Security Scan Report: enterpriseenrollment.personalcreations.com

Redirected to: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019c1a79-6395-7df0-8455-0905eb56d6d0&response_mode=fragment&client_info=1&nonce=019c1a79-6397-7cb4-a9bb-28e5f18ac713&state=eyJpZCI6IjAxOWMxYTc5LTYzOTctNzZhNy1iNzg4LWJkNzYyMTk4ZTlhNSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=_S_BUy-fTxmilwNcKCJ7g6E9ciNQvmFhr8FxvlL9ARk&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=true

Site favicon
Submitted: Feb 1, 2026, 6:31:24 PMCompleted: Feb 1, 2026, 6:32:38 PMpubliccompleted
Loading additional data...

Summary

This website contacted 6 IPs in 3 countries across 7 domains to perform 26 HTTP transactions. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://enterpriseenrollment.personalcreations.com

Effective URL: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019c1a79-6395-7df0-8455-0905eb56d6d0&response_mode=fragment&client_info=1&nonce=019c1a79-6397-7cb4-a9bb-28e5f18ac713&state=eyJpZCI6IjAxOWMxYTc5LTYzOTctNzZhNy1iNzg4LWJkNzYyMTk4ZTlhNSIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=4.21.0&response_type=code&code_challenge=_S_BUy-fTxmilwNcKCJ7g6E9ciNQvmFhr8FxvlL9ARk&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=trueRedirected

The Cisco Umbrella rank of the primary domain is #207,025 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Phishing login page impersonating Microsoft Azure on a low‑ranked domain – do not enter credentials.

Risk Factors
Credential harvesting form on non‑official domain
Brand impersonation of Microsoft on low‑ranked domain
Low Cisco Umbrella ranking for a domain claiming a major brand
Domain age information unavailable

Details

Page Title

Sign in to Microsoft Azure

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(78%)

Domain Information

The domain name 'enterpriseenrollment.personalcreations.com' uses the commercial generic top-level domain (.com); it also runs on subdomain 'enterpriseenrollment'. Count 17 characters in 'personalcreations' with seven vowels and ten consonants. Splitting it apart reveals 2 words: personal, creations. Median word length is 8.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://enterpriseenrollment.personalcreations.com

Page Load Overview

1.75s
Total Load Time
26
HTTP Requests
8
Domains
494 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software78% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
78%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
620.91.147.72Ireland
4150.171.84.26United States
AS8075Microsoft Corporation
420.190.160.66NetherlandsUnknown
420.189.173.18UnknownUnknown
420.190.159.71UnknownUnknown
413.107.246.45UnknownUnknown
266--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1D2835BEA7EB71937878A4575A8B57E02AE3A4D03984CC964F14CCC842FF675D8137253

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:sr8GLGGi/6K6u0m7ozTEyqU6MVnvnaloMPbzEfiitZ6+1:O8R/6k7XyS2TT1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:85847:Ei0C14AwEETBEQAQQQRiWBAUglgVKxGlK6dIQFgJUjohAEiIKSRYOWgArXKMiIAIACHDAigAACRqISUDI0jAAisIIoIAyJ6h

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003e3f3f373fff00
Perceptual Hash:85d970f626d919e4
Difference Hash:c8e2d2d2e4cae6e7
Wavelet Hash:003a3b3f373f7700
Color Hash:#c587b7

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data