Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@namecheap.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
microsotf[.]comi-site[.]website
“We are sorry, the page you requested cannot be found”
microsotf.comi-site.website — Non vérifié. Usurpation de l'identité de la marque : Microsoft; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 16/91 (ADMINUSLabs, ArcSight Threat Intelligence, BitDefender, CyRadar, ESET); URLQuery 5 alerts; Spamhaus DBL_BOTNET; PhishDestroy score 95/100. Bureau d’enregistrement: Namecheap.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
microsotf.comi-site.website is currently listed as an active brand‑impersonation campaign targeting Microsoft. The domain was registered on 2025-11-06 through a registrar associated with NAMECHEAP INC and resolves to the IPv4 address 212.83.61.198, which geolocates to Germany and is operated by the hosting provider 23media. The server presents a TLS certificate issued by Let’s Encrypt (YR1) and enforces HTTP Strict Transport Security, indicating a deliberately configured HTTPS service. Network resolution is handled by dns1.registrar-servers.com and dns2.registrar-servers.com. Passive fingerprinting reveals the presence of a .NET‑based web application framework, a cloud fronting service and a content‑delivery network, consistent with the use of Azure‑derived infrastructure and an Akamai edge node. These components suggest the operators have access to commercial cloud and CDN resources, which can aid in evading simple IP‑based blocking. The site mimics Microsoft branding and has been flagged by PhishDestroy and appears on a single public blocklist. No detections were reported by VirusTotal at the time of analysis (0/95 scans). The lack of antivirus hits does not imply benign intent; the observed brand‑impersonation behavior aligns with typical credential‑harvesting campaigns. The infrastructure’s recent creation date and active status indicate the campaign is still in its deployment phase. Defenders should add the domain and its resolving IP to URL filtering and network‑level deny lists. Monitoring of DNS queries for the two registrar‑provided nameservers can provide early warning of additional domains that reuse the same registration profile. Because the TLS certificate is publicly trusted, users should be educated to verify the exact spelling of the URL and to report any unexpected credential requests to the legitimate brand’s security channels.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | microsotf.comi-site.website |
malicious | Sinkholed |
| DNS4EU | microsotf.comi-site.website |
malicious | Sinkholed |
| Cloudflare DNS | microsotf.comi-site.website |
malicious | Sinkholed |
| DigiCert UltraDNS | microsotf.comi-site.website |
malicious | Sinkholed |
| Quad9 DNS | microsotf.comi-site.website |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Registration: comi-site.website
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain comi-site.website behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 5 identified
ASP.NET is an open-source, server-side web-application framework designed for web development to produce dynamic web pages.
www.asp.net Confiance à 100 %Azure Front Door is a scalable and secure entry point for fast delivery of your global web applications.
docs.microsoft.com Confiance à 100 %Azure is a cloud computing service for building, testing, deploying, and managing applications and services through Microsoft-managed data centers.
azure.microsoft.com Confiance à 100 %HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confiance à 100 %Akamai is global content delivery network (CDN) services provider for media and software delivery, and cloud security solutions.
akamai.com Confiance à 100 %Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of microsotf.comi-site.website · checked Jul 12, 2026
Données factuelles et rapports externes
PD-20260712-A96019 Recipient: abuse@namecheap.com Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif