Security Scan Report: zscaler.my.salesforce.com

Redirected to:
https://login.zscalertwo.net/samlsso/HxnBcP11TmLwf827tTW1XUi1R7yxh6kb
Submitted: May 10, 2026, 7:23:37 AMCompleted: May 10, 2026, 7:25:30 AMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 1 country across 2 domains to perform 4 HTTP transactions. The main domain is login.zscalertwo.net and was registered NaN years ago.

Submitted URL: https://zscaler.my.salesforce.com

Effective URL: https://login.zscalertwo.net/samlsso/HxnBcP11TmLwf827tTW1XUi1R7yxh6kbRedirected

The Cisco Umbrella rank of the primary domain is #1,775 of the top 1 million websitesTop 10K Site

AI Security Verdict

High Risk

Confidence: 94%

9
Risk Score

The site impersonates Zscaler on an unranked domain, redirects users, and triggers critical IDS alerts, indicating a high‑risk phishing/malware threat.

Risk Factors
Brand impersonation on an unranked, unrelated domain
Critical network IDS alert for possible malware exfiltration
Redirect from a well‑known domain to an unknown domain
Absence of a proper login form while claiming authentication
Domain age information unavailable

Details

Page Title

Welcome To Zscaler Directory Authentication

Scan Type

public

Language

🇺🇸

English

(63% confidence)

Category

unknown

(0%)

Domain Information

Within the commercial generic top-level domain (.com), 'zscaler.my.salesforce.com' is registered, featuring subdomain 'zscaler.my'. The core label 'salesforce' covers 10 characters split between 4 vowels and 6 consonants. Segmentation suggests two words: sales, force. Average segment length settles at five characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://zscaler.my.salesforce.com

Page Load Overview

0.93s
Total Load Time
5
HTTP Requests
2
Domains
16 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:63%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:63%
Script Type:Latin
Text Length:188 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
335.158.127.53Frankfurt am Main, Hesse, Germany
AS16509Amazon.com, Inc.
2165.225.73.180Frankfurt am Main, Hesse, Germany
AS62044Zscaler Switzerland GmbH
52--

Detected Technologies1

40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B672A411EF03364A7506D29D6BE1969677150033A31B23BDBF8DB344C3CAA504A72BED

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:vjF2VOkYNcn9NCf51XxDaXYleZq5mQDjSj9h4+r0+1Q8XS1aFd95BtD+v/jzW3iK:QlK5SIcZ2VDjkh1QCXMoiJaxW6

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:16328:ANKQkxIkBxCbCAEISLJgZIgJvUAmxkogBOTIgRPkCwFJHdBgAIIFB0TLUcVCS6cQFboRRADBwyDkoQclAM5APhgDE5BlwchQ

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000003c3d000000
Perceptual Hash:9b64649b9b64649b
Difference Hash:0000047879060000
Wavelet Hash:0f0f2f3f3c3c3030
Color Hash:#c587a2

Other Hashes

Crop Resistant:0000047879060000

Scan History

Scan history not available

Unable to load historical scan data