MALICIOUS — CRITICAL
security-docs-sign--microsoft-login[.]replit[.]app
12 of 91 security engines flagged the domain; the latest stored check returned HTTP 404.
- VirusTotal
- 12/91
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
security-docs-sign--microsoft-login.replit.app — Contenuto non disponibile (HTTP 404). Simulazione del marchio: Microsoft; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 12/91 (alphaMountain.ai, BitDefender, ESET, Emsisoft, Fortinet); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 98/100. Registrar: Replit.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain security-docs-sign--microsoft-login.replit.app is currently active and resolves to IP 34.117.33.233. Google Safe Browsing classifies it under SOCIAL_ENGINEERING, indicating attempts to harvest credentials. VirusTotal reports that 12 out of 91 scanned security vendors have flagged the domain, reinforcing the malicious assessment. The domain lacks publicly resolvable name‑server records (NS_NOT_FOUND), which hampers attribution but suggests deliberate obscuration of infrastructure. No additional metadata such as ASN or registration details are available, leaving the hosting environment largely opaque. Analysis indicates the site is being used for credential phishing, likely targeting users of a well‑known productivity platform given the “microsoft‑login” substring. Defenders should block network connections to the IP address 34.117.33.233 and add the full domain to URL filtering policies. Incident response teams should monitor for related DNS queries and consider sink‑hole routing for any future sub‑domains that resolve to the same host. Continuous re‑scanning on VirusTotal and other reputation services is advised to capture any changes in detection rates. Until further forensic evidence is obtained, the domain should be treated as high‑risk.
Copertura dei dati13 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: replit.app
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain replit.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.