Security Scan Report: passimovrt.cfd

Redirected to:
https://www.noticeofpleadings.net/lumma/domainseizurenotice.htm
Submitted: Sep 15, 2026, 1:48:01 AMCompleted: Sep 15, 2026, 1:49:13 AMpubliccompleted

This website contacted 3 IPs in 1 country across 2 domains to perform 12 HTTP transactions. The main domain is noticeofpleadings.net and was registered 1 year 11 months ago.

Submitted URL: https://passimovrt.cfd/api

Effective URL:

https://www.noticeofpleadings.net/lumma/domainseizurenotice.htm
Redirected

AI Security Verdict

Low Risk

Confidence: 88%

3
Risk Score

Fake Microsoft 'domain seized' page on malware infrastructure tied to Lumma Stealer; flagged URL and domain are known stealer distribution. Do not interact.

Risk Factors (4)
Fake Microsoft domain-seizure notice used as a lure on non-Microsoft infrastructure
Lumma Stealer malware-family indicators on the scanned URL and primary domain
Redirect from a .cfd domain to an unrelated destination domain
ML classifier flags phishing/scam at non-trivial probability
Safety Factors (3)
No credential, password or payment forms observed on the captured page
No JavaScript malware (YARA) or behavioral exfiltration signals detected in this capture
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 9 to 3
Domain age information unavailable

Details

Page Title

This website domain has been seized by Microsoft

Scan Type

public

Domain Name Analysis

Domain 'passimovrt.cfd' uses the .cfd top-level domain. The core label 'passimovrt' covers 10 characters containing 3 vowels alongside 7 consonants. Segmentation suggests 3 words: pass, imov, rt. Average segment length settles at 4 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://passimovrt.cfd/api

Page Load Overview

28.00s
Total Load Time
2.7 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:56%
Script:Latin
Direction:ltr

Detection Details

Text Length:1,000 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software71% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
71%
corporate business
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
440.91.108.115Azure · CLOUDUnited States
AS8075Microsoft Corporation
4150.171.110.53Azure · CLOUDUnited States
AS8075Microsoft Corporation
4150.171.109.104Azure · CLOUDUnited States
AS8075Microsoft Corporation
123--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CFA17601E5D5762BB04284C056273FA53BC84107C36E89A4B5E563AD1FC7CD6C6B3798

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

96:qewe5LfAnARZab+1wJDkev3oa5Zwj3yAWuo6OXpryDv8UV3m:qeBtfPRd6wa5XI8UV2

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:4766:AMAABIFgBiABCeAICjAgEIAWAlIIQBAgAAAAACAKIYIgAEEgggwgQDBAgAJcIKJBAmBAAEIQgACAAQwCwQRAYgLIgRBgQAPg

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e700ff0fffffffff
Perceptual Hash:b33266e6b2b3a2c4
Difference Hash:0c22313900080008
Wavelet Hash:e7000000ffffff81
Color Hash:#ac5396

Scan History

Scan history not available

Unable to load historical scan data