Security Scan Report: auth.properties

Site favicon
Submitted: Sep 30, 2026, 12:45:32 PMCompleted: Sep 30, 2026, 12:46:44 PMpubliccompleted

This website contacted 3 IPs in 2 countries across 2 domains to perform 2 HTTP transactions. The main domain is auth.properties and was registered 15 years ago.

Submitted URL: https://auth.properties/E.PxCeyvJg-GyX6TZN?/microsoftonline/mailbox/upgrade

AI Security Verdict

Confirmed Scam

Confidence: 97%

10
Risk Score

Confirmed Microsoft credential-phishing page: Microsoft-branded sign-in on the unrelated, unranked domain auth.properties, flagged by Google Safe Browsing for social engineering. Never enter credentials.

Risk Factors (5)
Brand impersonation of Microsoft on an unrelated domain
Credential-harvesting login form (email + password)
Google Safe Browsing Social Engineering detection
Deceptive URL path mimicking /microsoftonline/mailbox/upgrade
Unranked, non-Microsoft domain hosting a Microsoft-branded sign-in page
Domain age information unavailable

Details

Page Title

Sign in to your Microsoft account

Scan Type

public

Domain Name Analysis

Domain 'auth.properties' uses the .properties top-level domain and has no subdomain. The registrable portion 'auth' spans 4 characters split between two vowels and two consonants. Breaking it apart gives 2 words: au, th. The median word length lands at 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://auth.properties/E.PxCeyvJg-GyX6TZN?/microsoftonline/mailbox/upgrade

Page Load Overview

6.24s
Total Load Time
33 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:627 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software68% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
68%
documentation technical
43%
government public service
35%
adult content
32%
healthcare medical
31%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2212.104.128.2Cloudflare · CDNFinland
AS13335Cloudflare, Inc.
0104.16.78.6Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
0212.104.128.0Cloudflare · CDNFinland
AS13335Cloudflare, Inc.
23--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F2D3F77A4183157C8B0E7836B6EB2D003FE191034953D9A4B7EC46B88F0A9E1569D3EF

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:DxifuNadm9uwUdW5UfkGKF0qd8SlWIYOQ1rt+p2sE62e7bRXJdRrsoqW/f:+u2mowUdLkNF0e8SlWBQ7Rf

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:137116:gkB8wjnEw+IMlCQ4AYTIymDcABSEFAAqCFIPIiiSExVAAaCWVGiBQAGySBiyIT4ZAIRBNqSQACSD3gZXjMbFOSoNcANCkBWA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0010293b37373737
Perceptual Hash:8559746646b9596e
Difference Hash:88e4d2dbe5e6e6e6
Wavelet Hash:00202b3b373f373f
Color Hash:#836ce0

Other Hashes

Crop Resistant:88e4d2dbe5e6e6e6

Scan History

Scan history not available

Unable to load historical scan data