Security Scan Report: security-server-page--signsexpress98.replit.app

Site favicon
Submitted: Oct 1, 2026, 2:50:10 AMCompleted: Oct 1, 2026, 2:50:51 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 88%

8
Risk Score

Fake Microsoft sign-in on a replit.app subdomain harvesting passwords behind a 'verify your identity / sensitive file' pretext. Not Microsoft — do not enter any credentials.

Risk Factors (5)
Brand impersonation of Microsoft on a non-Microsoft, unranked domain
Credential-capturing password field without a corresponding username field
Urgency/verification pretext ('sensitive file' identity check)
Free/shared hosting subdomain with no reputation and indeterminate page age
Unranked domain (not in Cisco Umbrella top 1M) claiming a major global brand
Domain age information unavailable

Details

Page Title

Microsoft | Login

Scan Type

public

Domain Name Analysis

Within the application-focused generic top-level domain (.app), 'security-server-page--signsexpress98.replit.app' is registered with subdomain 'security-server-page--signsexpress98'. Count 6 characters in 'replit' containing two vowels alongside 4 consonants. Splitting it apart reveals two words: rep, lit. Median word length is three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://security-server-page--signsexpress98.replit.app/

Page Load Overview

1.44s
Total Load Time
793 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:437 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software53% confidence
Type: dynamic
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
53%
documentation technical
49%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
434.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1142.251.14.95Google · CDNUnited States
AS15169Google LLC
1151.101.129.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1104.21.27.152Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
113.107.246.44Azure · CLOUDUnited States
AS8075Microsoft Corporation
1104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
1104.18.11.207Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
135.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
1195.80.159.133France
AS29152Decknet SARL
1151.101.65.155Fastly · CDNUnited States
AS54113Fastly, Inc.
1613--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T16C34431FE8F212991C43947817EA6BA57379C003CA19FDBA7D8E7354CF4E6848D62B48

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:Lfm0VHSXf28zNta3cjyHE9uc6BcgGk9Byf/MuSj+Yrj0YYM2pNgxQw/BPD:NSXeDuSj+Yrj0YYDw/BPD

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:242731:BFILUcgxTJCAEIIGgAlAVAwMUIBUsCRcwFhQHSKGBp0AIFoIAQgVBkC1c4kAAhIoA6DABlcRsAilFiSQQqghARMFDAA1AAqQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f8f8fcfebffb7f00
Perceptual Hash:c9cc43aa55a457b3
Difference Hash:e2b0903673c799dc
Wavelet Hash:f0f8fcda9d294d00
Color Hash:#2d6786

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data