Scan report · 26 days agoPublic

webmail.hanz.health.nz

185.125.84.79AS16509 · NZ

the page presents itself as Microsoft and asks the visitor for a password

Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 11.9 s · 5 requests
01 · Visitor openswebmail.hanz.health.nz
02 · Redirected · 3 hopsSame host, another address/OWA/auth/logon.aspx?replace…ail.hanz.health.nz%2fowa%2f
03 · Page shown
Outlookstyled as Microsoft · high
04 · OutcomeCredential phishingA login page wearing a brand it does not own.

Be careful — warning signs found

Automated

It presents itself as Microsoft while being hosted somewhere Microsoft does not own. It asks you to enter a password. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
SupportingBrand impersonation detected
Microsoft · high

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteHigh confidence: brand keywords AND a password field — classic credential phishing.

Infrastructure

IP
185.125.84.79AMAZON-02 - Amazon.com, Inc., US · AS16509NZ
TLS
CN=Entrust OV TLS Issuing RSA CA 2, O=Entrust Limited, C=CA · expires Oct 14, 2026
Redirects
3 hops · / → /OWA/auth/logon.aspx?replace…ail.hanz.health.nz%2fowa%2f
2 malicious9 suspicious

Hashes & fingerprints

Page capture

Live

Title “Outlook” · brand shown: Microsoft (high)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Outlook
Load
11.88 s · 5 requests
Stack · 2Microsoft ASP.NETOutlook Web App