ms-online[.]live
“Sign In”
Evidence Summary
Analysis of the domain ms-online.live, observed on August 04, 2026, indicates an active generic phishing campaign that is currently under investigation. The site has been indexed by VirusTotal and examined by 91 security vendors; at the time of analysis no vendor flagged the domain as malicious. This lack of detections is not interpreted as evidence of benign intent, but rather reflects the possibility that existing detection signatures have not yet been updated to recognize the payload or infrastructure employed.
Independent threat‑intelligence feeds have recorded the domain on a single security blocklist and it is explicitly blocked by the PhishDestroy service, confirming that external mitigation platforms consider it hostile. The limited public metadata—absence of disclosed registrar, hosting IP, SSL certificate details, or page title—precludes a deeper infrastructure profile. Consequently, the primary observable indicators are the blocklist inclusion and the VirusTotal scan result.
Defenders should treat ms-online.live as a confirmed phishing vector, enforce network‑level blocks, add the domain to local deny lists, and monitor for any associated command‑and‑control or credential‑harvesting activity. Continuous re‑evaluation is advised, as future scans may reveal detections once signature updates propagate.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 10, 2026
8 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
-
Domain status
Unreachable → Reachable
-
Domain status
Reachable → Unreachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of ms-online.live · checked Aug 4, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive