Security Scan Report: vsp.coupahost.com

Redirected to:
https://login.microsoftonline.com/3510753d-6c40-48ae-9b9e-2fc672d5e5dd...
Site favicon
Submitted: Aug 17, 2026, 9:34:52 AMCompleted: Aug 17, 2026, 9:36:04 AMpubliccompleted

This website contacted 4 IPs in 3 countries across 9 domains to perform 25 HTTP transactions. The main domain is login.microsoftonline.com and was registered 24 years ago.

Submitted URL: https://vsp.coupahost.com

Effective URL:

https://login.microsoftonline.com/3510753d-6c40-48ae-9b9e-2fc672d5e5dd...
Redirected

The Cisco Umbrella rank of the primary domain is #18,321 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 82%

2
Risk Score

The page impersonates VSP Vision and harvests credentials via a login form that forwards to Microsoft; treat as high‑risk phishing.

Risk Factors (3)
Brand impersonation of VSP Vision
Credential collection form on unrelated domain
Cross‑origin SSO redirect to Microsoft login
Safety Factors (4)
No IoC or YARA malware matches
No network IDS alerts
Domain age is well‑established
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 7 to 2
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Domain Name Analysis

The domain 'vsp.coupahost.com' uses the commercial generic top-level domain (.com), featuring subdomain 'vsp'. The core label 'coupahost' covers 9 characters holding 4 vowels versus five consonants. Breaking it apart gives three words: coup, a, host. Expect four characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://vsp.coupahost.com

Page Load Overview

4.30s
Total Load Time
622 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:249 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software41% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
41%
government public service
35%
healthcare medical
29%
social media network
28%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
754.244.45.207Aws · CLOUDBoardman, Oregon, United States
AS16509Amazon.com, Inc.
640.126.31.67Ireland
AS20940Akamai International B.V.
652.223.59.71Germany
AS16509Amazon.com, Inc.
654.244.45.171Aws · CLOUDBoardman, Oregon, United States
AS16509Amazon.com, Inc.
254--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19D734A9A7FA21D37C68644B5B5BA6E026E3A6D07884CDD60F19CCC882FEB30D8137557

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:FHUh8GLG2jpcxSyzr2o3IZ9Tjuokmap5vPoMLufT0VpYiTpoC:g8ster2la/AcuC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:80335:QJwRHBAKEAAAQoRmC4EJrACACNWkMchG4gVqABRcY0ApXkoGKCMBDtYooZLFC4RAAJRDOkoAoYA/cy0yFCpsQIQQzR4LkxAB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0218181818180000
Perceptual Hash:8d9d62638c3699d9
Difference Hash:5e723232b2b3e7c7
Wavelet Hash:bf1e1e1f1b392121
Color Hash:#6ce0e0

Scan History

Scan history not available

Unable to load historical scan data