Summary
API
This website contacted 14 IPs in 1 country across 10 domains to perform 16 HTTP transactions. The main domain is theodore3.com and was registered 17 years ago.
Submitted URL: https://www.theodore3.com/the-cover-up/wp-content/upgrade/Microsoft.html#a.b@c
AI Security Verdict
Confirmed Scam
Confidence: 95%
Confirmed Microsoft credential-phishing page injected into a compromised WordPress site; Safe Browsing Social Engineering hit, password-harvesting form and Microsoft branding on a non-Microsoft domain.
Risk Factors (5)
Details
Page Title
Microsoft | Login
Scan Type
public
Domain Name Analysis
The domain 'www.theodore3.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'www'. The second-level label 'theodore3' is 9 characters long holding four vowels versus 4 consonants, along with one digit. It segments into two words: theodore, 3. Median word length comes out to 4.5 characters. No strong language cues emerged from the frequency lists.
Screenshot

Page Load Overview
Language Analysis
Primary Language
Detection Details
Website Classification
Primary Category
All Detected Categories
Detected Features
Domain & IP Information
| Requests | IP Address | Location | AS Autonomous System |
|---|---|---|---|
| 3 | 162.241.24.83 | Phoenix, Arizona, United States | AS31898Oracle Corporation |
| 1 | 172.67.142.245Cloudflare · WAF | United States | AS13335Cloudflare, Inc. |
| 1 | 151.101.65.155Fastly · CDN | United States | AS54113Fastly, Inc. |
| 1 | 142.251.20.95Google · CDN | United States | AS15169Google LLC |
| 1 | 13.107.246.44Azure · CLOUD | United States | AS8075Microsoft Corporation |
| 1 | 104.17.25.14Cloudflare · WAF | United States | AS13335Cloudflare, Inc. |
| 1 | 104.18.11.207Cloudflare · WAF | United States | AS13335Cloudflare, Inc. |
| 1 | 142.250.154.95Google · CDN | United States | AS15169Google LLC |
| 1 | 188.114.97.9Cloudflare · WAF | United States | AS13335Cloudflare, Inc. |
| 1 | 104.26.13.205Cloudflare · WAF | United States | AS13335Cloudflare, Inc. |
| 16 | 14 | - | - |
Detected Technologies9
Content Similarity HashesFor malware variant detection
TLSH (Trend Micro Locality Sensitive Hash)
Specialized for malware detection and similarity analysis
ssdeep (Context Triggered Piecewise Hashing)
Detects similar content even with modifications
sdhash (Similarity Digest Hashing)
High-precisionHigh-precision similarity detection for forensic analysis
These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.
Image Hashes
Perceptual Hashes
Other Hashes
Scan History
Scan history not available
Unable to load historical scan data