quick-review-submited[.]surge[.]sh
“Unavailable”
quick-review-submited.surge.sh — 콘텐츠를 사용할 수 없음. 브랜드 사칭: Microsoft; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 6/91 (alphaMountain.ai, Emsisoft, Fortinet, G-Data, Netcraft); PhishDestroy score 68/100. 등록기관: Surge.sh.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, quick-review-submited.surge.sh, is actively engaged in credential harvesting through phishing, specifically targeting Microsoft account users. Analysis indicates the site mimics legitimate Microsoft login portals to deceive victims into submitting sensitive authentication details, including usernames, passwords, and multi-factor authentication codes. The domain remains operational as of the latest verification, posing an immediate threat to users who encounter it through malicious links in emails, messages, or compromised advertisements. Infrastructure analysis reveals the following technical indicators: the domain resolves to the IP address 159.203.50.177, hosted on DigitalOcean, LLC infrastructure (AS14061) in the Netherlands. It is flagged by 6 of 95 security vendors on VirusTotal, indicating a consensus among detection engines regarding its malicious nature. The domain is registered through Surge.sh, a platform often exploited for rapid deployment of phishing pages due to its ease of use and lack of stringent registration requirements. It appears on at least one security blocklist, and its SSL certificate is issued by Sectigo Limited under the Sectigo Public Server Authentication CA DV R36 chain. No legitimate creation date or historical registration data is available, further suggesting its ephemeral and fraudulent nature. Current status confirms the domain remains active, continuing to host phishing content designed to harvest credentials. Organizations and individuals are advised to implement immediate countermeasures, including blocking the domain and its associated IP address (159.203.50.177) at the network perimeter. Endpoint protection systems should be updated to recognize and quarantine any attempts to access this domain. Users who may have interacted with the site should be instructed to reset their Microsoft account credentials from a secure device and enable additional authentication safeguards. Security teams are encouraged to monitor logs for connections to the IP or domain, as such activity may indicate compromised accounts within their environment. Proactive threat hunting for related indicators, such as similar Surge.sh-hosted domains or DigitalOcean IP ranges, is recommended to identify and mitigate emerging threats.
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.