Security Scan Report: enterpriseenrollment.csaa.com

Redirected to:
https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?...
Site favicon
Submitted: May 29, 2026, 12:43:22 PMCompleted: May 29, 2026, 12:44:30 PMpubliccompleted

This website contacted 2 IPs in 2 countries across 8 domains to perform 26 HTTP transactions. The main domain is login.microsoftonline.com and was registered 24 years ago.

Submitted URL: https://enterpriseenrollment.csaa.com

Effective URL:

https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?...
Redirected

The Cisco Umbrella rank of the primary domain is #693,901 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 72%

2
Risk Score

The site mimics Microsoft branding and contains a login form, but its age and lack of malicious indicators keep the risk at a moderate level.

Risk Factors (3)
Brand impersonation of a well‑known entity
Low reputation ranking for a brand‑claiming domain
High JavaScript obfuscation score
Safety Factors (4)
Domain age >30 years (well‑established)
Legitimate cross‑origin form submission to Microsoft login endpoint
No malicious IoC, YARA, or network IDS detections
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 5 to 2
Domain age information unavailable

Details

Page Title

Sign in to Microsoft Azure

Scan Type

public

Domain Name Analysis

You're looking at domain 'enterpriseenrollment.csaa.com' on the commercial generic top-level domain (.com); it also runs on subdomain 'enterpriseenrollment'. The second-level label 'csaa' is 4 characters long with two vowels and 2 consonants. Word splitting yields 2 words: csa, a. Expect 2 characters per word on average. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://enterpriseenrollment.csaa.com

Page Load Overview

1.11s
Total Load Time
897 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software77% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
77%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13150.171.84.49United States
AS8075Microsoft Corporation
1313.74.111.192Dublin, Leinster, Ireland
AS8075Microsoft Corporation
262--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1B4630845B3C2F032E9696AE4952514B1BB3D259F252DC904B2F847842F63ADDCDB3A0F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:2H3GEGsh95rJiZ1/Pxv/14BmgAQfYDIS60Kj:K3V55FizP9942QfYDs0Kj

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:71772:oZkzRxgcAEFBxCHQgBkgAAIQMAQL5lFCkRKEbipCqXkgmgCkKBAAQBRD4sdiwRkhRACJMFuGAEo6JoQ4eIADoppDpAAzQAAk

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003a3f3f373fff00
Perceptual Hash:85d970f626d919e4
Difference Hash:c8e2d2d2e4cae6e7
Wavelet Hash:003a3b3f373f7700
Color Hash:#86502d

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data