As of August 01, 2026, oauth.onedrive.biz.id is assessed as a high-risk domain actively involved in generic phishing operations, with a specific focus on social engineering threats. Multiple threat intelligence sources have flagged this domain, including PhishDestroy and OpenPhish, both of which have placed it on their blocklists. Google Safe Browsing further confirms its engagement in social engineering, indicating attempts to deceive users for sensitive information extraction. The domain resolves to IP address 35.173.245.255; no further infrastructure details are available at this time.
Notably, the domain currently has no valid nameservers, suggesting possible attempts to evade standard DNS resolution or detection mechanisms. VirusTotal reveals that 14 out of 91 security vendors flag the domain as malicious, strengthening the evidence of active phishing-related activity. The domain appears on two distinct security blocklists, indicating recognition across independent threat monitoring communities. The exact content hosted at oauth.onedrive.biz.id has not been analysed, so specifics regarding the site’s presentation or targeting are unknown.
Defenders should treat any traffic to or from this domain as highly suspicious and immediately block access at the network perimeter. Security teams are advised to update detection signatures to reflect the indicators presented and monitor for attempted connections to IP 35.173.245.255. Evidence from mainstream blocklists and Google Safe Browsing underscores the urgency of mitigating exposure. Continued monitoring is recommended until the domain status changes from active to inactive.