servermailprotection-1sfinfomembers.s3.eu-west-1.amazonaws.com
52.92.35.178AS16509 · USthe page presents itself as Microsoft and asks the visitor for a password
- Browser Analysissuspicious
- Content Inspectionsuspicious
- Threat Intelligenceclean
- Network & Hostingclean
- Related Infrastructureclean
- TLS Fingerprintunknown
- Domain Intelligenceunknown
What happened
Step by step, from what the scanner recorded.Be careful — warning signs found
AutomatedIt presents itself as Microsoft while being hosted somewhere Microsoft does not own. It asks for a password in a sign-in box that stays hidden in the page until you click — so the request only appears once you interact with it. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.
What to do
Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.
"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.
Findings
Strongest firstOur Content Inspection engine downloaded the file this URL serves and analyzed it. The payload shows traits commonly seen in malware. Treat it as unsafe until verified.
Success
SHA-256 b9a9cdab8f4f0ff7a01512e566d190bcfc0bafb3d8087d7c68fed3c787e53aa4
The page presents itself as a known brand (brand keywords/branding detected).
Analyst noteHigh confidence: brand keywords AND a password field — classic credential phishing.
The brand fired at high confidence on a credential page, so the page was checked against the brand's self-hosted products (server fingerprint, the product's own credential sink on this host, return address, the organisation's mail records). It did not pass: refused: no server fingerprint of a Microsoft self-hosted product among 2 detected technologies
Analyst noteAn ordinary clone: the brand is on the page but the server is not the brand's product, or the credentials leave for somewhere that is not the product's own endpoint. Read the brand impersonation card below.
File
Stored by the engineWhat you download may be live malware. Open it only in an isolated environment, and do not double-click it.
The ZIP is encrypted. Password:infected
Inside the ZIP the file carries a name the engine generated, not the one the page used.
Downloaded fileSuspiciousThe engine stored it under a generated name
SHA-256b9a9cdab8f4f0ff7a01512e566d190bcfc0bafb3d8087d7c68fed3c787e53aa4
Fromhxxps://servermailprotection-1sfinfomembers[.]s3[.]eu-west-1[.]amazonaws[.]com/log[.]html#ssa@microsoft[.]com
Infrastructure
- IP
- 52.92.35.178AMAZON-02 - Amazon.com, Inc., US · AS16509US
- TLS
- CN=Amazon RSA 2048 M04, O=Amazon, C=US · expires Nov 6, 2026
Hashes & fingerprints
Page capture
LiveTitle “Microsoft E-mail Service” · brand shown: Microsoft (high)
Engines
7 · time to verdictPage
- HTTP
- 200 · Completed
- Title
- Microsoft E-mail Service
- Load
- 8.99 s · 3 requests