Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@microsoft.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
office365microsoftlogin[.]com
Pemeriksaan phishing dan keamanan office365microsoftlogin.com
“Login :: Damn Vulnerable Web Application (DVWA) v1.10 *Development*”
office365microsoftlogin.com — Belum terverifikasi. Peniruan identitas merek: Microsoft; Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 3/91 (alphaMountain.ai, SOCRadar, Sophos); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrar: Hosting Concepts.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain office365microsoftlogin.com is actively engaged in credential harvesting through brand impersonation targeting Microsoft. Analysis confirms the domain is designed to mimic legitimate Office 365 login portals, posing a high risk of unauthorized account access and data exfiltration. As of the latest assessment, the domain remains operational and unmitigated. Infrastructure analysis reveals the domain was registered on June 19, 2026, through Hosting Concepts B.V. d/b/a Registrar.eu, a registrar frequently associated with malicious registrations. It resolves to the IP address 172.197.176.182, geolocated in Malaysia under AS8075 (Microsoft Corporation), though this likely represents hijacked or misconfigured infrastructure. The domain appears on three distinct security blocklists and is flagged by 3 of 95 vendors on VirusTotal, indicating limited but growing detection coverage. Notably, the page title, "Login :: Damn Vulnerable Web Application (DVWA) v1.10 *Development*," suggests either an attempt to obfuscate malicious intent or exploitation of a compromised web application framework. The absence of an SSL certificate further undermines any perceived legitimacy and increases the likelihood of interception during credential transmission. Current status confirms the domain remains active, with no evidence of takedown or remediation. Organizations are advised to implement immediate network-level blocking of 172.197.176.182 and the domain office365microsoftlogin.com across all security gateways. Endpoint protection systems should be updated to recognize the domain and associated IP as malicious, with particular emphasis on detecting anomalous login page behavior. Users should be educated to verify domain authenticity before entering credentials, especially when prompted by unsolicited login requests. Given the high-risk nature of this campaign, incident response teams are encouraged to monitor for unauthorized access attempts linked to this infrastructure.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260621-CEE975 Recipient: abuse@microsoft.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive