الانتقال إلى تقرير الأمان
Checked 09/08/2026 Ref F4637579

MALICIOUS — CRITICAL

فحص التصيد والأمان للنطاق microsoft-passkey.com

microsoft-passkey[.]com

microsoft-passkey.com is an active brand impersonation site that pretends to be a Microsoft passkey service in order to trick users into entering their credentials or passkeys.

92/100 evidence score · Critical
VirusTotal
14/91
Blocklists
2 · MetaMask, SEAL
التوفر
المحتوى غير متوفر · HTTP 502
Report / Add Evidence Appeal this listing
2026-04-28 14:30 UTCالمحتوى غير متوفر · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
تم الإبلاغ عن هذا النطاق باعتباره ضارًّا
محركات الأمان التي تبلغ عن اكتشاف: 14. قوائم الحظر العامة التي تبلغ عن تطابق: 2. توخي الحذر الشديد — لا تدخل بيانات الاعتماد أو المعلومات الشخصية.
Jump to section
ملخص التقرير

microsoft-passkey.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Microsoft; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 14/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 92/100. مسجّل النطاق: NiceNIC.

يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.

Evidence Analysis

Ref F4637579

microsoft-passkey.com is an active brand impersonation site that pretends to be a Microsoft passkey service in order to trick users into entering their credentials or passkeys. The domain specifically targets Microsoft users by using the term 'passkey,' a legitimate feature Microsoft promotes for passwordless authentication. By leveraging Microsoft’s trusted brand, attackers aim to harvest sensitive login information or passkey tokens, which could then be used to hijack accounts, access personal data, or perform further malicious actions on behalf of the victim. This operation is ongoing and represents an elevated risk to users who encounter it.

PhishDestroy identifies this domain as a confirmed phishing scam based on multiple independent security indicators. This domain was flagged by 2 out of 95 security vendors on VirusTotal, indicating limited but meaningful detection. It was created on April 27, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for hosting high volumes of low-trust domains. Additionally, the domain resolves to IP address 104.251.180.208, which is linked to suspicious hosting activity and has been blocked by SEAL and MetaMask security systems. These technical markers, combined with its deceptive branding, confirm malicious intent.

If you visited microsoft-passkey.com or entered any credentials or passkeys, immediately change your Microsoft account password and revoke any active sessions or tokens associated with the account from a known-safe device. Use Microsoft’s official account security portal to review recent sign-ins and remove unrecognized sessions. Enable multi-factor authentication (MFA) using an authenticator app or hardware key, not SMS. If you re-used the same password elsewhere, update those accounts immediately with strong, unique passwords. Scan your device with updated antivirus software to check for malware. Report the site to Microsoft via their abuse portal and warn others. Avoid visiting or clicking links from unsolicited emails, messages, or ads claiming to offer Microsoft passkeys or login portals.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
14 det.
DNS Security
1/12
العمر
3 mo
الحالة المرصودة
المحتوى غير متوفر 502
PhishDestroy
قائمة الإتلاف
مُدرج
نطاق تغطية البيانات12 recorded checks
VirusTotal 14 / 91 URLQuery لم يتم التحقق منها PhishStats checked — no match recorded OTX no community references رادار CF scan completed URLScan capture التقرير المخزن URLScan verdict اكتمل التحليل حجب عناوين DNS 1/12 TLS لا توجد بيانات للشهادة WHOIS 3 mo old لقطة شاشة 2 captures · 2 sources سلسلة إعادة التوجيه لم يتم التحقيق فيها
استخبارات أمن الشبكات Registrar context
DNS Provider Blocks 1 / 12
Brand Microsoft
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

مسار الاستجابة للتهديدات Pipeline

الاكتشاف
Checks
Reports
التوفر
15/16
تم استيعاب التهديد
microsoft-passkey.com تم اكتشافها وإدراجها في قائمة الانتظار لإجراء تحليل شامل
28/04/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
اكتمل تحليل URLScan؛ لا تغير نتيجة التقاط الويب هذه حكم تهديد الصفحة · score 0
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
14/91 recorded on VirusTotal
01/08/2026
Google Safe Browsing
28/04/2026
الكشف عن قوائم الحظر
موجود في 2 blocklists: MetaMask, SEAL
09/08/2026
DNS Security Blocks
Blocked by 1 of 12 checked DNS providers: Brand microsoft
Registrar Context: NiceNIC
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Brand Impersonation
Impersonation of Microsoft
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
Technical Analysis Recorded
يحتوي التقرير على التكنولوجيا المخزنة أو نتائج تحليل الطب الشرعي.
09/08/2026
Complaint Draft Available
لا يتم تسجيل أي تقديم. يمكنك إنشاء مسودة ومراجعتها وتقديمها بنفسك إلى السلطة المختصة.
تم نشر قائمة «DestroyList»
28/04/2026
Content Observed Unavailable
تشير أحدث عمليات التحقق المخزنة إلى أن المحتوى الذي تم الإبلاغ عنه غير متوفر؛ هذا لا يحدد من أو ما سبب التغيير.
08/05/2026
الوقت حتى أول تعذّر للوصول
انقضت ساعات 230 منذ الكشف وحتى أول ملاحظة غير متاحة.

حالة قوائم الحظر العامة

لقطة محفوظة

عنوان الصفحة
microsoft-passkey.com
Impersonates
Google

معلومات النطاق

النطاق
URLScan Verdict اكتمل التحليل score 0 report ↗
الخادم / ASN gws · AS402253 SKN Subnet & Telecom Ltd
سمعة عنوان IP abuse score 0/100 0 reports checked 13/07/2026
مسجّل النطاق NiceNIC RU(RU) PhishDestroy Investigation
جهة الإبلاغ عن إساءة الاستخدامabuse@nicenic.net
البحث في قاعدة بيانات WHOISICANN RDAP لـ microsoft-passkey.com →
عنوان IP 104.251.180.208 US
الموقع الجغرافيUS Fenton, US
الشبكةAS402253 · Tri-County Wireless, LLC
التسجيلتم إنشاؤه 28/04/2026 (103d)
حالة HTTP502 Error
الوقت حتى أول تعذّر للوصول 10 days
ما الذي نحتسبه الوقت المنقضي من أول تقرير عن إساءة الاستخدام المخزن إلى الملاحظة الأولى بأن المحتوى غير متوفر. هذا لا يحدد السبب.
ما يحتويه كل تقرير قد تشير سجلات التقارير الصادرة المخزنة إلى الأدلة المتاحة في ذلك الوقت، مثل أحكام البائعين أو بيانات التسجيل أو تفاصيل الاستضافة أو التصنيفات أو لقطات الشاشة. لا تستنتج هذه الصفحة الحمولة الدقيقة التي تم تسليمها أو استلامها أو إقرارها أو الإجراء الذي اتخذه المستلم.
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
تاريخ أول اكتشاف28/04/2026
DOM Analysisanalyzed 01/08/2026score 63/1001 brand signal
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://microsoft-passkey.com/
خوادم الأسماءdara.ns.cloudflare.com
TLS Observationscanned 09/08/2026
ICANN OVERSIGHT

الاعتماد وسياق RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft لا يُرسل أي شيء تلقائياً.

Latest Classified Outcome 2026-08-09 02:07:56 UTC

Primary outcome غير معروف reason: Origin unreachable 20% confidence
Attribution mechanism: Http 5xx source: Current Http Probe
Evidence layers Availability: Unreachable Content: Unknown DNS: Timeout Registration: Active
Latest HTTP observation غير معروف Origin unreachable Http 5xx 20% 2026-08-09 02:07:56 UTC
RDAP registration نشط NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientTransferProhibited expires 2027-04-27 14:49:04 UTC checked 2026-08-05 19:05:02 UTC
Observed timeline last reachable: 2026-08-08 22:15:00 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
الإبلاغ عن هذا النطاق أرسل الأدلة وساعد في حماية الآخرين

تحليل VirusTotal

14 / قام موردو الأمان 91 بوضع علامة على هذا المجال
View on VT
Last analyzed Previous stored snapshot: 2 detections
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
ESET
Fortinet
G-Data
Gridinsoft
كاسبرسكي
Lionic
SOCRadar
سوفوس
VIPRE
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.

اليوروبول
ابحث عن قناة التقارير الرسمية لبلدك في الاتحاد الأوروبي
National police directory
احذروا من المحتالين الذين يزعمون أنهم يساعدون في استرداد الأموال! قد يتصل المجرمون بالضحايا مرة أخرى بينما يتظاهرون بأنهم محققون أو محامون أو وكلاء استرداد. لا تدفع رسومًا مقدمة أو تشارك بيانات الاعتماد. تعرف على المزيد حول الاحتيال في مجال التعافي →

أبلغ السلطات المحلية

حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.

دليل 97 دولة
المسودة بمساعدة الذكاء الاصطناعي - تتم معالجة تفاصيل الحادث بواسطة موفر الذكاء الاصطناعي قم بمراجعتها وتقديمها بنفسك
تضمين هذا التقريرRead-only HTML widget
HTML · IFRAME

تضمين هذا التقرير

شارك هذه المعلومات الاستخباراتية المتعلقة بالتهديدات على موقعك الإلكتروني أو مدونتك

embed.html
<iframe
  src="https://phishdestroy.io/ar/embed/domain/microsoft-passkey.com"
  title="PhishDestroy threat report for microsoft-passkey.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

رسالة شكر صادقة جداً

منشئ مسودة ساخرة

المستلم
سياق الرسوم

مسودة ساخرة. أرقام الرسوم تقديرية، ولا ندّعي نسبتها بدقة إلى هذا النطاق.