Security Scan Report: auth.properties

Site favicon
Submitted: Sep 22, 2026, 1:45:05 AMCompleted: Sep 22, 2026, 1:45:27 AMpubliccompleted

This website contacted 4 IPs in 3 countries across 2 domains to perform 2 HTTP transactions. The main domain is auth.properties and was registered 15 years ago.

Submitted URL: https://auth.properties/E.rU-TDP5DOv4?/microsoftonline/mailbox/upgrade&userid=75468973984785978212312307887543

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Fake Microsoft sign-in page on the unrelated domain auth.properties that harvests email/password credentials with a pre-filled victim address. Brand impersonation plus credential capture — do not enter any credentials.

Risk Factors (4)
Impersonation of Microsoft brand on a non-Microsoft domain
Login form collecting email and password credentials
Unranked domain not registered to the impersonated brand
Pre-filled target email address indicating a targeted phishing campaign
Domain age information unavailable

Details

Page Title

Sign in to your Microsoft account

Scan Type

public

Domain Name Analysis

Domain 'auth.properties' uses the .properties top-level domain and has no subdomain. The core label 'auth' covers 4 characters holding two vowels versus 2 consonants. Word splitting yields two words: au, th. Average segment length settles at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://auth.properties/E.rU-TDP5DOv4?/microsoftonline/mailbox/upgrade&userid=75468973984785978212312307887543

Page Load Overview

1.25s
Total Load Time
38 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:627 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software68% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
68%
documentation technical
43%
government public service
35%
adult content
32%
healthcare medical
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2212.104.128.0Cloudflare · CDNFinland
AS13335Cloudflare, Inc.
0146.75.121.137Fastly · CDNFrankfurt am Main, Hesse, Germany
AS54113Fastly, Inc.
0212.104.128.3Cloudflare · CDNFinland
AS13335Cloudflare, Inc.
0104.16.79.6Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
24--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1FAD3F77A4183157C8B1E783AB6EB2D003FE191034953D9A4B7EC46B48F0A9E1569D3EF

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:DxifuNadm9uwUdW5UfkGKF0qd8SlWIYOQ1rt+p2sE62eydXRjKRrsoqW/f:+u2mowUdLkNF0e8SlWBQyWf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:137214:ICAByETQnDEAyiSJACLgTRYwCBBgBQQoMoCBATpQHkqQCWAJBQpAUMGACMCOEgtICgpbI8RBgQFBApWRgDlhALTJEIFAwNqs

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000393b37373737
Perceptual Hash:845971764699d96e
Difference Hash:88e4f2d3e5eee6e6
Wavelet Hash:00003b3b373f373f
Color Hash:#9653ac

Other Hashes

Crop Resistant:88e4f2d3e5eee6e6

Scan History

Scan history not available

Unable to load historical scan data