Security Scan Report: cluster1.instructure.com

Redirected to:
https://cluster1.instructure.com/login/canvas
Site favicon
Submitted: May 7, 2026, 4:10:35 PMCompleted: May 7, 2026, 4:11:27 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 17 HTTP transactions. The main domain is cluster1.instructure.com and was registered NaN years ago.

Submitted URL: https://cluster1.instructure.com

Effective URL: https://cluster1.instructure.com/login/canvasRedirected

The Cisco Umbrella rank of the primary domain is #994 of the top 1 million websitesTop 1K Site

AI Security Verdict

Moderate Risk

Confidence: 85%

5
Risk Score

The page impersonates Facebook and harvests passwords without a username field, indicating a high‑risk phishing site.

Risk Factors
Brand impersonation / typosquatting
Credential harvesting pattern (password‑only field)
Highly obfuscated JavaScript
Safety Factors
Domain age >10 years (well‑established)
Cisco Umbrella ranking in top 1 000
No Indicators of Compromise matched
No JavaScript malware YARA signatures
No network IDS alerts
Established domain (10298 days old) with no strong malicious indicators — risk clamped from 8 to 5
Domain age information unavailable

Details

Page Title

Canvas Login | Instructure

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

social media network

(86%)

Domain Information

Within the commercial generic top-level domain (.com), 'cluster1.instructure.com' is registered; it also runs on subdomain 'cluster1'. The core label 'instructure' covers 11 characters holding 4 vowels versus 7 consonants. Breaking it apart gives 2 words: in, structure. Median word length is 5.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://cluster1.instructure.com

Page Load Overview

5.32s
Total Load Time
56
HTTP Requests
3
Domains
556 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:411 chars
Detector Agreement:100%

Website Classification

Primary Category

social media network86% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

social media network
86%
technology software
28%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2844.192.143.204Ashburn, Virginia, United States
AS14618Amazon.com, Inc.
2818.173.206.143United States
AS16509Amazon.com, Inc.
562--

Detected Technologies2

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1DB921B3610646D765DE283D4EA707F1C9AB8814BB08078D4FAFD4A1C5FE3EE64A1325B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:FxGdqwtFs/s1svwZCfVKOvHl0GrGxz0+4FM+9/fc5EYzXHaozpTReH14AAvFJMoM:k0+t+93AQ8h+VO8

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:21100:oIBqCCBRLKwR1ooIx4gagjZAdYUEBkECSQKEZBAAKkVhIxIBHsAkAq8u0C2DieJxQRBoLgEMCUMJlRFgukhcKYydAA4RFQLl

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:1018180000000000
Perceptual Hash:cccccc3333366699
Difference Hash:24b2b21410000000
Wavelet Hash:1c1c1c1c0f0f0f0f
Color Hash:#406cbf

Scan History

Scan history not available

Unable to load historical scan data