Security Scan Report: office-365-msn--oficeer.replit.app

Submitted: Sep 22, 2026, 5:50:07 AMCompleted: Sep 22, 2026, 5:50:35 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Microsoft-branded fake 'terms update' page on a lookalike replit.app subdomain whose form posts to a second lookalike domain (vercel.app) — classic multi-stage phishing; do not enter any data.

Risk Factors (5)
Brand impersonation of Microsoft on a non-Microsoft domain
Form action posts to a different lookalike domain (20260utlookmsn.vercel.app) rather than a Microsoft endpoint
Social-engineering lure: 'we are updating our terms / service contract'
Deceptive hostname designed to resemble Office 365/Outlook
Single-source threat-intel phishing report on the primary domain
Domain age information unavailable

Details

Page Title

Iniciar

Scan Type

public

Domain Name Analysis

Domain 'office-365-msn--oficeer.replit.app' uses the application-focused generic top-level domain (.app) with subdomain 'office-365-msn--oficeer'. The registrable portion 'replit' spans 6 characters with 2 vowels and four consonants. It segments into 2 words: rep, lit. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://office-365-msn--oficeer.replit.app/

Page Load Overview

0.87s
Total Load Time
304 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:219 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software41% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
41%
documentation technical
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
534.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
235.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2142.251.20.95Google · CDNUnited States
AS15169Google LLC
2142.251.20.94Google · CDNUnited States
AS15169Google LLC
114--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17D4140C28CE30886A2036198B2C7B90927D5D903921ADC107BFD52798FC9B9DC4AB75D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:s84Mwe40PYmDnvYDGR3g3itqr1EvobD6/UceaMpHNB:94Mx40xwStqryvo6cccptB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1939:AAAAAGACARAAAAAABAAIAACBAAAKAAhABAAAAEBQAgAAAABAAAgQABAACAAAAAQQAIAUABQADQAIAARARAIAAAAAAAgAERAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f0f8fc9abd250d3e
Perceptual Hash:c3cc4562dd297789
Difference Hash:e2b0b03a698dd9dc
Wavelet Hash:f0f8dc18b9211d3e
Color Hash:#784f3a

Other Hashes

Crop Resistant:e2b0b03a698dd9dc

Scan History

Scan history not available

Unable to load historical scan data