Security Scan Report: cetic.blob.core.windows.net

Submitted: Sep 26, 2026, 6:50:59 AMCompleted: Sep 26, 2026, 6:52:00 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 95%

10
Risk Score

Confirmed Microsoft credential-phishing kit hosted on an Azure blob bucket: fake sign-in harvesting passwords and MFA codes, with DevTools and right-click blocking. Do not enter any credentials.

Risk Factors (5)
Microsoft brand impersonation on a non-Microsoft cloud-storage bucket
Credential (password) harvesting form with password and username fields
Cloud-storage hosting (blob.core.windows.net) used to host a phishing kit instead of first-party infrastructure
DevTools and right-click blocking plus obfuscated eval() — active anti-analysis behavior
Repeated 'verify your identity / enter code / approve sign-in request' prompts to capture MFA/one-time codes
Domain age information unavailable

Details

Page Title

Sign In For Secure Access

Scan Type

public

Domain Name Analysis

Domain 'cetic.blob.core.windows.net' uses the network infrastructure generic top-level domain (.net), featuring subdomain 'cetic.blob.core'. Count 7 characters in 'windows' holding 2 vowels versus 5 consonants. It segments into one word: windows. Median word length is 7 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cetic.blob.core.windows.net/cetic/Cetic.html

Page Load Overview

1.23s
Total Load Time
542 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:3,158 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical61% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

documentation technical
61%
technology software
42%
government public service
42%
corporate business
40%
cryptocurrency blockchain
30%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
820.209.32.1Azure · CLOUDFrankfurt am Main, Hesse, Germany
AS8075Microsoft Corporation
1151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1140.82.121.3Frankfurt am Main, Hesse, Germany
AS36459GitHub, Inc.
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
113.107.246.44Azure · CLOUDUnited States
AS8075Microsoft Corporation
1185.199.108.133Fastly · CDNUnited States
AS54113Fastly, Inc.
1151.101.193.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1185.199.111.133Fastly · CDNUnited States
AS54113Fastly, Inc.
158--

Detected Technologies9

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T12964F817CD5B3E0A0762A22636EC9CE61A1D87C6709200DDF62DE4C9CFF99169CE21DD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

3072:Zh1XqzJcQIcVzyQJ/Rt+Aiseo6QRtF+T6h392XfMXJHNPM:lX/MRislyXkXJHNPM

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:333839:qIMQBcBByAEMCIUIAcQO4QCAdBA3JhOiMGQquqSrAggkYmggGY4IUeQICAiVhQiLxIAhE0gQAlAHIQgAhUADCBAKASSYUsAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000393b3f373737
Perceptual Hash:855974765b79648c
Difference Hash:88e4f2dbe3e6e6e6
Wavelet Hash:00203b2b3f37373f
Color Hash:#d2932d

Other Hashes

Crop Resistant:88e4f2dbe3e6e6e6

Scan History

Scan history not available

Unable to load historical scan data