Security Scan Report: auth.properties

Site favicon
Submitted: Sep 24, 2026, 12:45:36 AMCompleted: Sep 24, 2026, 12:47:02 AMpubliccompleted

This website contacted 4 IPs in 3 countries across 2 domains to perform 2 HTTP transactions. The main domain is auth.properties and was registered 15 years ago.

Submitted URL: https://auth.properties/E.u3z2xUZjIi-O?/microsoftonline/mailbox/upgrade

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Fake Microsoft sign-in hosted on auth.properties, an unrelated unranked domain, harvesting email and password credentials. Do not enter any login details.

Risk Factors (4)
Brand impersonation of Microsoft on a non-Microsoft, unranked domain
Credential collection form (email + password) on an unrelated domain
Spoofed Microsoft sign-in URL path and branding
Prefilled victim email with account-error lures
Domain age information unavailable

Details

Page Title

Sign in to your Microsoft account

Scan Type

public

Domain Name Analysis

You're looking at domain 'auth.properties' on the .properties top-level domain while skipping any subdomain. The core label 'auth' covers 4 characters containing two vowels alongside 2 consonants. Tokenizing the label suggests 2 words: au, th. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://auth.properties/E.u3z2xUZjIi-O?/microsoftonline/mailbox/upgrade

Page Load Overview

0.89s
Total Load Time
75 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:627 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software68% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
68%
documentation technical
43%
government public service
35%
adult content
32%
healthcare medical
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2212.104.128.1Cloudflare · CDNFinland
AS13335Cloudflare, Inc.
0146.75.121.137Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
0212.104.128.0Cloudflare · CDNFinland
AS13335Cloudflare, Inc.
0104.16.79.6Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
24--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T156D3F77A4183157C8B1E7836B6EB2D003FE1A1034953D9A4B7EC46B48F0A9E1569D3EF

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:DxifuNadm9uwUdW5UfkGKF0qd8SlWIYOQ1rt+p2sE62emtRd+2RrsoqW/f:+u2mowUdLkNF0e8SlWBQmIaf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:137140:AYAArBECgQCMkQU4C6AoSHFZFrBGhCI4kOFUIDCCEwlIkwWsSBiAZQjAKiCQ8RaCAAFRAslhoIAIa0wzBAYBECI60RZAcIHi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000393b37373737
Perceptual Hash:845971764699d96e
Difference Hash:88e4f2d3e5eee6e6
Wavelet Hash:00003b3b373f373f
Color Hash:#1f8293

Other Hashes

Crop Resistant:88e4f2d3e5eee6e6

Scan History

Scan history not available

Unable to load historical scan data