Security Scan Report: pop3.zoominternet.net

Redirected to:
https://authorize.agoc.com/u/login/identifier?state=hKFo2SBlUGc4alliUT...
Submitted: Jul 25, 2026, 7:16:43 PMCompleted: Jul 25, 2026, 7:19:05 PMpubliccompleted

Summary

This website contacted 2 IPs in 1 country across 5 domains to perform 2 HTTP transactions. The main domain is authorize.agoc.com and was registered 30 years ago.

Submitted URL: https://pop3.zoominternet.net

Effective URL: https://authorize.agoc.com/u/login/identifier?state=hKFo2SBlUGc4alliUTRUcWNIX3JRZXF4M2JKU2RIZ2pualEtWqFur3VuaXZlcnNhbC1sb2dpbqN0aWTZIHNNRmpWX2Z5VDhrUzVKM3EzcGNWYndvWTU0SFhPaU04o2NpZNkga0JWQ1R4a3hHTzU2blh5NTJnV0NBZ2hzR1ZFRGtBcXARedirected

The Cisco Umbrella rank of the primary domain is #81,961 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 75%

3
Risk Score

The site harvests credentials while impersonating the Armstrong brand on an unrelated, old domain – high risk of phishing.

Risk Factors
Credential collection on a non‑official brand domain
Cross‑domain redirect to a different domain
Brand impersonation without official branding
Safety Factors
No malicious IoC matches
No JavaScript malware patterns detected
No network IDS alerts
Top-ranked domain (Cisco Umbrella #81,961, 11217 days old) with no strong malicious indicators — a login form on a household-name site is normal; risk clamped from 8 to 3
Domain age information unavailable

Details

Page Title

Log in

Scan Type

public

Language

🇺🇸

English

(58% confidence)

Category

government public service

(47%)

Domain Information

Domain 'pop3.zoominternet.net' uses the network infrastructure generic top-level domain (.net); it also runs on subdomain 'pop3'. Its registrable label 'zoominternet' stretches across 12 characters containing five vowels alongside 7 consonants. Splitting it apart reveals two words: zoom, internet. Median word length is 6 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of agoc.com

Page Load Overview

75.13s
Total Load Time
11
HTTP Requests
5
Domains
7 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:58%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:58%
Script Type:Latin
Text Length:179 chars
Detector Agreement:100%

Website Classification

Primary Category

government public service47% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

government public service
47%
finance banking
45%
news media journalism
43%
real estate property
39%
healthcare medical
34%

Detected Features

Login Form

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6193.122.169.252Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
5129.159.124.34Oracle · CLOUDAshburn, Virginia, United States
AS31898Oracle Corporation
112--

Page Statistics

11
Requests
5
Unique Domains
123.3 KB
Total Size

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F4331AD971E230731AA7107661DF604AB235A9439C0ECC00B4AEDAE05FBCB965F23E5D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:LKCabVtn9rCKIdcufLQXr+FKLK+KwVjU9gfj:eDn9rC/cuU+Frhg7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:54248:KnIsgUAKCx4UIEaSSggAyOZNAKMkiiCHCIoBTIBUopfK4NwJGaQDvEggRRawDMGQQUMYBCpZEXUkWAABBQYcKAAsJZgYAJDc

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7ffe7e7ffff
Perceptual Hash:b38ccc3333cc3333
Difference Hash:00000c004d0c0008
Wavelet Hash:3c3c24242727273f
Color Hash:#4062bf

Other Hashes

Crop Resistant:00000c004d0c0008

Scan History

Scan history not available

Unable to load historical scan data