Security Scan Report: mfa-portal.amwayconnect.com

Redirected to:
https://mfa-portal.amwayconnect.com/global-protect/login.esp
Site favicon
Submitted: May 3, 2026, 5:07:33 AMCompleted: May 3, 2026, 5:08:50 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 11 HTTP transactions. The main domain is mfa-portal.amwayconnect.com and was registered NaN years ago.

Submitted URL: https://mfa-portal.amwayconnect.com

Effective URL: https://mfa-portal.amwayconnect.com/global-protect/login.espRedirected

The Cisco Umbrella rank of the primary domain is #434,170 of the top 1 million websites

AI Security Verdict

Moderate Risk

Confidence: 88%

5
Risk Score

Site impersonates GlobalProtect, hosts a credential‑stealing login form on a low‑ranked domain; treat as high‑risk phishing.

Risk Factors
Brand impersonation (GlobalProtect) on non‑official domain
Low Cisco Umbrella ranking for a claimed brand
Credential phishing form with multiple password fields
Critical JavaScript obfuscation score
Safety Factors
Domain age >17 years (well‑established)
No Indicators of Compromise detected
No YARA malware patterns
No network IDS alerts
Established domain (6317 days old) with no strong malicious indicators — risk clamped from 8 to 5
Domain age information unavailable

Details

Page Title

GlobalProtect Portal

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(62%)

Domain Information

Domain 'mfa-portal.amwayconnect.com' uses the commercial generic top-level domain (.com) and includes subdomain 'mfa-portal'. The registrable portion 'amwayconnect' spans 12 characters containing 4 vowels alongside eight consonants. Word splitting yields 2 words: amway, connect. Average segment length settles at 6 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://mfa-portal.amwayconnect.com

Page Load Overview

4.02s
Total Load Time
11
HTTP Requests
2
Domains
880 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:151 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software62% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
62%
phishing scam
41%
adult content
41%
government public service
29%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
618.173.205.5United States
AS16509Amazon.com, Inc.
5167.23.245.80Grand Rapids, Michigan, United States
AS11870ALTICOR INC
112--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15B4284129BA60811124BE0BC6EF986093970C417070ADE007DBC56E99FE6E5BC8BF7DD

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:ZiRiCiaMini3iIiNiBiIiAiRiriUiPiViBu72y:gYraBiyl8IldYOJKEc2y

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:12695:QFYUGJEAkRCIVuAJoYVoBV0DbQoBTmAUxlCYgjCAChIBDAiBTEHGhACG2hAIAVDcAQBAgArMMWAECCBCgaKBEYmAEUKPGAq6

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:88e5e7fff7e7ffff
Perceptual Hash:f272585899991d37
Difference Hash:308d4c220e0e0e00
Wavelet Hash:0080e7cbc3c3c3ff
Color Hash:#40bf59

Other Hashes

Crop Resistant:308d4c220e0e0e00

Scan History

Scan history not available

Unable to load historical scan data