Security Scan Report: enterpriseenrollment.ylamaankivi.fi

Redirected to: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019bfb95-21fb-79a3-bb9b-2703d6046f1f&response_mode=fragment&client_info=1&nonce=019bfb95-21fc-761d-9ee4-c566dbc0ec59&state=eyJpZCI6IjAxOWJmYjk1LTIxZmMtNzUzNC1hMjJkLTdkYjM3ZjBiY2Q4OCIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=AWYHm1fOrVr_DDPWnGHClAdOs4NoMXD04Z6uR8l5F2M&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=true

Submitted: Jan 26, 2026, 6:33:30 PMCompleted: Jan 26, 2026, 6:34:39 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 2 countries across 8 domains to perform 1 HTTP transaction. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://enterpriseenrollment.ylamaankivi.fi

Effective URL: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019bfb95-21fb-79a3-bb9b-2703d6046f1f&response_mode=fragment&client_info=1&nonce=019bfb95-21fc-761d-9ee4-c566dbc0ec59&state=eyJpZCI6IjAxOWJmYjk1LTIxZmMtNzUzNC1hMjJkLTdkYjM3ZjBiY2Q4OCIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=AWYHm1fOrVr_DDPWnGHClAdOs4NoMXD04Z6uR8l5F2M&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=trueRedirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing login page impersonating Microsoft Azure; do not enter credentials.

Risk Factors
Brand impersonation (Microsoft Azure) on unrelated domain
Credential harvesting form (email + password)
Mismatched domain vs. final URL (enterpriseenrollment.ylamaankivi.fi → login.microsoftonline.com)
Unranked domain used for brand‑spoofing
Domain age information unavailable

Details

Page Title

Sign in to Microsoft Azure

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(78%)

Domain Information

You're looking at domain 'enterpriseenrollment.ylamaankivi.fi' on the Finnish country-code top-level domain (.fi) with subdomain 'enterpriseenrollment'. The second-level label 'ylamaankivi' is 11 characters long split between five vowels and 6 consonants. Tokenizing the label suggests four words: y, lama, an, kivi. Median word length comes out to 3 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://enterpriseenrollment.ylamaankivi.fi

Page Load Overview

1.11s
Total Load Time
26
HTTP Requests
7
Domains
621 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software78% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
78%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
8104.208.16.92Des Moines, Iowa, United States
AS8075Microsoft Corporation
320.190.159.2United States
3150.171.84.25United States
AS8075Microsoft Corporation
320.91.147.72Sweden
AS8075Microsoft Corporation
320.190.160.132Unknown
313.107.246.44United States
AS8075Microsoft Corporation
323.53.42.114Unknown
267--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1C9835AEA7EB31A37874A45B5B5B57D02AA7A69038D48CD60F08CCD842FFB64D8137253

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:ej8GLGGyHXWpozTEyqU6MVnvnaloMPt3Efoitq1:I8FGpXyS2Pq1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:88060:oxEAjCkAQAEQBDE0meKvRIEhEeFUEWRoCACgMAgAIIeIAEwCBILCPNwppGvFBQQiRTS1ARiAOEUgEBBXIIiCQDRySDgHQ4kS

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003e3f3f373fff00
Perceptual Hash:85d970f626d919e4
Difference Hash:c8e2d2d2e4cae6e7
Wavelet Hash:003a3b3f373f7700
Color Hash:#935f1f

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data