Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@hetzner.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
microsoft-login[.]it
Проверка домена microsoft-login.it на фишинг и безопасность
“Sign in to your Microsoft account”
microsoft-login.it — Последний известный активный (HTTP 308). Олицетворение бренда: Microsoft; Тип мошенничества: Tech Support Scam. Сводка доказательств: VirusTotal 24/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 100/100. Регистратор: Sensible Data s.p.a.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, microsoft-login.it, is identified as a brand impersonation threat targeting Microsoft account credentials. Analysis indicates the domain hosts a fraudulent login page titled 'Sign in to your Microsoft account,' designed to harvest user credentials through deceptive authentication prompts. No evidence of a drainer kit or secondary payload delivery was observed, but the page structure closely mimics legitimate Microsoft login portals, increasing the likelihood of successful social engineering attacks. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Sensible Data s.p.a., and resolves to the IP address 116.202.107.52, hosted on AS24940 (Hetzner Online GmbH) in Germany. The domain is flagged by 24 out of 95 security vendors on VirusTotal, with detection labels primarily categorizing it as a phishing site. It appears on one security blocklist, and its SSL certificate is associated with an unrelated domain, test-gozzo.dev, suggesting potential misuse of shared or compromised infrastructure. As of the latest assessment, microsoft-login.it has been taken offline, reducing immediate exposure risk. However, the domain remains registered, and the infrastructure may be repurposed for future campaigns. Organizations are advised to monitor for related indicators, including the IP address and registrar details, and implement domain-based blocking for microsoft-login.it in security controls. Users should verify login portals via official channels and enable multi-factor authentication to mitigate credential theft risks.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | microsoft-login.it |
malicious | Sinkholed |
| DNS4EU | microsoft-login.it |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260217-C22B5F Recipient: abuse@hetzner.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание