login[.]security[.]onmicrosoft[.]aviasg[.]co
“Avia Solutions Group – the world’s largest ACMI provider | AviaSG”
login.security.onmicrosoft.aviasg.co — المحتوى غير متوفر. انتحال العلامة التجارية: Microsoft; نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 19/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, Cluster25); Google Safe Browsing flagged; PhishDestroy score 98/100. مسجّل النطاق: Namecheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain is flagged as a high-risk brand impersonation phishing site targeting Microsoft users. Analysis indicates the domain is designed to mimic legitimate Microsoft login portals, specifically leveraging the onmicrosoft subdomain structure to deceive users into entering credentials. The threat type is classified as credential harvesting through brand impersonation, with no indications of additional payload delivery or crypto-draining functionality at this time. Infrastructure analysis reveals the domain was registered on March 13, 2023, through NAMECHEAP INC and currently resolves to the IPv6 address 2606:4700:20::681a:107, geolocated to Lithuania under AS211771 (AVIA SOLUTIONS GROUP PLC). VirusTotal detection metrics show 20 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is explicitly categorized as phishing by Google Safe Browsing. The SSL certificate is issued by Let's Encrypt (YR2), providing a false sense of security to potential victims. The page title, "Avia Solutions Group – the world’s largest ACMI provider | AviaSG," does not align with the domain's purported Microsoft login functionality, further indicating malicious intent. Mitigation requires immediate blocking of the domain and its resolving IP address across all security controls. Organizations should implement strict filtering rules to prevent access to domains containing "onmicrosoft" strings registered outside Microsoft's official infrastructure. User awareness training should emphasize the risks of credential submission on unexpected Microsoft login pages, particularly those hosted on third-party domains. Security teams are advised to monitor for successful authentications from this domain in authentication logs and initiate password resets for any affected accounts. The domain's continued activity status necessitates ongoing monitoring for changes in infrastructure or additional malicious functionality.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 12 identified
YouTube is a video sharing service where users can create their own profile, upload videos, watch, like and comment on other videos.
www.youtube.com ثقة 100٪Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com ثقة 100٪jQuery UI is a collection of GUI widgets, animated visual effects, and themes implemented with jQuery, Cascading Style Sheets, and HTML.
jqueryui.com ثقة 100٪jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com ثقة 100٪Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com ثقة 100٪FancyBox is a tool for displaying images, html content and multi-media in a Mac-style 'lightbox' that floats overtop of web page.
fancyapps.com ثقة 100٪Detectify is an automated scanner that checks your web application for vulnerabilities.
detectify.com ثقة 100٪Cookie-Script automatically scans, categorizes and adds description to all cookies found on your website.
cookie-script.com ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of login.security.onmicrosoft.aviasg.co · checked Jun 2, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب