mlcrosoft[.]co[.]com
“GRIDFLOW // AUTH”
संग्रहीत अवलोकन
देखा गया शीर्षक अंतर
साक्ष्य सारांश
Analysis of mlcrosoft.co.com, observed as offline as of the report date, shows definitive indicators of a brand impersonation campaign targeting Microsoft. The domain was registered on March 06, 2026 through Moniker Online Services LLC and resolves to IP address 172.67.195.41, which belongs to the Cloudflare network (AS13335) located in the United States. The site presented an HTTP 403 response and served a TLS certificate issued by Let’s Encrypt (E8), confirming the use of publicly available encryption.
The page title "GRIDFLOW // AUTH" was recorded, but the content of the page has not been captured, leaving the specific payload or credential‑capture mechanisms uncertain. The domain appears on three reputable security blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal reporting indicates that one of ninety‑four scanning engines flagged the domain, reinforcing the malicious assessment despite the low detection count.
The infrastructure—shared Cloudflare IP, generic certificate, and common nameserver set (ns1‑ns4.nic.co.com)—suggests the operator leveraged widely available hosting and DNS services to obscure attribution. Given the confirmed impersonation of Microsoft and the presence on multiple blocklists, defenders should continue to deny any traffic to this domain, update URL filtering policies to include it, and monitor for similar typosquatting variants that may reuse the same registration or hosting patterns. Further investigation is warranted to obtain the full page content and any associated payloads, but existing evidence justifies an elevated risk rating and immediate remediation actions.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | mlcrosoft.co.com |
malicious | Sinkholed |
| Hagezi Threat Feed | mlcrosoft.co.com |
malicious | Sinkholed |
| DNS4EU | mlcrosoft.co.com |
malicious | Sinkholed |
| Quad9 DNS | mlcrosoft.co.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।