Security Scan Report: rucorovibo.z1.web.core.windows.net

Redirected to:
https://rucorovibo.z1.web.core.windows.net/xyhq7/alchemister/amerlesse...
Site favicon
Submitted: Sep 14, 2026, 2:24:24 PMCompleted: Sep 14, 2026, 2:24:45 PMpubliccompleted

This website contacted 4 IPs in 2 countries across 4 domains to perform 26 HTTP transactions. The main domain is rucorovibo.z1.web.core.windows.net and was registered 2 weeks ago.

Submitted URL: https://rucorovibo.z1.web.core.windows.net/xyhq7/

Effective URL:

https://rucorovibo.z1.web.core.windows.net/xyhq7/alchemister/amerlesse...
Redirected

AI Security Verdict

High Risk

Confidence: 82%

8
Risk Score

Fake Microsoft Defender/Windows security alert on a cloud-storage subdomain, with obfuscated title, hostile .top domain traffic and a phishing-flagged URL shortener — a tech-support scam.

Risk Factors (5)
Impersonation of Microsoft security/support branding on a mismatched cloud-storage domain
Fake antivirus/Defender alert pressuring users to call a support number
Obfuscated page title using invisible characters and fabricated error codes
HIGH IDS alerts for hostile *.top domain traffic
Third-party resource iplog.co reported as phishing
Domain age information unavailable

Details

Page Title

‌ ‍ ‍0x800402 ‌ ‍ ‍0xE00160 ‌ ‍ ‍0xB00248​ ​ ​ ‍‌ ​ ‌ ‌ ‍  ‍‌ ‌

Scan Type

public

Domain Name Analysis

You're looking at domain 'rucorovibo.z1.web.core.windows.net' on the network infrastructure generic top-level domain (.net); it also runs on subdomain 'rucorovibo.z1.web.core'. The registrable portion 'windows' spans 7 characters containing 2 vowels alongside 5 consonants. Breaking it apart gives one word: windows. Expect seven characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://rucorovibo.z1.web.core.windows.net/xyhq7/

Page Load Overview

2.35s
Total Load Time
1.4 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:86,953 chars
Detector Agreement:75%

Website Classification

Primary Category

healthcare medical80% confidence
Type: spa
Method: ml+structural

All Detected Categories

healthcare medical
80%
news media journalism
63%
cryptocurrency blockchain
59%
education learning
58%
finance banking
56%

Detected Features

OG: website
Schema.org

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
857.150.59.36Azure · CLOUDSweden
AS8075Microsoft Corporation
6172.67.187.61Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6104.17.25.14Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6188.114.97.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
264--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17C346B57E71433770BA3006676995B97A93BC12A321A0D4070DC817C7B9ECEC937B3AA

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6144:FfLsLSeaGe385T9dU6BRxmYBPrXhAOxNOJ:BKxaGeiiOxAJ

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:249254:YroBUAZxICuKRLABxHoIXAyQsaAg5HQHFaADMEYIRFEAHMDCQEKBRCCRrJ6NsOAYICkAAqoAEMWRA4AE4FA8NKhgA4g3OLgN

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ff28383838e7ffff
Perceptual Hash:c34bb4b0ccbcb4c9
Difference Hash:61c9e0e0e10e0f61
Wavelet Hash:fc0038382803ffff
Color Hash:#90ac53

Scan History

Scan history not available

Unable to load historical scan data