Scan report · 13 days agoPublic

storage.googleapis.com

216.58.201.219AS15169 · US

this page offers the visitor no link at all, yet its own script carries the address www.

a different site from the one being visitedand navigates there with what the visitor types. A page whose only destination is somewhere else is a hand-off, not a document
Verdict

Be careful — warning signs found

Automated

It shows Microsoft's own website, www.microsoft.com, in a full-screen frame behind its sign-in box, on an address Microsoft does not own — the page itself never says Microsoft anywhere. It asks you to enter a password. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

This verdict rests on other evidence: the site never showed us its own page, so its content was not assessed. Re-scan later or verify through a trusted channel.

Findings

Strongest first
InfoBrand impersonation detected
Microsoft · medium · www.microsoft.com framed full-screen behind the page

The page loads www.microsoft.com — the brand's OWN website — in a frame that covers the viewport, and puts its own sign-in box in front of it. The brand's name is written nowhere on the page, so nothing that reads text or image files could have seen it.

Analyst noteThe costume is a live frame of www.microsoft.com — not a keyword, not a logo file — so a kit can build it at runtime for any brand (this one reads the victim's own e-mail domain out of the URL fragment). Capped at medium by design: it labels what the page WEARS and never decides what it IS. Judge it by what the form collects and where that goes.

File

The file was not analysed, so the scan carries no verdict on the file itself.

Infrastructure

IP
216.58.201.219GOOGLE - Google LLC, US · AS15169US
TLS
CN=WR2, O=Google Trust Services, C=US · expires Nov 27, 2026
7 malicious52 suspicious

Hashes & fingerprints

Page capture

Live

brand shown: Microsoft (medium)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Load
11.47 s · 189 requests
Stack · 10Adobe Experience ManagerAzure Front DoorGoogle Cloud StorageGoogle Hosted LibrariesHTTP/3jQuery