Security Scan Report: enterpriseenrollment.banpuindo.co.id

Redirected to:
https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?...
Site favicon
Submitted: Jun 24, 2026, 8:32:56 PMCompleted: Jun 24, 2026, 8:34:06 PMpubliccompleted
Loading additional data...

Summary

This website contacted 2 IPs in 2 countries across 2 domains to perform 1 HTTP transaction. The main domain is login.microsoftonline.com and was registered NaN years ago.

Submitted URL: https://enterpriseenrollment.banpuindo.co.id

Effective URL: https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=c44b4083-3bb0-49c1-b47d-974e53cbdf3c&scope=https%3A%2F%2Fmanagement.core.windows.net%2F%2F.default%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fintune.microsoft.com%2Fauth%2Flogin%2F&client-request-id=019efb56-08e8-7cbf-8c9a-39e79d907bc2&response_mode=fragment&client_info=1&clidata=1&nonce=019efb56-08e8-7cef-b7bd-904c5511dd5b&state=eyJpZCI6IjAxOWVmYjU2LTA4ZTgtN2RjMy1iZjQyLTg3YzM5NmRlMTk0ZCIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&x-client-SKU=msal.js.browser&x-client-VER=5.8.0&response_type=code&code_challenge=KYEXmwlNoMuAELCZNB_0K-UuaD75FGF1O8SDljL-SDo&code_challenge_method=S256&site_id=501430&instance_aware=true&sso_reload=trueRedirected

The Cisco Umbrella rank of the primary domain is #942,011 of the top 1 million websites

AI Security Verdict

Low Risk

Confidence: 92%

2
Risk Score

The site hosts a credential‑phishing login that impersonates Microsoft Azure and forwards credentials to Microsoft’s SSO endpoint; high confidence of scam.

Risk Factors
Brand impersonation of Microsoft
Credential collection form
Cross‑origin form submission to external SSO endpoint
Low domain reputation for brand claim
Safety Factors
Domain age > 20 years
No Indicators of Compromise matches
No YARA malware detections
No network IDS alerts
Page served from an identity-provider sign-in endpoint (login.microsoftonline.com); a relying-party brand and login form here are normal SSO, not impersonation — risk clamped from 10 to 2
Domain age information unavailable

Details

Page Title

Microsoft Intune admin center

Scan Type

public

Language

🇺🇸

English

(80% confidence)

Category

technology software

(77%)

Domain Information

You're looking at domain 'enterpriseenrollment.banpuindo.co.id' on the Indonesian country-code top-level domain (.co.id), featuring subdomain 'enterpriseenrollment'. The registrable portion 'banpuindo' spans 9 characters with 4 vowels and five consonants. Tokenizing the label suggests 3 words: ban, pu, indo. Average segment length settles at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://enterpriseenrollment.banpuindo.co.id

Page Load Overview

2.62s
Total Load Time
25
HTTP Requests
8
Domains
569 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

Language Code:en
Detection Confidence:80%
Script Type:Latin
HTML Lang Attribute:en
Text Length:187 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software77% confidence
Type: webapp
Method: ml+structural

All Detected Categories

technology software
77%

Detected Features

Login Form
Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13150.171.84.25United States
AS8075Microsoft Corporation
1213.74.111.192Dublin, Leinster, Ireland
AS8075Microsoft Corporation
252--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T150630946F382F032E9196ED4A51514B1BF3D259F212ED944B1F846842E63AD9CEB3A0F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

1536:gH3GlEpsh9540Kij1/qxv/1cB4n2q9GQZA:U3UEc54tiJq99c9q9bS

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:72519:AngUBAkAiUAAIBQI4AB5gCW5QILJkREVpUlgBp/RU5gAPgiYCBEMhJICBFAmWOlM48MkDCMlXwTwIAISABSAAcAokEMFcgFb

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:003a3f3f373fff00
Perceptual Hash:85d970f626d919e4
Difference Hash:c8e2d2d2e4cae6e7
Wavelet Hash:003a3b3f373f7700
Color Hash:#291f93

Other Hashes

Scan History

Scan history not available

Unable to load historical scan data