains to perform 15 HTTP transactions. The main domain is bfui2bp0kz.credibledomain.de.
Submitted URL: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?scope=openid&prompt=none&client_id=8d216f7e-d484-46a2-b5b0-07b7d1b3d10d&state=ZW1haWxAbWFpbC5jb20=
Effective URL: https://bfui2bp0kz.credibledomain.de/l/JeRLk2aiKXQ?error=login_required&error_description=AADSTS50058%3a+A+silent+sign-in+request+was+sent+but+no+user+is+signed+in.+The+cookies+used+to+represent+the+user%27s+session+were+not+sent+in+the+request+to+Azure+AD.+This+can+happen+if+the+user+is+using+Internet+Explorer+or+Edge%2c+and+the+web+app+sending+the+silent+sign-in+request+is+in+different+IE+security+zone+than+the+Azure+AD+endpoint+(login.microsoftonline.com).+Trace+ID%3a+5d5a9f14-67e6-47ac-8189-861a614c6d00+Correlation+ID%3a+4f4d8bde-f582-4196-80f5-a152ae64e8b0+Timestamp%3a+2026-04-22+21%3a05%3a54Z&error_uri=https%3a%2f%2flogin.microsoftonline.com%2ferror%3fcode%3d50058&state=ZW1haWxAbWFpbC5jb20%3d#Redirected
The Cisco Umbrella rank of the primary domain is #8 of the top 1 million websitesTop 100 Site
AI Security Verdict
Moderate Risk
Confidence: 92%
The page redirects from Microsoft’s login to an unknown domain, contains a base64‑encoded email token and brand impersonation – high‑risk credential phishing. Report as scam.
Risk Factors
Safety Factors
Details
Page Title
Trail
Scan Type
public
Language
English
Category
unknown
(0%)Domain Information
The domain name 'login.microsoftonline.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'login'. The core label 'microsoftonline' covers 15 characters containing 6 vowels alongside nine consonants. Breaking it apart gives two words: microsoft, online. The median word length lands at 7.5 characters. No strong language cues emerged from the frequency lists.
Screenshot

Page Load Overview
Language Analysis
Primary Language
Detection Details
Website Classification
Primary Category
All Detected Categories
Detected Features
Domain & IP Information
| Requests | IP Address | Location | AS Autonomous System |
|---|---|---|---|
| 3 | 23.53.42.114 | Frankfurt am Main, Hesse, Germany | AS20940Akamai International B.V. |
| 2 | 20.190.160.2 | Amsterdam, North Holland, Netherlands | AS8075Microsoft Corporation |
| 2 | 20.190.160.14 | Amsterdam, North Holland, Netherlands | AS8075Microsoft Corporation |
| 2 | 104.18.95.41 | United States | AS13335Cloudflare, Inc. |
| 2 | 104.18.94.41 | United States | AS13335Cloudflare, Inc. |
| 2 | 40.126.32.134 | Amsterdam, North Holland, Netherlands | AS8075Microsoft Corporation |
| 2 | 172.67.144.224 | United States | AS13335Cloudflare, Inc. |
| 15 | 7 | - | - |
Detected Technologies4
Content Similarity HashesFor malware variant detection
TLSH (Trend Micro Locality Sensitive Hash)
Security-focusedSpecialized for malware detection and similarity analysis
ssdeep (Context Triggered Piecewise Hashing)
Context-awareDetects similar content even with modifications
sdhash (Similarity Digest Hashing)
High-precisionHigh-precision similarity detection for forensic analysis
These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.
Image Hashes
Perceptual Hashes
Other Hashes
Scan History
Scan history not available
Unable to load historical scan data