Security Scan Report: rb.tamg.io

Redirected to:
https://login.microsoftonline.com/cf3dc8a2-b7cc-4452-848f-cb570a56cfbf...
Site favicon
Submitted: Aug 22, 2026, 9:43:41 PMCompleted: Aug 22, 2026, 9:44:53 PMpubliccompleted

This website contacted 4 IPs in 4 countries across 7 domains to perform 17 HTTP transactions. The main domain is login.microsoftonline.com and was registered 8 years ago.

Submitted URL: https://rb.tamg.io

Effective URL:

https://login.microsoftonline.com/cf3dc8a2-b7cc-4452-848f-cb570a56cfbf...
Redirected

AI Security Verdict

Low Risk

Confidence: 92%

2
Risk Score

The site impersonates TripAdvisor and harvests credentials via a Microsoft SSO login, posing a high‑risk phishing threat.

Risk Factors
Brand impersonation of a well‑known company
Credential collection on a non‑official domain
Unranked domain with no reputation
Highly obfuscated JavaScript
Safety Factors
Form posts to a legitimate Microsoft SSO endpoint
No Indicators of Compromise or YARA malware matches
No network IDS alerts
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 8 to 2
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Domain Name Analysis

You're looking at domain 'rb.tamg.io' on the British Indian Ocean Territory country-code top-level domain (.io), featuring subdomain 'rb'. The second-level label 'tamg' is 4 characters long containing 1 vowel alongside three consonants. Breaking it apart gives 2 words: tam, g. Median word length comes out to 2 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://rb.tamg.io

Page Load Overview

2.84s
Total Load Time
696 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:177 chars
Detector Agreement:67%

Website Classification

Primary Category

corporate business42% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

corporate business
42%
travel tourism
34%
social media network
34%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
540.126.32.76Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
440.126.31.69Office365 · CLOUDDublin, Leinster, Ireland
AS8075Microsoft Corporation
454.236.154.48Aws · CLOUDAshburn, Virginia, United States
AS14618Amazon.com, Inc.
423.207.210.132Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
174--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1CC234AEA3F883427CB87657484AFBB06D57D49538888CCC8F2DDC8495DB9BDA4627207

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:jjAL8J7QLG2RErxrsjutA0rMrYt1r7OrLoSaNyqt0NWTj8Z9TjuvhCknmaprVvPd:jjAL8GLG2O9YIA0wMt1vO+ya8WTIZ9Ti

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:45932:HCBMEM7FzpCGABwEToEBLAShAKsKSGaBggJIEtxlAAgIDQwAM4HYQRIzHC5AIwiihA0CAHBsRDGBmAAdqx1BRAM4KAxCA1gI

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:001f7fffff180000
Perceptual Hash:98cd36c3ac13d999
Difference Hash:dcf0b2b2b2b0e8ac
Wavelet Hash:043f7fffff180000
Color Hash:#1f9361

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data