Scan report · 13 days agoPublic

security-server-landing-page--spencer-hunt1.replit.app

34.117.33.233AS396982 · US

the page matches the catalogued phishing kit "Microsoft tenant-branding harvester (revisasen xx/)"

it requested that kit's own files from the kit's infrastructure
Verdict

Dangerous — confirmed threat

Automated

It asks you to enter a password. Its page code matches a known phishing kit (brand-clone). We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
StrongKnown phishing-kit signature matched
Microsoft tenant-branding harvester (revisasen xx/) · brand-clone · high

The page's structure/assets match a catalogued phishing kit — pre-built attacker software for cloning a brand's login.

Analyst noteKit rated high and flagged for auto-escalation — treat as malicious.

SupportingPage matches a protected brand's fingerprint
Microsoft · logoPhash d=0 (60) + credentialForm (15) · confidence 75

This page's fingerprint — its logo, screenshot, favicon, page structure or scripts — matches a brand's protected baseline, and the page is served from a host that brand does not own. The baseline's owner has been alerted separately.

Analyst noteThe strongest shape this matcher knows: the page serves the brand's own logo file byte-for-byte (Hamming 0) AND asks for a credential, on a host the brand does not own. A review page or a partner page carries the same asset; it does not ask for the password. Check where the form posts.

File

The file was not analysed, so the scan carries no verdict on the file itself.

Infrastructure

IP
34.117.33.233GOOGLE-CLOUD-PLATFORM - Google LLC, US · AS396982US
TLS
CN=WR3, O=Google Trust Services, C=US · expires Dec 1, 2026
18 malicious16 suspicious

Hashes & fingerprints

Page capture

Live

Title “Sign in to your account”

Engines

9 · time to verdict

Page

HTTP
200 · Completed
Title
Sign in to your account
Load
1.36 s · 8 requests
Stack · 8Google Cloud CDNGoogle Cloud Load BalancingGoogle Cloud TraceHSTSHTTP/3jQuery