east-app-73c39d3b[.]azurewebsites[.]net
“Bei Ihrem Konto anmelden”
east-app-73c39d3b.azurewebsites.net — Контент недоступний. Уособлення бренду: Microsoft; Тип шахрайства: Tech Support Scam. Зведення доказів: VirusTotal 20/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 100/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain east-app-73c39d3b.azurewebsites.net has been identified as a high-risk brand impersonation threat targeting Microsoft. Analysis indicates that this domain was used to create a phishing page with the title 'Bei Ihrem Konto anmelden' to deceive users into providing sensitive information. No drainer kit has been detected in this infrastructure.
Technical indicators show that the domain has a VirusTotal score of 20/95, indicating a significant number of security vendors have flagged it as malicious. The domain is registered through MarkMonitor, Inc., and resolves to the IP address 20.208.5.128, which is located in Switzerland (CH) under the Autonomous System number AS8075, associated with Microsoft Corporation. The domain was created on January 24, 2012, and does not have an SSL certificate. Google Safe Browsing has flagged the domain for phishing, and it appears on two security blocklists: PhishDestroy and PhishingDB.
The domain is currently offline, which suggests that the threat actor's infrastructure has been taken down. Despite this, the domain remains a potential risk due to its presence on multiple blocklists and the high number of positive detections by security vendors. Organizations and individuals are advised to continue monitoring for any signs of reactivation and to ensure that users are educated on recognizing and reporting phishing attempts. Additionally, security teams should verify that no sensitive data was compromised during the active period of this threat.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога