https://login.microsoftonline.com/savedusers?wreply=https://outlook.office365.com/mail/&appid=00000002-0000-0ff1-ce00-000000000000&uaid=fcb88453-1259-48ad-ee90-502336e35ace&partnerId=exchange&idpflag=proxy

Last Checked: Feb 08, 2023, 21:20 EST

IP Address: 20.190.154.19
ASN #: AS8075 MICROSOFT-CORP-MSN-AS-BLOCK, US
Location: Unknown, Unknown, Unknown
URL Reputation:
  • Unknown This URL is not identified as malicious in the PhishTank Database.
  • Unknown PhishCheck thinks this URL is likely not a phish.
  • Unknown OpenPhish: URL not in feed.

Other submissions on 20.190.154.19:

Other submissions on microsoftonline.com:

  • http://passwordreset.microsoftonline.com/?ru=https%3a%2f%2flogin.microsoftonline.com%2fcommon%2freprocess%3fctx%3drQIIAYWSO2_TUABG46RNH0MpCAESUlUkBoTk5NrXj7oICT8Sp4kT14mT1BFSFL8SO341durGAzNjJ4ayMVYwwIT6D-jUGXViQkwICQkx0f4Clk8633rO-gpVgiVQAk8LWAnbfUxAghzROoMyIwqiBIMBdETgFApJSEEcYCYJ4OzO-ubLk1cfr943xLeXxrMv-StwhmxNkiSKd8vlNE1LoW07hlUyQr_sjQLTCcafEeQSQb4jyGl-2QpQkTvLxxSksZ0dQDMAhxACigYlzeXcll_1NFdJBoI5afIAaJlBSqrnaC6baG7L0_Cq28oUUlarU1msLFqqQTQzJdHUlqM5ADQzDUj9PWIgVK6_ga9lWjoQ2u5AGHhf87dkdp5M8JsJZ05m_cqv2eHMH0ZhnJwW3uQP60ToNoei01EFfOCyrhdg42goHmViTTJQUpsuaDrSiYNYbfPGHIuq9a44IElZSlpHRz0mVXuSPqaVTE77vm4e18eNiO3NzERXycjsuKZtMpYrqtzUttrjflDrs3N0UWmgaVusy9Wu74mEjqITz8d1ZsZJUtTgjuUDs88y-6jepuI-nMYeQxyLkcKiOxWhzx3UmirhdHncaxBGV-dNRbFsKuTZdlhNDZjZ8DiLWShjZKLQknY0z9p-A9SVoLOQx2qmcXIvVaeZ3ZMXcM5HI67RodEdHTYzjwQ1_ABvsJ8KxWuZfhhcFDbCyAocczuahbbjWd8KD-PEiiZWkDpeHAYvvDAww0AfLW70Xy4hP5burRY3Cw9y27knd0Fhd3V1fTN3Q3-WkHfL1y0xzBahP_rAnt_fL278_Z27WC4fjg1P163uqOZ0Nc4dE_tJJYisiOdHlBXZoEscliW2o_GHzef0LnZSRE6KxYvi7T1h2KqoHZVtCWxbwIfgZ7HweiV3vvafOv8B0&amp

  • https://login.microsoftonline.com/redeem?rd=https%3a%2f%2finvitations.microsoft.com%2fredeem%2f%3ftenant%3d0708ea9b-9fc6-41ba-bb9b-7e066a181c09%26user%3d112ccebe-2f70-4ba0-a9d4-ad204cdcc656%26ticket%3dVa1QpswdRChGUoGTUyKBXlW2lqo3H5B3qjKGmnYGc1k%25253d%26ver%3d2.0

  • https://login.microsoftonline.com/redeem?rd=https%3a%2f%2finvitations.microsoft.com%2fredeem%2f%3ftenant%3d72f988bf-86f1-41af-91ab-2d7cd011db47%26user%3d16786c71-b517-4b56-bce9-2004618b8193%26ticket%3dn00v2ThhqR%25252fxQxImRjraANEzclTKM9s1nq5rsB5eicE%25253d%26ver%3d2.0

  • https://login.microsoftonline.com/redeem?rd=https%3a%2f%2finvitations.microsoft.com%2fredeem%2f%3ftenant%3d37c354b2-85b0-47f5-b222-07b48d774ee3%26user%3d607f6945-eaee-4b61-9d12-d391c7d7621f%26ticket%3dS8kj3Rx%25252bhfY01XH8jpeqDYbB4vx1INToH0EKAUBfSuo%25253d%26ver%3d2.0

  • https://login.microsoftonline.com/sc.com/oauth2/v2.0/authorize?client_id=c1c74fed-04c9-4704-80dc-9f79a2e515cb&scope=https%3A%2F%2Fwww.yammer.com%2Fuser_impersonation%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fweb.yammer.com%2Fmain%2Fauthredirect&client-request-id=91876f48-b8af-4a8b-b11b-98e5e45123ef&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=3.7.0&client_info=1&code_challenge=cjuMXsz00T_oVA9xAVrqe3bHSZczMmiAsDMwUHM3-zE&code_challenge_method=S256&nonce=040999be-80b4-4b21-aa7e-42170b206998&state=eyJpZCI6IjIyYWYyMzI0LWYzNWQtNDY4Ny1iNWYwLTI2ZDRmNDRhOGJjNiIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D&claims=%7B%22access_token%22%3A%7B%22xms_cc%22%3A%7B%22values%22%3A%5B%22CP1%22%5D%7D%7D%7D&sso_reload=true

  • https://login.microsoftonline.com/organizations/oauth2/v2.0/authorize?client_id=4765445b-32c6-49b0-83e6-1d93765276ca&redirect_uri=https%3A%2F%2Fwww.office.com%2Flandingv2&response_type=code%20id_token&scope=openid%20profile%20https%3A%2F%2Fwww.office.com%2Fv2%2FOfficeHome.All&response_mode=form_post&nonce=638514476150213132.ZmY2ZTk1YTUtYjI3OC00NTEyLThhMTItNGIyMDgzMTBjMGQyNmIzYWYxZDgtN2QyNi00MTA4LTk4ZTItMDhhMDc3NjE4Y2U3&ui_locales=es-ES&mkt=es-ES&msafed=0&client-request-id=1b563aa9-dde6-446e-84e8-9d76ad3485d9&state=kvbZNsaAXpJyNK2iMWfKS0xLHnYo-_1o3nYP3Ctx7sZh-aa9JI0IJMYBpuHeko7OqGyomtZOGu4PstD0wBecWhWuPTYKFeyTbrRfu-28kxWz426sardxh3XPkZsc_20-HjFLKGbnQOYWaVxl8LfM_bgbkSCltpYMqBWNrrVqOhTqk1bJXzI-Yr6gwXcH5q2hwtM1M7juQrMFXiltFZ4sQbPWuRDpim6xh85XPgu8hcV1_4u_sDZsWNGXm4YqQorfh4Vfs1lREuEe6__s0KMD23y4PDe7-nsiFzfT41pYpvInQFSm-clG6zTA2m3ahyQKj7qYVC2JVWAd9_AW-fbmclEMLD8GG9AiLj3wgUuOMAw&x-client-SKU=ID_NET6_0&x-client-ver=7.3.1.0&sso_reload=true

  • https://login.microsoftonline.com/common/oauth2/v2.0/authorize?scope=service%3A%3Aaccount.microsoft.com%3A%3AMBI_SSL+openid+profile+offline_access&response_type=code&client_id=81feaced-5ddd-41e7-8bef-3e20a2689bb7&redirect_uri=https%3A%2F%2Faccount.microsoft.com%2Fauth%2Fcomplete-signin-oauth&client-request-id=4aa73825-954d-4b0a-aa99-d2f09c4275c5&x-client-SKU=MSAL.Desktop&x-client-Ver=4.45.0.0&x-client-CPU=x64&x-client-OS=Windows+Server+2019+Datacenter&prompt=login&client_info=1&state=H4sIAAAAAAAEAAXB0aJCMAAA0H_p9T5Y18o8zoZSqLYuemMtDJVQ09ffcxZeGUHY9BewZb_PgT92NP-Zhy5nEzqjlnwRS892oAW5Uv94KLG-p21VUeRBPhGnWz_Gi_uKmvgyP8kQY15uyEplEQUMwn5zfewGvMSr7enGfG0crwVtgLNSnq-F7Vgo6PhHvaBnzb5DTsFTv-O9gWTvJroz3HRt9Xs5dmDFek52UeXiPp00NJ-x1C-yrZuN4DBUWoLsqCecWRjVdXgYRJ0K64D3E08bOC_9dDkO3m_Qll_75z1TkoV-biJ-Wke1c5cFKCi5BnmS0JiZBgnMzMRvQ8ZA2ugyumEduRPxu1R7OUnwnbJEfJ2-k6L9RKxFj6_y5FacCLDjaqgUd_a1yPHfJ0SFQnEVFaxUQuq_dxK8bkqBaizW7jEpfW-4L_4B--fEkIIBAAA&msaoauth2=true&lc=2058&sso_reload=true

  • https://login.microsoftonline.com/17a8b2c6-b69e-4f1f-8377-a679f3ae4b47/oauth2/v2.0/authorize?client_id=c1c74fed-04c9-4704-80dc-9f79a2e515cb&scope=https%3A%2F%2Fwww.yammer.com%2Fuser_impersonation%20openid%20profile%20offline_access&redirect_uri=https%3A%2F%2Fweb.yammer.com%2Fmain%2Fauthredirect&client-request-id=59a41c6b-77bd-4058-ab08-fc72924f1c79&response_mode=fragment&response_type=code&x-client-SKU=msal.js.browser&x-client-VER=2.30.0&client_info=1&code_challenge=NHKn07MGun4HioPZPKG_QeXZF9dVNLVTMeiQwDE4WFo&code_challenge_method=S256&nonce=3b4bfc0d-6167-49cf-8f01-2bca4c0e863d&state=eyJpZCI6ImVhYjQ2ZWUwLTU3ZGItNDkzNy1iZjQ4LTAyODViZDBmOGZhNyIsIm1ldGEiOnsiaW50ZXJhY3Rpb25UeXBlIjoicmVkaXJlY3QifX0%3D

  • https://login.microsoftonline.com/c6d2a3fb-3200-4579-80f3-ec32db9f2baa/oauth2/authorize?client_id=0000000c-0000-0000-c000-000000000000&redirect_uri=https%3A%2F%2Faccount.activedirectory.windowsazure.com%2F&response_mode=form_post&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DAQAAAAQAAAAIVGVuYW50SWSrAWI5MHJDci1laS1BbjZaR2MtX1JialAwUmRaNHRGeEE4Z3NDZmpkaFRvY3pVNGtEaXduODFEVXM5RmY5Skx2NjBDWDRyTlNYVjNwTnJQWGkwWkcxdjZiSXpUT0tOX3Y4WWRFeWJhdHAxVTNvV21TNl9IWElXQjJOTzJpNTFJVWxXX1N5ckxwcGdNU01GNmlkdUdkX3lTaGt5ZC1jRUltLVg2ZWhvNm5TeC1sdwpsb2dpbl9oaW50lgF5UHR0OXBNTzQxQTZpLUpBdERRUjg0aWU0V21rNzBsM2dfRi1nYzhlbjFXU0phcE1BQUw4U2FPYmE5UWcxS1FvOGk5Q3EwUEFxU3VGR3pNMVpCM2FQX3RkU1hRSHhoQ0E0djBxYXl2b0NuRGl5SWNqZFhDcHhMZ1FyV01qWTF0VWFuVnRkM0FDSTFlVmdpS2ZpQ2h3WWcJLnJlZGlyZWN0ggFodHRwczovL2FjY291bnQuYWN0aXZlZGlyZWN0b3J5LndpbmRvd3NhenVyZS5jb20vcj90ZW5hbnRpZD1jNmQyYTNmYi0zMjAwLTQ1NzktODBmMy1lYzMyZGI5ZjJiYWEmbG9naW5faGludD1hY2FuYXN0dWolNDBjZW1wcm8uY29tHk9wZW5JZENvbm5lY3QuQ29kZS5SZWRpcmVjdFVyacABUUtIblJUcktWajBqWjhpaU5XMl95VTNsWEhiNkVFVU5lMTdZVFR4eVYxMkdyY29tYWM1RGNXZ3RDQkF1RkR3UENUV0ZkT0xEd1FLNzR2eGhPN2luTEo5U28tMk9UUTZMU2lqSUxja1JiNHRBVUlxRkVDSzAwTE9aMnE0RWZ0aUdBdEcyRG01Q19zTmhnSmhfWjU1T3JRcGVLZWNQNm42WlhrQ1BDenB0RFJvMHpoUGxQODRkVS0wVkJkUjZza0Rx&nonce=1675274440.kuGiejtNqyPILdbP1DDJqA&login_hint=acanastuj%40cempro.com&nux=1

  • https://login.microsoftonline.com/c6d2a3fb-3200-4579-80f3-ec32db9f2baa/oauth2/authorize?client_id=0000000c-0000-0000-c000-000000000000&redirect_uri=https%3A%2F%2Faccount.activedirectory.windowsazure.com%2F&response_mode=form_post&response_type=code%20id_token&scope=openid%20profile&state=OpenIdConnect.AuthenticationProperties%3DAQAAAAQAAAAIVGVuYW50SWSrAVlGOVJUdUFldExNSjRDVUNIVHQ3T2c0WVN5Y2ViSnlNcS1GV3ZmQzFoVUk4U0FjakRUX2hXZWpYaTRxQTJTeGJsSnlRbS15UWg1N2U3X3ROcWRIWDVOTjd3V09vNmhJM05VNEF4X3VnSVcxN2pMM1Nma0FNVXJjN3cxeVdwdTVjbVM1RVRfYXZLZm1qcjFZNm9EMmxKa180TTVFdWNBY09OYW50YU9RNVJRSQpsb2dpbl9oaW50lgE4M042eWFSMnlleExRa3pVQk03WkZJV016b1hFdzZvclFsa19zQmx0ZzdVR2FnQTBWUndBV1Nsa2dvc0hqQWhXWlU0NW9JbWRSLUxBclFONWJhQ0xVelFoNk02UVpwc3pCelBWTzRNdUZXUGZXMV95cW9xc2xrbVJjaDViZG1vaHJuM3MtSVRFT2JZQzJHOUZ1RG5MNEEJLnJlZGlyZWN0ggFodHRwczovL2FjY291bnQuYWN0aXZlZGlyZWN0b3J5LndpbmRvd3NhenVyZS5jb20vcj90ZW5hbnRpZD1jNmQyYTNmYi0zMjAwLTQ1NzktODBmMy1lYzMyZGI5ZjJiYWEmbG9naW5faGludD1hY2FuYXN0dWolNDBjZW1wcm8uY29tHk9wZW5JZENvbm5lY3QuQ29kZS5SZWRpcmVjdFVyacABblBReXhqd0RtN29PWDJabXhsY1dYM29hY0xXZXZsc3otUDVGNlBUcG1rdWt5bkRLLXdlbHE1MjRTWkFHOTBSLWNpNUZLWGx3TzQxVml4RXZsZVRmdy1PbTZibWRTS2s2OE9jTnA5NzRDSzBHNUNKT0hUbmhVVHF3MF9DV2kteG92NlR3WG9XNXdITlFpamozTDhFcmxKVXVadElOeVZQdFlUNFJMUHFIT19EQXNWemQ1ejY2MnFRUzQ0ZmpVVmFP&nonce=1675274441.bL9-ZZlAHTKZCe6gbh_wqg&login_hint=acanastuj%40cempro.com&nux=1

Previous checks:

                               
                             
  • GET
    200 OK

    https://logincdn.msftauth.net/16.000/content/js/MeControl_3NHOxA-1M1TpY-uDDP6vgw2.js

<html><head>
    <meta name="viewport" content="width=device-width">
    <meta name="PageID" content="MeControl">
    <title>User Data</title>
</head>
<body>
    <script type="text/javascript">
        function getPerformanceObjectData(object)
        {
            var result = {};

            if (!object)
            {
                return result;
            }

            // In some browsers, some of the PerformanceTiming objects have a native toJSON method
            // that returns a JS object with all of the properties of the PerformanceTiming object.
            if (object.toJSON)
            {
                return object.toJSON();
            }

            // PerformanceTiming objects are not regular JS objects. Calling Object.hasOwnProperty
            // on them does not work.
            // eslint-disable-next-line guard-for-in
            for (var property in object)
            {
                result[property] = object[property];
            }

            return result;
        }

        function getPerformance()
        {
            if (!window.performance)
            {
                return null;
            }

            var timingData = getPerformanceObjectData(window.performance.timing);

            var entriesData = [];

            if (window.performance.getEntries)
            {
                var entries = window.performance.getEntries();

                if (entries)
                {
                    for (var i = 0; i < entries.length; i++)
                    {
                        entriesData[i] = getPerformanceObjectData(entries[i]);
                    }
                }
            }

            var performance = {
                idp: "aad",
                timing: timingData,
                entries: entriesData,
                ssoReload: false
            };

            return performance;
        }

        function constructResponse()
        {
            var response = { userList: [] }, idp,
                user, error;

            response.idp = 'aad';


            var performance = getPerformance();
            if (performance)
            {
                response.performance = performance;
            }

            if (typeof JSON !== "undefined")
            {
                return JSON.stringify(response);
            }
            else
            {
                return "";
            }
        }

             
                function handleIdpResponse(e) {

                    if (e.origin == "https://login.live.com") {
                        postResponse(e.data)
                    }
                    else {
                        return;
                    }
                }

                (function addEvent(evnt) {
                    if (window.attachEvent)
                        return window.attachEvent('on' + evnt, handleIdpResponse);
                    else
                        return window.addEventListener(evnt, handleIdpResponse, false);
                })('message');
            
         
             
                function postResponse(message)
                {
                    if (window === window.parent) {
                        return;
                    }
                    var destination = 'https://outlook.office365.com/mail/';
                    window.parent.postMessage(message, destination);
                }

                window.setTimeout(function ()
                {
                    var message = constructResponse();
                    postResponse(message);
                }, 0);
             
    </script>
    <div>
            <iframe src="https://login.live.com/Me.srf?wa=wsignin1.0&amp;idpflag=indirect&amp;id=12&amp;wreply=https%3a%2f%2flogin.microsoftonline.com&amp;owreply=https%3a%2f%2foutlook.office365.com%2fmail%2f" style="display: none"> </iframe>
    </div>


</body></html>

                             

Screenshot: