Security Scan Report: evrihr.icasework.com

Redirected to: https://login.microsoftonline.com/9c132d09-4765-4d2b-a356-e76985eecf78/oauth2/v2.0/authorize?response_type=code&scope=openid+email+profile+offline_access&client_id=9fbb7b0f-9934-4791-bb91-e954e1463b14&redirect_uri=https%3A%2F%2Fevrihr.icasework.com%2Flogin&state=evrihr%40t8gnqcph1c0tubrqvlejke382c%40https%3A%2F%2Flogin.microsoftonline.com%2F9c132d09-4765-4d2b-a356-e76985eecf78%2Fv2.0%2F.well-known%2Fopenid-configuration&nonce=qshk918ufr6r9ijt53lfpd21fl&sso_reload=true

Site favicon
Submitted: Jan 8, 2026, 6:27:10 AMCompleted: Jan 8, 2026, 6:28:27 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 1 country across 7 domains to perform 33 HTTP transactions. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://evrihr.icasework.com

Effective URL: https://login.microsoftonline.com/9c132d09-4765-4d2b-a356-e76985eecf78/oauth2/v2.0/authorize?response_type=code&scope=openid+email+profile+offline_access&client_id=9fbb7b0f-9934-4791-bb91-e954e1463b14&redirect_uri=https%3A%2F%2Fevrihr.icasework.com%2Flogin&state=evrihr%40t8gnqcph1c0tubrqvlejke382c%40https%3A%2F%2Flogin.microsoftonline.com%2F9c132d09-4765-4d2b-a356-e76985eecf78%2Fv2.0%2F.well-known%2Fopenid-configuration&nonce=qshk918ufr6r9ijt53lfpd21fl&sso_reload=trueRedirected

The Cisco Umbrella rank of the primary domain is #185,440 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing site impersonating EVRi to steal credentials

Risk Factors
Brand impersonation on low‑ranking domain
Credential harvesting login form
Suspicious redirect to Microsoft login for a custom tenant
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain 'evrihr.icasework.com' uses the commercial generic top-level domain (.com) with subdomain 'evrihr'. The second-level label 'icasework' is 9 characters long containing 4 vowels alongside 5 consonants. Breaking it apart gives 2 words: i, casework. Median word length is 4.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://evrihr.icasework.com

Page Load Overview

5.03s
Total Load Time
2
HTTP Requests
1
Domains
N/A
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:109 chars
Detector Agreement:67%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
213.107.246.44United Kingdom
020.190.159.0United Kingdom
020.190.159.4United Kingdom
02.16.241.211United Kingdom
051.11.192.50United Kingdom
020.190.159.71United Kingdom
013.41.174.6United Kingdom
27--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T156734BD97EA71E37828A50B5B5B57E02AA3A69038D4CDDA0F14CC9802FFB70D8177647

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:lu8GLGGMihBeax/U+zzTEyqU6MVnvnaloMPbJEA/hirwC:s8WY+myS2iC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:77304:QKAAKAgQQEiQQAIHApYxkJKKDJQAAKhNE6BNClQnmRJQ4EgE1FzjUEgzFbEvQJeCs4UCwSbIgYpUA3EQYAEQAKAATgwd8Sgp

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000181818180000
Perceptual Hash:9c996366c8d9c9cc
Difference Hash:202cb2b2b2b24c33
Wavelet Hash:0c3f1f1f1f1f0701
Color Hash:#405dbf

Scan History

Scan history not available

Unable to load historical scan data