Security Scan Report: office-365-msn--oficeer.replit.app

Submitted: Sep 15, 2026, 4:50:08 AMCompleted: Sep 15, 2026, 4:50:34 AMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 88%

5
Risk Score

Microsoft-branded phishing page on a typosquatted Replit subdomain that forwards to another lookalike domain to harvest credentials. Do not enter any details.

Risk Factors (5)
Brand impersonation of Microsoft on a non-Microsoft domain
Typosquatted/deceptive subdomain imitating Office 365 and MSN
Form action posts credentials to a separate external lookalike domain (20260utlookmsn.vercel.app)
Single-purpose credential-collection landing page with no legitimate Microsoft content
Hosted on a free instant-publishing platform used to evade domain-age reputation
Safety Factors (4)
No password, email, or payment fields detected in the captured DOM snapshot
No threat-intelligence Indicators of Compromise matched
No JavaScript YARA malware patterns or behavioral exfiltration signals detected
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 8 to 5
Domain age information unavailable

Details

Page Title

Iniciar

Scan Type

public

Domain Name Analysis

The domain 'office-365-msn--oficeer.replit.app' uses the application-focused generic top-level domain (.app); it also runs on subdomain 'office-365-msn--oficeer'. Its registrable label 'replit' stretches across 6 characters with 2 vowels and 4 consonants. Breaking it apart gives 2 words: rep, lit. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://office-365-msn--oficeer.replit.app/

Page Load Overview

1.49s
Total Load Time
304 KB
Total Size

Language Analysis

Primary Language

🇪🇸Spanish
Code: es
Confidence:50%
Script:Latin
Direction:ltr

Detection Details

Text Length:219 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software41% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
41%
documentation technical
28%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
535.190.3.23Google · CDNKansas City, Missouri, United States
AS396982Google LLC
234.117.33.233Google · CDNKansas City, Missouri, United States
AS396982Google LLC
2142.251.13.95Google · CDNUnited States
AS15169Google LLC
2142.251.14.94Google · CDNUnited States
AS15169Google LLC
114--

Detected Technologies4

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T17D4140C28CE30886A2036198B2C7B90927D5D903921ADC107BFD52798FC9B9DC4AB75D

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:s84Mwe40PYmDnvYDGR3g3itqr1EvobD6/UceaMpHNB:94Mx40xwStqryvo6cccptB

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1939:AAAAAGACARAAAAAABAAIAACBAAAKAAhABAAAAEBQAgAAAABAAAgQABAACAAAAAQQAIAUABQADQAIAARARAIAAAAAAAgAERAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:f0f8fc9abd250d3e
Perceptual Hash:c3cc4562dd297789
Difference Hash:e2b0b03a698dd9dc
Wavelet Hash:f0f8dc18b9211d3e
Color Hash:#60ac53

Other Hashes

Crop Resistant:e2b0b03a698dd9dc

Scan History

Scan history not available

Unable to load historical scan data