Security Scan Report: authenticate.tools.engine.alloyed.com

Redirected to: https://login.microsoftonline.com/4a71a66b-9528-4bfb-b5f5-adc541e1f9de/oauth2/v2.0/authorize?client_id=c8413d30-9aca-4532-8202-4655fda2e1d6&prompt=select_account&redirect_uri=https%3A%2F%2Fauthenticate.tools.engine.alloyed.com%2Foauth2%2Fcallback&response_type=code&scope=openid+profile+email+offline_access&state=YmNEaDF3NkJFUnpxNWZKT2xNWkJ2T1ZwL1pyZkxWNVlHajE5Yzk1Z0QxQUN1MTh6UDhnQnE1THRoSW1VNlVuZ1M4MHVYM2VSY2N2bjRqSjBWRVd5L3c9PXwxNzY3ODE3NDQzfNjzOtpeKSrZ9PuypbLiCm6j7o2cNM0z8UZTS6Q3ntJyIMEVALPYkosweN0gtMxNPSvBaLUC0tmCX2p7f-KyqN0j4M2IY_XQfeOHgL4_8_-X-A4odp0ZZdYyEuTlLTEzW3lLmAonCVhV82nMOMeu9R4a1yZc88b15QbGujoVtkpFhDRBfvuNwZQDMa0gCDTkyks8wZ8OCRe1jr18nExrP5aj_wl473dbTcq-rUcsAfeV8jLL0agr_FeCYQ68hU2v_tNP2hSmSqNweUgO4wVoLvIK0l9whjJl0UqsNkMJ7OE4NptfpL3MB7SyT2_SIV0R4O9t7O1tFWhJ0kzwwns216bH9jqxBnkfxnTc62roNuE49xSr6bSsHFgBj5pKp9cRvxH_TxYEzVAWKGOU04RVB7U80eA8QA38FTdglPdJeBSXu0NSat1zz7zP_iFEuDN3yyOPaoQZ1xmyPhT5Pxg%3D&sso_reload=true

Submitted: Jan 7, 2026, 8:23:54 PMCompleted: Jan 7, 2026, 8:25:17 PMpubliccompleted
Loading additional data...

Summary

This website contacted 7 IPs in 3 countries across 5 domains to perform 12 HTTP transactions. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://authenticate.tools.engine.alloyed.com/.pomerium/sign_in?pomerium_expiry=1767578852&pomerium_idp_id=D7MQwPfBXnWvEGJqV8GqP8VnwHrwfyGtYxLpZD2NhYz2&pomerium_issued=1767578552&pomerium_redirect_uri=https%3A%2F%2Fverify.engine.alloyed.com%2F&pomerium_signature=nga-s_aVXZPVHIh7amcG9KeQbqiQvbxE-4YbZuzrw9g%3D

Effective URL: https://login.microsoftonline.com/4a71a66b-9528-4bfb-b5f5-adc541e1f9de/oauth2/v2.0/authorize?client_id=c8413d30-9aca-4532-8202-4655fda2e1d6&prompt=select_account&redirect_uri=https%3A%2F%2Fauthenticate.tools.engine.alloyed.com%2Foauth2%2Fcallback&response_type=code&scope=openid+profile+email+offline_access&state=YmNEaDF3NkJFUnpxNWZKT2xNWkJ2T1ZwL1pyZkxWNVlHajE5Yzk1Z0QxQUN1MTh6UDhnQnE1THRoSW1VNlVuZ1M4MHVYM2VSY2N2bjRqSjBWRVd5L3c9PXwxNzY3ODE3NDQzfNjzOtpeKSrZ9PuypbLiCm6j7o2cNM0z8UZTS6Q3ntJyIMEVALPYkosweN0gtMxNPSvBaLUC0tmCX2p7f-KyqN0j4M2IY_XQfeOHgL4_8_-X-A4odp0ZZdYyEuTlLTEzW3lLmAonCVhV82nMOMeu9R4a1yZc88b15QbGujoVtkpFhDRBfvuNwZQDMa0gCDTkyks8wZ8OCRe1jr18nExrP5aj_wl473dbTcq-rUcsAfeV8jLL0agr_FeCYQ68hU2v_tNP2hSmSqNweUgO4wVoLvIK0l9whjJl0UqsNkMJ7OE4NptfpL3MB7SyT2_SIV0R4O9t7O1tFWhJ0kzwwns216bH9jqxBnkfxnTc62roNuE49xSr6bSsHFgBj5pKp9cRvxH_TxYEzVAWKGOU04RVB7U80eA8QA38FTdglPdJeBSXu0NSat1zz7zP_iFEuDN3yyOPaoQZ1xmyPhT5Pxg%3D&sso_reload=trueRedirected

AI Security Verdict

High Risk

Confidence: 92%

8
Risk Score

Phishing page impersonating Microsoft; high risk of credential theft.

Risk Factors
Brand impersonation (Microsoft) on an unranked domain
Credential harvesting form on a non‑official domain
Suspicious redirect to Microsoft login without being a known redirect service
Domain age information unavailable

Details

Page Title

Sign in to your account

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

unknown

(0%)

Domain Information

The domain 'authenticate.tools.engine.alloyed.com' uses the commercial generic top-level domain (.com) and includes subdomain 'authenticate.tools.engine'. The second-level label 'alloyed' is 7 characters long holding three vowels versus 4 consonants. Breaking it apart gives 1 word: alloyed. Median word length comes out to seven characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://authenticate.tools.engine.alloyed.com/.pomerium/sign_in?pomerium_expiry=1767578852&pomerium_idp_id=D7MQwPfBXnWvEGJqV8GqP8VnwHrwfyGtYxLpZD2NhYz2&pomerium_issued=1767578552&pomerium_redirect_uri=https%3A%2F%2Fverify.engine.alloyed.com%2F&pomerium_signature=nga-s_aVXZPVHIh7amcG9KeQbqiQvbxE-4YbZuzrw9g%3D

Page Load Overview

9.76s
Total Load Time
12
HTTP Requests
5
Domains
295 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:128 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: webapp
Method: structural

All Detected Categories

No categories detected

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
652.203.241.203Ashburn, Virginia, United States
AS14618AMAZON-AES
123.207.210.137Frankfurt am Main, Hesse, Germany
AS20940Akamai International B.V.
140.126.31.2Dublin, Leinster, Ireland
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
113.107.246.44United States
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
120.190.159.2Dublin, Leinster, Ireland
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
140.126.31.128Dublin, Leinster, Ireland
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
140.126.31.3Dublin, Leinster, Ireland
AS8075MICROSOFT-CORP-MSN-AS-BLOCK
127--

Detected Technologies6

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T105836CEA7E775937878645B5B4B63D02AF3A5A038D4CCDA4F04CC9842FFA60D812B653

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:Feew8GLGGfG+0tJWoxzTEyqU6MVnvnaloMPU1ESiicC:M8D/JWvyS26C

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:86356:GpMACjBEDmCSMgpDSCrAk8rKaPEIAI1hE4BGiHfAjwQAGEunAAgIHJQMCGkg4L+6AABECJlRDjAmERdB2VzQJEAUjBRAgBw2

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:00103933372f3737
Perceptual Hash:8659517666d9d90b
Difference Hash:88e4d2e7e5cee6e6
Wavelet Hash:00203b33373f373f
Color Hash:#a487c5

Other Hashes

Crop Resistant:88e4d2e7e5cee6e6

Scan History

Scan history not available

Unable to load historical scan data