Security Scan Report: martins-bauer.com

Submitted: Sep 23, 2026, 2:02:56 PMCompleted: Sep 23, 2026, 2:03:32 PMpubliccompleted

AI Security Verdict

Moderate Risk

Confidence: 93%

5
Risk Score

Confirmed Microsoft SharePoint device-code phishing: a 0-day unranked domain impersonates SharePoint document sharing and pushes a one-time code to be entered at microsoft.com/devicelogin, hijacking victim accounts.

Risk Factors
Brand impersonation of Microsoft SharePoint on a domain that is not any Microsoft property
Device-code phishing flow directing victims to authorise account access
Brand-new domain (0 days old) with risk multiplier 3.0x
Domain absent from Cisco Umbrella top 1M
Deceptive file-sharing lure with urgency (code expires in 15 minutes)
Safety Factors
No HTML credential or payment form fields were present in the captured DOM (no password/payment inputs)
No Indicator of Compromise matches, JavaScript YARA patterns, or network IDS alerts were reported
Verdict cited a credential/login form, but DOM analysis found no password field (real or disguised) or payment field, and no other hard signal — credential-phishing framing unsupported; risk adjusted from 10 to 5
Domain age information unavailable

Details

Page Title

SharePoint — Documentssecondary capture

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'martins-bauer.com' is registered with no subdomain. Count 13 characters in 'martins-bauer' containing five vowels alongside 7 consonants; it also includes one hyphen. Word splitting yields two words: martins, bauer. Median word length is six characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://martins-bauer.com/

Page Load Overview

0.11s
Total Load Time
1 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:631 chars
Detector Agreement:100%

Website Classification

Primary Category

documentation technical42% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

documentation technical
42%
phishing scam
42%
technology software
37%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
2192.52.166.175United States
AS199959Gwy It Pty Ltd
015.197.225.128Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
03.33.251.168Aws · CLOUDUnited States
AS16509Amazon.com, Inc.
23--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15872DA31A351243EB03BC8D2B893A7CFB195D607D5234614FAAD32A4CFC6CD79A66748

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

384:VvsVnTH3mFNzLYAaOWd1kGssrR6oqnfutwJFcfuB1:YHcx9A1kGsmafut2FcfuB1

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:17149:AAFsgEiIGACYMZEByELsSrghkMIoSZ04AgimyGRQAEBiQJhWCA5wDmQnQIQCfEKSTEGAygkABABCUAODECEABAZmEoAF2IVl

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0f0fefffffe7e7e7
Perceptual Hash:b3193f379962e2c0
Difference Hash:78588cd8d8cccccc
Wavelet Hash:040e6f6f6f676620
Color Hash:#53ac7d

Other Hashes

Crop Resistant:78588cd8d8cccccc

Scan History

Scan history not available

Unable to load historical scan data