Security Scan Report: security-server-landing-page--spencer-hunt1.replit.app

Site favicon
Submitted: Sep 27, 2026, 4:50:07 AMCompleted: Sep 27, 2026, 4:50:46 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Fake Microsoft password-verification page on a replit.app subdomain, using real Microsoft auth assets to harvest credentials. Do not enter any password.

Risk Factors (4)
Brand impersonation of Microsoft on a non-Microsoft domain
Credential (password) collection form on an unranked shared-hosting subdomain
Lure language about verifying password for 'sensitive info'
Single-source threat-intel report flagging the primary domain as a known attacker
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Domain Name Analysis

The domain name 'security-server-landing-page--spencer-hunt1.replit.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'security-server-landing-page--spencer-hunt1'. The second-level label 'replit' is 6 characters long holding two vowels versus 4 consonants. Splitting it apart reveals two words: rep, lit. Average segment length settles at 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://security-server-landing-page--spencer-hunt1.replit.app/

Page Load Overview

1.07s
Total Load Time
303 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:246 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software56% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
56%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
334.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
12.16.241.224Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
113.107.246.44Azure · CLOUDUnited States
AS8075Microsoft Corporation
135.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1185.221.216.117London, England, United Kingdom
AS393960Host4Geeks LLC
123.207.210.136Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
123.207.210.132Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
108--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15FB3B890692039269037C63671D1BD8766211403E73BAEB7F62D2DF8CF996C74E32A49

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:GxoBMCgKy+U5KazA/PWrF7qvEAFiQcpm2CkMgpC490kvSqmD:UoBgp4490kMD

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:116045:RcSBAeRITRKCSkIgoCBaqhhgCaWHTtEg0CjhERooKCQswgA2vQYACUgCcHgCg2VaURfEIiyhCoOIgQOggZskBAUAQABA5lQQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:181818181f1f1fbe
Perceptual Hash:9d6a55aad5aa54a8
Difference Hash:7171313131707d74
Wavelet Hash:191818191f1f1ffe
Color Hash:#4d783a

Other Hashes

Crop Resistant:7171313131707d74

Scan History

Scan history not available

Unable to load historical scan data