# PhishDestroy threat dossier — powerusers.microsoft.com ================================================================ Fetched: 2026-07-29 03:41:23 UTC Canonical: https://phishdestroy.io/domain/powerusers.microsoft.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 95/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: Microsoft ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/91 security vendors flagged this domain Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 20.112.250.133 (US, Des Moines) ASN: AS8075 Microsoft Corporation Hosting org: Microsoft Azure Cloud (centralus) Registrar: MarkMonitor Inc. Nameservers: ["ns1-39.azure-dns.com", "ns2-39.azure-dns.net", "ns3-39.azure-dns.org", "ns4-39.azure-dns.info"] Page title: Find Answers | Microsoft Power Platform Community HTTP response: 301 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Microsoft Corporation / Microsoft TLS G2 RSA CA OCSP 16 Expires: 2026-12-16 Status: INVALID chain Fingerprint: cde181ac7c588c2877fa9be102a19595740e0a3e3903b3781d117a6e124b0f97 Subject Alternative Names (related infrastructure — often same operator): - 2010office.it - adatum.ai - ai.fluentui.dev - aiandyou.today - aielectionsaccord.com - aiotlabs.microsoft.com - airlift.microsoft.com - aiusecaseexplorer.microsoft.com - apc.delve.office.com - auth.flip.com - bestxboxgames.com - blog.aspire.dev - book.ms - boulder-innovations.com - can.delve.office.com ... +182 more ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- First detected: 2026-07-27 22:23:08 UTC (by PhishDestroy tracker) Last verified: 2026-07-29 04:20:27 UTC Current status: ACTIVE / observable ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 22:24:53 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] powerusers.microsoft.com generic phishing site identified On 27 July 2026 analysts observed that the domain powerusers.microsoft.com continues to be active and is classified as a generic phishing infrastructure. Registration records show the domain was acquired through MarkMonitor Inc., a registrar commonly used for legitimate Microsoft‑related properties, which may be an attempt to lend credibility. The authoritative DNS configuration points to four Azure DNS name servers (ns1-39.azure-dns.com, ns2-39.azure-dns.net, ns3-39.azure-dns.org, ns4-39.azure-dns.com), indicating hosting on Microsoft Azure infrastructure. An HTTP request to the apex resolves with a 301 permanent redirect, but the target URL has not been disclosed in the current dataset. The domain has been submitted to VirusTotal where 91 scanning engines evaluated the associated resources; none raised a detection, yet the absence of alerts does not constitute a security endorsement. The domain is listed on a single public blocklist and is actively blocked by the PhishDestroy filtering service, confirming that at least one security community has observed malicious use. No additional intelligence such as IP address, SSL certificate details, Safe Browsing verdicts, OTX references, or page title has been published, leaving the full scope of the campaign unclear. Defenders should continue to monitor DNS queries for the Azure name‑server pattern, enforce outbound filtering for the domain, and incorporate the domain into blocklists and URL filtering policies. Organizations using Microsoft services should educate users about unsolicited communications that reference Power Users or Microsoft resources, and encourage verification of any credential‑submission requests through official channels. Ongoing collection of payloads, redirects, and host‑level artifacts will be required to refine attribution and to determine whether the infrastructure is shared with other observed phishing campaigns. ## EVIDENCE HASHES ---------------------------------------------------------------- TLS cert SHA-256: cde181ac7c588c2877fa9be102a19595740e0a3e3903b3781d117a6e124b0f97 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/powerusers.microsoft.com/ JSON API: https://api.destroy.tools/v1/check?domain=powerusers.microsoft.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 191,831 domains (82,883 alive under monitoring, 107,637 confirmed takedowns/dead). Site: https://phishdestroy.io