Security Scan Report: creditsafe.167.235.134.13.sslip.io

Redirected to:
https://login.microsoftonline.com/eec3c7b7-a8b0-43c7-be4b-b44925652963...
Site favicon
Submitted: Sep 24, 2026, 7:14:20 AMCompleted: Sep 24, 2026, 7:15:00 AMpubliccompleted

This website contacted 9 IPs in 2 countries across 6 domains to perform 18 HTTP transactions. The main domain is login.microsoftonline.com and was registered 31 years ago.

Submitted URL: http://creditsafe.167.235.134.13.sslip.io/

Effective URL:

https://login.microsoftonline.com/eec3c7b7-a8b0-43c7-be4b-b44925652963...
Redirected

The Cisco Umbrella rank of the primary domain is #479,547 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 55%

2
Risk Score

Redirects to a genuine Microsoft sign-in via OAuth, so no credential theft occurs. However, the flow is launched from a dynamic-DNS IP host named 'creditsafe', which is atypical and warrants caution before granting consent.

Risk Factors
OAuth authorization request originates from a dynamic-DNS (sslip.io) subdomain bound to a raw IP address rather than a normal hosted domain
Third-party OAuth application redirecting credentials/session authorization to a self-hosted callback on an IP-based domain
Name 'creditsafe' used on a non-Creditsafe domain raises brand-misuse concerns
Safety Factors
Final landing page is the genuine login.microsoftonline.com domain, not a lookalike
SSO flow judged legitimate; no credential exfiltration or cross-origin JS data sinks
No Indicators of Compromise, no YARA malware patterns, no kit-roster match, no Safe Browsing threat
OAuth scopes requested are minimal (openid, email, profile)
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 5 to 2
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Domain Name Analysis

Within the British Indian Ocean Territory country-code top-level domain (.io), 'creditsafe.167.235.134.13.sslip.io' is registered, featuring subdomain 'creditsafe.167.235.134.13'. Count 5 characters in 'sslip' containing 1 vowel alongside four consonants. Word splitting yields two words: s, slip. Average segment length settles at 2.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://creditsafe.167.235.134.13.sslip.io/

Page Load Overview

2.98s
Total Load Time
472 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:109 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software79% confidence
Type: webapp
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
79%
social media network
28%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
240.126.32.138Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
2167.235.134.13Nuremberg, Bavaria, Germany
AS24940Hetzner Online GmbH
223.207.210.132Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
220.190.160.14Azure · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
240.126.32.136Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
223.207.210.136Akamai · CDNFrankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
220.190.160.67Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
240.126.32.134Office365 · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
252.178.17.234Azure · CLOUDAmsterdam, North Holland, Netherlands
AS8075Microsoft Corporation
189--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1F4235CE63FD4341B8B8324B1C4BEBB06D67959634858DC84F19CC94D2EBABEA4637113

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:jCzhizhU8J7QLG2RDzhl6oIZfzhudQsSaHWKS0NZTj8Z9TjuvhCknmaprVvPoML+:jCFiFU8GLG2dFEZfFudRWIZTIZ9Tjuol

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:45823:EGCmooAxAYIgJGIUPSgyCuKaELBCBhqMpAB0BkGQCAAjAMgAAgaI4KGNYUS0SQQBQGwuQ9GIACDCWkVxxUIEAwTELGoS9BTB

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0010393b373f3737
Perceptual Hash:845971764699d96e
Difference Hash:88e4d2d3e5eee6e6
Wavelet Hash:00003b3b373f373f
Color Hash:#d22d69

Other Hashes

Crop Resistant:88e4d2d3e5eee6e6

Scan History

Scan history not available

Unable to load historical scan data