Security Scan Report: creditsafe.167.235.134.13.sslip.io

Redirected to:
https://login.microsoftonline.com/eec3c7b7-a8b0-43c7-be4b-b44925652963...
Site favicon
Submitted: Oct 3, 2026, 5:19:41 AMCompleted: Oct 3, 2026, 5:20:19 AMpubliccompleted

This website contacted 12 IPs in 3 countries across 7 domains to perform 17 HTTP transactions. The main domain is login.microsoftonline.com and was registered 31 years ago.

Submitted URL: https://creditsafe.167.235.134.13.sslip.io/

Effective URL:

https://login.microsoftonline.com/eec3c7b7-a8b0-43c7-be4b-b44925652963...
Redirected

The Cisco Umbrella rank of the primary domain is #479,547 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 68%

2
Risk Score

Unranked raw-IP dynamic-DNS host (creditsafe.<ip>.sslip.io) that forwards to genuine Microsoft OAuth but returns the authorization code to its own sslip.io callback — an OAuth consent-phishing pattern; do not sign in from this link.

Risk Factors (4)
Entry point is an IP-embedded dynamic-DNS (sslip.io) host rather than a normal registered domain
OAuth redirect_uri points back to the attacker-controlled sslip.io host, exposing the Microsoft authorization code/token
Network IDS raised HIGH alerts for dynamic-DNS traffic to sslip.io
Brand-like subdomain name 'creditsafe' used on an untrusted raw-IP host as a lure
Safety Factors (6)
Final URL is the genuine login.microsoftonline.com Microsoft sign-in domain, not a lookalike
Microsoft-branded page matches the domain actually serving it; no third-party brand impersonation on the rendered content
Cross-origin form handling was assessed as a legitimate SSO flow, no credential exfiltration detected
No Indicators of Compromise, no YARA malware patterns, no known kit roster match
No payment fields and no disguised/orphan password fields
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 7 to 2
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Domain Name Analysis

Domain 'creditsafe.167.235.134.13.sslip.io' uses the British Indian Ocean Territory country-code top-level domain (.io) and includes subdomain 'creditsafe.167.235.134.13'. Count 5 characters in 'sslip' containing one vowel alongside 4 consonants. Splitting it apart reveals 2 words: s, slip. Median word length comes out to 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://creditsafe.167.235.134.13.sslip.io/

Page Load Overview

1.87s
Total Load Time
475 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:109 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software79% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
79%
social media network
28%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
640.126.31.1Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
1167.235.134.13Nuremberg, Bavaria, Germany
AS24940Hetzner Online GmbH
120.190.159.68Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
113.107.246.44Azure · CLOUDUnited States
AS8075Microsoft Corporation
120.50.80.215Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
140.126.31.2Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
123.207.210.136Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
120.190.159.0Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
120.190.159.73Azure · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
113.107.246.60Azure · CLOUDUnited States
AS8075Microsoft Corporation
1712--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1E9834AE97FA71D37868A81B5B17A2E026E3A5D07894C8DA0F19CCD843FFA64D8133553

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:ljsl8GLG2Gfajpa0dW+sTIZ9Tjuokmap5vPoMLufu0/IifmC:tY87Ixhs2a/AOC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:82646:JoPSSMCBBQIAdBaOCmVEUDCjxjDIQgG0QFwwhAMJKYQNoEKAXmNCGhISsSIAWgAWAhwgV1GAAUwWpROUIUsEAaivVhlLCAxi

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0010393b373f3737
Perceptual Hash:845971764699d96e
Difference Hash:88e4d2d3e5eee6e6
Wavelet Hash:00003b3b373f373f
Color Hash:#7997d2

Other Hashes

Crop Resistant:88e4d2d3e5eee6e6

Scan History

Scan history not available

Unable to load historical scan data