micro365[.]live
“Domain Default page”
This domain, micro365.live, poses a high-risk brand impersonation threat designed to deceive users into believing they are interacting with a legitimate Microsoft service. The site likely harvests login credentials, enabling unauthorized access to accounts, data theft, or further malicious activity such as financial fraud or corporate espionage. Brand impersonation attacks like this often exploit trust in well-known platforms to bypass user skepticism and increase success rates. Analysis indicates the domain was registered on November 26, 2025, through Name.com, Inc., a common registrar for both legitimate and malicious domains. It resolves to the IP address 178.16.54.95, hosted in the Netherlands under AS202412 (Omegatech LTD). The domain is flagged by 20 out of 95 security vendors on VirusTotal, with additional detections from PhishDestroy, PhishingDB, and Google Safe Browsing. The SSL certificate, issued by Let’s Encrypt (R13), provides encryption but does not validate legitimacy, a tactic frequently abused by threat actors to appear trustworthy. If you visited micro365.live or entered credentials on a site resembling Microsoft services, take immediate action. First, change passwords for any accounts accessed from the same device, prioritizing email, financial, and work-related platforms. Enable multi-factor authentication (MFA) where available to add an additional security layer. Scan the device used to visit the site with updated security software to detect potential malware or keyloggers. Monitor accounts for unauthorized activity, such as unfamiliar logins, password changes, or transactions. Report the incident to your organization’s IT security team if the device is work-issued or used for professional purposes.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of micro365.live · checked Mar 1, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive