MALICIOUS — CRITICAL
microsoft-passkey[.]com
microsoft-passkey.com is an active brand impersonation site that pretends to be a Microsoft passkey service in order to trick users into entering their credentials or passkeys.
- VirusTotal
- 14/91
- Blocklists
- 2 · MetaMask, SEAL
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
microsoft-passkey.com — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Microsoft; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 14/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 92/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
microsoft-passkey.com: Active Microsoft Passkey Phishing Scam
microsoft-passkey.com impersonates Microsoft to steal passkeys, is blocked by SEAL & MetaMask, and has been live since April 27, 2026.
microsoft-passkey.com is an active brand impersonation site that pretends to be a Microsoft passkey service in order to trick users into entering their credentials or passkeys. The domain specifically targets Microsoft users by using the term 'passkey,' a legitimate feature Microsoft promotes for passwordless authentication. By leveraging Microsoft’s trusted brand, attackers aim to harvest sensitive login information or passkey tokens, which could then be used to hijack accounts, access personal data, or perform further malicious actions on behalf of the victim. This operation is ongoing and represents an elevated risk to users who encounter it.
PhishDestroy identifies this domain as a confirmed phishing scam based on multiple independent security indicators. This domain was flagged by 2 out of 95 security vendors on VirusTotal, indicating limited but meaningful detection. It was created on April 27, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for hosting high volumes of low-trust domains. Additionally, the domain resolves to IP address 104.251.180.208, which is linked to suspicious hosting activity and has been blocked by SEAL and MetaMask security systems. These technical markers, combined with its deceptive branding, confirm malicious intent.
If you visited microsoft-passkey.com or entered any credentials or passkeys, immediately change your Microsoft account password and revoke any active sessions or tokens associated with the account from a known-safe device. Use Microsoft’s official account security portal to review recent sign-ins and remove unrecognized sessions. Enable multi-factor authentication (MFA) using an authenticator app or hardware key, not SMS. If you re-used the same password elsewhere, update those accounts immediately with strong, unique passwords. Scan your device with updated antivirus software to check for malware. Report the site to Microsoft via their abuse portal and warn others. Avoid visiting or clicking links from unsolicited emails, messages, or ads claiming to offer Microsoft passkeys or login portals.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:07:56 UTC
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.