Security Scan Report: md.rytzskl.com

Submitted: Sep 28, 2026, 8:28:09 AMCompleted: Sep 28, 2026, 8:28:43 AMpubliccompleted

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Fake OneDrive sharing page on md.rytzskl.com impersonating Microsoft to harvest sign-in/verification codes, posting user data to admin.greatoss.sbs; flagged as phishing. Do not enter credentials or codes.

Risk Factors (5)
Impersonation of Microsoft OneDrive file-sharing interface on a non-Microsoft domain
Single-source threat-intel phishing report on the page's primary domain
External admin API endpoint (admin.greatoss.sbs) receiving encoded user_id and device-code requests from inline JS
Deceptive verification/identity-confirmation lure ('Verify your identity to access', 'copy access code below')
Decoy 'session expired' content masking the active credential-harvesting flow
Domain age information unavailable

Details

Page Title

OneDrive

Scan Type

public

Domain Name Analysis

Domain 'md.rytzskl.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'md'. Its registrable label 'rytzskl' stretches across 7 characters containing zero vowels alongside 7 consonants. Breaking it apart gives 4 words: ry, tz, s, kl. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://md.rytzskl.com/file/sharep.html

Page Load Overview

1.85s
Total Load Time
61 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:60%
Script:Latin
Direction:ltr

Detection Details

Text Length:290 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software48% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
48%
documentation technical
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2162.254.24.67United States
AS54548IONOS Cloud Inc.
1142.251.20.102Google · CDNUnited States
AS15169Google LLC
1104.243.43.77Piscataway, New Jersey, United States
AS23470ReliableSite.Net LLC
1104.243.45.200Piscataway, New Jersey, United States
AS23470ReliableSite.Net LLC
1142.251.20.113Google · CDNUnited States
AS15169Google LLC
65--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FA039DA662C1943F358F89D3F06157CE3A648217E516E257F72C7AA48FD0E53C53A328

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:DN7JlrT3koALL9zpfxlm7iEs9lL06cST3koALL9zpP+:V33koGLbfTi6c63koGLbG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:39640:emEBg6V2EAKCAPJlOgMIIIIiFwhSVEAAgKJc4UPAUYglImJAyIyAIAo1QtU1kABYISiuggxqe/CCAkML6SCEBAFkCDQHBEAE

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffefefe7e7ffff
Perceptual Hash:b399cc6619996666
Difference Hash:102a085a4d4d0c00
Wavelet Hash:f0f8c0c0c3c3c3c3
Color Hash:#40a6bf

Other Hashes

Crop Resistant:102a085a4d4d0c00

Scan History

Scan history not available

Unable to load historical scan data