Security Scan Report: mipipave.z28.web.core.windows.net

Redirected to:
https://mipipave.z28.web.core.windows.net/mcily9hd/z92ou6ewlyxo.html
Site favicon
Submitted: Sep 17, 2026, 11:30:50 AMCompleted: Sep 17, 2026, 11:31:09 AMpubliccompleted

This website contacted 4 IPs in 2 countries across 4 domains to perform 17 HTTP transactions. The main domain is mipipave.z28.web.core.windows.net and was registered 7 years ago.

Submitted URL: https://mipipave.z28.web.core.windows.net/mcily9hd/

Effective URL:

https://mipipave.z28.web.core.windows.net/mcily9hd/z92ou6ewlyxo.html
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Cloud-hosted decoy library page that overlays a fake Windows Defender alert with a support phone number and contacts an IP-logger domain. Safe Browsing flags it for social engineering — a classic tech-support scam.

Risk Factors (5)
Google Safe Browsing Social Engineering threat
Fake Microsoft Windows Defender security alert impersonating a trusted brand
Impersonated brand hotline phone number presented for 'support'
IP logger / shortener domain (iplog.co) contacted by the page
Right-click blocking and packed/encoded inline scripts (anti-analysis)
Domain age information unavailable

Details

Page Title

新着情報

Scan Type

public

Domain Name Analysis

The domain 'mipipave.z28.web.core.windows.net' uses the network infrastructure generic top-level domain (.net) with subdomain 'mipipave.z28.web.core'. The second-level label 'windows' is 7 characters long containing 2 vowels alongside five consonants. It segments into one word: windows. Median word length is 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mipipave.z28.web.core.windows.net/mcily9hd/

Page Load Overview

1.05s
Total Load Time
771 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:46%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:ja-JP
Text Length:97,919 chars
Detector Agreement:100%
Language mismatch: Declared as ja-JP but detected as en

Website Classification

Primary Category

healthcare medical64% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

healthcare medical
64%
cryptocurrency blockchain
60%
news media journalism
50%
technology software
50%
documentation technical
45%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
520.60.13.228Azure · CLOUDParis, Île-de-France, France
AS8075Microsoft Corporation
4188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4104.17.24.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
4188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
174--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T115F3BF1CAB8C3439067383272D91A6CA863E9E37E1541D85707E849D3FD879CDE1EAB4

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:2BqcsTkMEaI+ks6MuC/SMpo2KUHM0jtvCOWtHPxhYLHv9HW+UX1ohxeOYr9dvtcY:dBTkMEaImVsco26gqOgvxh0kgxeOYZdf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:168222:yoSGLaICQyANBCAUQEAiELQesCDN5QVKqVU6AgKG8gNqBjwBXB0EEiGUBQALiasZBGDWcsCCFBQBSVtGBYdCAghBYICARSRo

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:383c3c3c3c3c0101
Perceptual Hash:cbd734ce7428552c
Difference Hash:c9c9e9e9e1e1fbb3
Wavelet Hash:3c3c7c3c7c7c3901
Color Hash:#ac537e

Scan History

Scan history not available

Unable to load historical scan data