Security Scan Report: msoid.taxiforsberg.fi

Redirected to:
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_...
Site favicon
Submitted: Jul 28, 2026, 5:25:11 AMCompleted: Jul 28, 2026, 5:26:20 AMpubliccompleted
Loading additional data...

Summary

This website contacted 5 IPs in 3 countries across 5 domains to perform 2 HTTP transactions. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://msoid.taxiforsberg.fi

Effective URL: https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=639208131139685148.NzFmY2YyNTMtYzQ4My00YzkxLThmNjgtMTM3MGFlYWM5ZjM4M2IxM2VjMTgtOThkMy00YTdiLWE4OTgtZjcyYTBkZjNkMDhh&ui_locales=en-US&mkt=en-US&client-request-id=c742b3a7-7d17-4e60-8d8b-67ffe79638d8&state=wp0F2HlD8At_AYkkjyqgjt5LTlyb9nFWASJ1IYTBxbSB_9vDzJXUKlnStQulr66NLKYdiIOHDpRrQCOT4natoGDX09pI1YWWo74T-Bo2AiNWzXW2FuAdc4TRA3Smy6qJ_wCL41J3U5Zn8pulFaKsMvPmUE5O-an4QSYIDayWe7bEftdrcJk0s1hCtTzAUiIyedUPKFdb4s8Th1aYdjAD917iBbIOPn_uiCgw23tVrEj_Dhjw_KrfJkOMfmy1UIKPm0m0p1AHKLvQedbhp2cQW9KFKs-SGtS9Pz9pn74dNSUIghlWTPXIcwV-5leTMroepHwnpFS3Sj2RMDIty9fq8T7y4g6XlNhMMHB9uz5TZ0f8sMDj08M_FFaX5KF2yJObEv2p9m8IPvRL7fAYbbQJJrHUz7usicTsiXpspTxwEWk&x-client-SKU=ID_NET8_0&x-client-ver=8.16.0.0&sso_reload=trueRedirected

AI Security Verdict

Low Risk

Confidence: 80%

2
Risk Score

Phishing page impersonating Microsoft login; high risk due to brand impersonation and credential form.

Risk Factors
Brand impersonation of Microsoft
Credential collection form on unrelated domain
Unranked / low‑reputation domain
Safety Factors
No malware YARA matches
No network IDS alerts
Form posts to legitimate Microsoft endpoint (no exfiltration observed)
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 7 to 2
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(85%)

Domain Information

The domain 'msoid.taxiforsberg.fi' uses the Finnish country-code top-level domain (.fi) and includes subdomain 'msoid'. Its registrable label 'taxiforsberg' stretches across 12 characters containing 4 vowels alongside eight consonants. It segments into 2 words: taxi, forsberg. Average segment length settles at six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://msoid.taxiforsberg.fi

Page Load Overview

1.31s
Total Load Time
29
HTTP Requests
5
Domains
476 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:133 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software85% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
85%
social media network
40%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
940.126.31.129Office365 · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
523.103.241.26Frankfurt am Main, Hesse, Germany
AS8075Microsoft Corporation
595.100.135.34Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
540.126.32.134Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
520.190.160.64Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
295--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T123937CD67EE71933828A84B5B9763F029A3A59439C4CCD74F25CC9882FFA74D8027653

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:Fchj8GLG2GKXgpIR3qPsRBH5soRIZ9Tjuokmap5vPoMLufjC0fiiidvlC:6hj8cgpIRweZsRa/AN6llC

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:91313:CaBaJSBWEwaeQgANkgmFMEFOrAMZSCDkFgAagACiAHoASCJZIC1rwgQLBioHtiDJABCAZUQMCRMANUpIrCMFSKQAWiASAmCK

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0010393b373f3737
Perceptual Hash:845971764699d96e
Difference Hash:88e4d2d3e5e6e6e6
Wavelet Hash:00003b3b373f373f
Color Hash:#2dd259

Other Hashes

Crop Resistant:88e4d2d3e5e6e6e6

Scan History

Scan history not available

Unable to load historical scan data