Scan report · 3 days agoPublic

sistema365.dothome.co.kr

112.175.185.139AS4766 · KR
Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 10.2 s · 6 requests
01 · Visitor openssistema365.dothome.co.kr
02 · Page shown
Cuenta de Microsoft - Iniciar sesiónstyled as Microsoft · high
03 · Data sent todiscord.com/api/webhooks/<redacted>
04 · OutcomeWhatever is typed leaves the pageA collection endpoint was observed; anything entered is treated as exposed.

Dangerous — confirmed threat

Automated

It presents itself as Microsoft while being hosted somewhere Microsoft does not own. It asks for a password in a sign-in box that stays hidden in the page until you click — so the request only appears once you interact with it. Its own script hands what you type to discord — a route attackers use to collect stolen details. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
StrongExfiltration endpoint detected
discord: discord.com/api/webhooks/<redacted>

The page's own script holds the address of a service phishing kits use to receive what they collect — a Telegram bot, a Discord webhook or a request-catcher — and hands it what the visitor types. Legitimate sites do not send visitor or form data to these. No request was observed: the kit only sends after the visitor submits.

Analyst noteDefinitive endpoint (Telegram/Discord/request-proxy), READ OUT OF THE PAGE'S SCRIPT rather than seen on the wire — no request was watched, because the kit sends only after the visitor submits. Capture it for an IOC/takedown and read what the script posts to it before calling it credential theft.

SupportingBrand impersonation detected
Microsoft · high

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteHigh confidence: brand keywords AND a password field — classic credential phishing.

InfoSelf-hosted product check: no-fingerprint
no server fingerprint of the brand's own product

The brand fired at high confidence on a credential page, so the page was checked against the brand's self-hosted products (server fingerprint, the product's own credential sink on this host, return address, the organisation's mail records). It did not pass: refused: no server fingerprint of a Microsoft self-hosted product among 3 detected technologies

Analyst noteAn ordinary clone: the brand is on the page but the server is not the brand's product, or the credentials leave for somewhere that is not the product's own endpoint. Read the brand impersonation card below.

Infrastructure

IP
112.175.185.139KIXS-AS-KR-KR - Korea Telecom, KR · AS4766KR
TLS
CN=GlobalSign GCC R6 AlphaSSL CA 2025, O=GlobalSign nv-sa, C=BE · expires Dec 13, 2026
13 malicious50 suspicious

Hashes & fingerprints

Page capture

Live

Title “Cuenta de Microsoft - Iniciar sesión” · brand shown: Microsoft (high)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Cuenta de Microsoft - Iniciar sesión
Load
10.18 s · 6 requests
Stack · 3Apache HTTP ServercdnjsCloudflare