Scan report · 22 days agoPublic

servermailprotection-1sfinfomembers.s3.eu-west-1.amazonaws.com

52.92.35.178AS16509 · US

the page presents itself as Microsoft and asks the visitor for a password

Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 9.0 s · 3 requests
01 · Visitor opensservermailprotection-1sfinfomembers.s3.eu-west-1.amazonaws.com/log.html
02 · Page shown
Microsoft E-mail Servicestyled as Microsoft · high
03 · OutcomeCredential phishingA login page wearing a brand it does not own.

Be careful — warning signs found

Automated

It presents itself as Microsoft while being hosted somewhere Microsoft does not own. It asks for a password in a sign-in box that stays hidden in the page until you click — so the request only appears once you interact with it. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
Suspicious fileSuspicious content in the downloaded file
1a161c12-2aa1-4424-844f-72a67698ef80.com

Our Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.

Success

SHA-256 b9a9cdab8f4f0ff7a01512e566d190bcfc0bafb3d8087d7c68fed3c787e53aa4

SupportingBrand impersonation detected
Microsoft · high

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteHigh confidence: brand keywords AND a password field — classic credential phishing.

InfoSelf-hosted product check: no-fingerprint
no server fingerprint of the brand's own product

The brand fired at high confidence on a credential page, so the page was checked against the brand's self-hosted products (server fingerprint, the product's own credential sink on this host, return address, the organisation's mail records). It did not pass: refused: no server fingerprint of a Microsoft self-hosted product among 2 detected technologies

Analyst noteAn ordinary clone: the brand is on the page but the server is not the brand's product, or the credentials leave for somewhere that is not the product's own endpoint. Read the brand impersonation card below.

File

Stored by the engine

What you download may be live malware. Open it only in an isolated environment, and do not double-click it.

The ZIP is encrypted. Password:infected

Inside the ZIP the file carries a name the engine generated, not the one the page used.

Downloaded fileSuspiciousThe engine stored it under a generated name

SHA-256b9a9cdab8f4f0ff7a01512e566d190bcfc0bafb3d8087d7c68fed3c787e53aa4

Fromhxxps://servermailprotection-1sfinfomembers[.]s3[.]eu-west-1[.]amazonaws[.]com/log[.]html#ssa@microsoft[.]com

Infrastructure

IP
52.92.35.178AMAZON-02 - Amazon.com, Inc., US · AS16509US
TLS
CN=Amazon RSA 2048 M04, O=Amazon, C=US · expires Nov 6, 2026
3 malicious8 suspicious

Hashes & fingerprints

Page capture

Live

Title “Microsoft E-mail Service” · brand shown: Microsoft (high)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Microsoft E-mail Service
Load
8.99 s · 3 requests
Stack · 2Amazon S3Amazon Web Services