Scan report · 29 days agoPublic

www.bleepingcomputer.com

172.66.139.132AS13335 · US

the page presents itself as Microsoft and asks the visitor for a password

Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 6.2 s · 155 requests
01 · Visitor openswww.bleepingcomputer.com/news/security/microsoft-hac…vice-code-phishing-attacks/
02 · Page shown
Microsoft: Hackers steal emails in device code phishing attacksstyled as Microsoft · high
03 · OutcomeCredential phishingA login page wearing a brand it does not own.

Be careful — warning signs found

Automated

It presents itself as Microsoft while being hosted somewhere Microsoft does not own. It asks you to enter a password. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
SupportingBrand impersonation detected
Microsoft · high

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteHigh confidence: brand keywords AND a password field — classic credential phishing.

InfoCross-domain scripts injected at runtime
14 script(s)

The page dynamically injected scripts from other domains. This is extremely common on legitimate sites (CDNs, analytics, asset domains) and is shown for context only.

Analyst noteNoisy by itself — a CDN/asset domain (e.g. a brand's own *.githubassets.com) is normal. Only meaningful if the source domain is unrelated/suspicious.

Infrastructure

IP
172.66.139.132CLOUDFLARENET - Cloudflare, Inc., US · AS13335US
TLS
CN=Sectigo Public Server Authentication CA DV R36, O=Sectigo Limited, C=GB · expires Oct 29, 2026

WHOIS

Registrar
GoDaddy.com, LLC
Created
Jan 26, 2004
Expires
Jan 26, 2027
Nameservers
leah.ns.cloudflare.commatt.ns.cloudflare.com
36 malicious9 suspicious

Hashes & fingerprints

Page capture

Live

Title “Microsoft: Hackers steal emails in device code phishing attacks” · brand shown: Microsoft (high)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Microsoft: Hackers steal emails in device code phishing attacks
Load
6.20 s · 155 requests
Stack · 16AMPBootstrapCloudflareDoubleClick Campaign Manager (DCM)DoubleClick FloodlightFancyBox