Security Scan Report: vpn-partners.essilorluxottica.com

Redirected to:
https://login.microsoftonline.com/c7d1a8f7-0546-4a0c-8cf5-3ddaebf97d51...
Submitted: Apr 6, 2026, 3:06:02 AMCompleted: Apr 6, 2026, 3:07:12 AMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 4 countries across 7 domains to perform 24 HTTP transactions. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://vpn-partners.essilorluxottica.com

Effective URL: https://login.microsoftonline.com/c7d1a8f7-0546-4a0c-8cf5-3ddaebf97d51/saml2?SAMLRequest=lZLNbtQwFIVfJfI%2BiZPJr5VJNXSEGKnAqDOwYIMc%2B6a1cOzg67Tw9njSVnRDJZa%2BOtffOcfurn5NOnoAh8qaLckSSq76brf4e3MLPxdAHwWBwS1ZnGGWo0Jm%2BATIvGCn3ccblieUzc56K6wmT2KGfNJvb3BEcD4wSfT1BR7mJDrst%2BR7I5uybes227SyppmoNlC2ZVUPBc%2BhkFCGoyyGIR%2FDAuICB4OeGx%2FuoHkV0yKm1ZluGK0YLZMsb76RaB%2ByKMP9irr3fkaWptreKZNMSjiLdvTWaGUgEXZKRS0z3ox1TMuiigtORdyIsYw3UnIYxraWZZZecuYk2r2EubYGlwncCdyDEvDl9uYvSmi7yJiHZhOjEz7PmMxcW64DFfyjdT9wBeOccoEkOj53%2Bk4Zqczd23UOTyJkH87nY3z8fDqT6L11AtaX3BLvFiB9d%2FHL1sJc%2F%2F%2B%2BuvT1fvcpuDjsj1Yr8fsCm7j%2Ft8ksydaJkvG4StlicAahRgUyNKi1fbx2wD08m037Ln39Dfs%2F&RelayState=_8d859979139d701c63e59567b4a2e4de5e59d4bb2f&SigAlg=http%3A%2F%2Fwww.w3.org%2F2001%2F04%2Fxmldsig-more%23rsa-sha256&Signature=oYw6piF3EZMHDs6rkFpsEATL6NKuGrAWIMrT%2Flsqn7M42XJxWXkJQt%2FlwCYHLaBTF0OGxAegDmuVQYZBz1KQz7pf4O%2BAdfdAOFlxVQ2rE8DtbJDxpuTAye%2FXxqz6b1o8IGiTtWNq%2ByqceDHE4WBrRkCzdQGOHj7NJHbU7NzqHj%2BuCvS%2BsAss4MPxlMMPhWPyD6RXcexnLhYR7UJnKEjF5lSRTjoxklwsBQT57Fxy47SfssHnRst7NSwXlzljAEFl4EOMDybC2HOPe8LYG0OFHGU3NbR4OKnomQ55twaP3o8aTH2up1DsA0ctmlIrZUrVjDiwEzbxDARfQkbUTy0BDw%3D%3D&sso_reload=trueRedirected

The Cisco Umbrella rank of the primary domain is #191,722 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 78%

2
Risk Score

Site appears to harvest credentials and shows malicious activity indicators; treat as high‑risk phishing.

Risk Factors
Critical IDS malware alert
High JavaScript obfuscation and dynamic code generation
Low domain ranking for a brand claim
Hidden SAML fields that could be abused for credential capture
Safety Factors
Domain age > 20 years (well‑established)
Form posts to legitimate Microsoft login endpoint
No IoC matches or YARA malware detections
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 7 to 2
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

You're looking at domain 'vpn-partners.essilorluxottica.com' on the commercial generic top-level domain (.com) and includes subdomain 'vpn-partners'. Its registrable label 'essilorluxottica' stretches across 16 characters split between 7 vowels and 9 consonants. It segments into six words: es, sil, or, lux, ot, tica. Average segment length settles at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://vpn-partners.essilorluxottica.com

Page Load Overview

1.12s
Total Load Time
19
HTTP Requests
6
Domains
503 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:109 chars
Detector Agreement:67%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
735.204.213.179Groningen, Groningen, Netherlands
AS396982Google LLC
223.207.210.137Ireland
213.69.116.104United States
213.107.246.44United States
AS8075Microsoft Corporation
220.190.160.130Amsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
2193.3.244.152Italy
AS212753Luxottica Group S.p.A.
240.126.31.2UnknownUnknown
197--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T19E735ADA7EB22937864A40B5B5B97E036E3B5903894CDC64F14CC8882FFB60D9137A57

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:lhC78GLG2S7vTwa4w26oIyEk77gx2xpTvPoMmCf2Ez9qitDC:fC78Z7vTwa4f6J32RAmDC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:78864:FAGAKtEACAA0AoUIgYZAOiUIEAhiCMHECgMEfEki1xwSqKAjkAgZRGXhANkBODQQxAQiU8rFoRmCAFXCgZAIaCQKGQoNgXRC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0038272f373f777f
Perceptual Hash:865359cccc337366
Difference Hash:88f0cdcbe5e6e6e6
Wavelet Hash:0030233b373f373f
Color Hash:#2d7fd2

Other Hashes

Crop Resistant:88f0cdcbe5e6e6e6

Scan History

Scan history not available

Unable to load historical scan data