Перейти до звіту про безпеку
Checked 09.08.2026 Ref 311E189F

MALICIOUS — CRITICAL

Перевірка домену microsoftauthenticatorappdownload.com на фішинг і безпеку

microsoftauthenticatorappdownload[.]com

The domain microsoftauthenticatorappdownload.com was identified as a brand impersonation threat targeting Microsoft users.

100/100 evidence score · Critical
VirusTotal
14/91
Blocklists
2 · MetaMask, SEAL
Доступність
Останній відомий активний · HTTP 200
Report / Add Evidence Appeal this listing
2026-05-08 06:45 UTCОстанній відомий активний · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 14. Публічні списки блокувань, які повідомляють про збіг: 2. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@godaddy.com. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
3 months
Reports sent
1
Latest case ID
PD-20260508-CDD5E1
Current status
HTTP 200 at latest stored check
Jump to section
Огляд звіту

microsoftauthenticatorappdownload.com — Останній відомий активний (HTTP 200). Уособлення бренду: Microsoft; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Реєстратор: GoDaddy.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Evidence Analysis

Ref 311E189F

The domain microsoftauthenticatorappdownload.com was identified as a brand impersonation threat targeting Microsoft users. Currently marked as under investigation and offline, this domain was designed to deceive visitors into believing it was an official Microsoft Authenticator download portal. The phishing campaign leverages Microsoft's trusted brand to harvest credentials or install malware, posing a significant risk to users who may inadvertently submit sensitive information.

Technical analysis reveals that the domain was created on May 8, 2026, and registered through GoDaddy.com, LLC. It resolves to IP address 76.223.105.230 and is secured with an SSL certificate issued by Starfield Technologies, Inc. (Starfield Secure Certificate Authority - G2). Despite its malicious intent, VirusTotal shows 0 detections out of 95 security vendors, indicating that traditional signature-based detection has not yet flagged the domain. However, it appears on 3 security blocklists and is referenced in 1 AlienVault OTX threat intelligence pulse, suggesting that community-driven threat sharing has recognized the risk.

Given that the domain is now offline, the immediate threat is mitigated. However, users should remain vigilant against similar impersonation domains. PhishDestroy recommends verifying URLs directly through official Microsoft channels, avoiding unsolicited download links, and enabling multi-factor authentication to protect accounts. Organizations should monitor for related domains and educate employees about brand impersonation tactics to prevent future compromises.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
14 det.
OTX references
URLScan
URLScan
Сертифікат TLS
Starfield Technologies, Inc. / Starfield Secure Certificate Authority - G2
Вік
3 mo
Зафіксований статус
Останній відомий активний 200
PhishDestroy
DestroyList
У списку
Reports Sent
1
Обсяг даних12 recorded checks
VirusTotal 14 / 91 URLQuery checked — no detections recorded PhishStats не перевірено OTX 1 community reference CF Radar no data URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS не перевірено TLS valid certificate, 94d WHOIS 3 mo old Знімок екрана 2 captures · 2 sources Ланцюжок перенаправлень не досліджено

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
12/13
Загроза виявлена
microsoftauthenticatorappdownload.com виявлено та додано до черги для повного аналізу
08.05.2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
Аналіз URLScan завершено; цей результат веб-захоплення не змінює вердикт про загрозу сторінці · score 0
29.07.2026
VirusTotal
14/91 recorded on VirusTotal
26.07.2026
Google Safe Browsing
10.05.2026
Виявлення списків блокування
Знайдено в 2 blocklists: MetaMask, SEAL
09.08.2026
OTX Community References
1 community publication reference on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
08.05.2026
Brand Impersonation
Impersonation of Microsoft
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
Звіт містить збережені результати технологічного або криміналістичного аналізу.
09.08.2026
Sent Report Recorded
Stored sent-report record for registrar GoDaddy.com, LLC, hosting provider
08.05.2026
Опубліковано список «DestroyList»
08.05.2026
Monitoring Continues
Домен залишається доступним або обмеженим; майбутні перевірки можуть оновити це спостереження.

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
microsoftauthenticatorappdownload.com
Сертифікат TLS
Valid transport encryption · Виданий Starfield Technologies, Inc. / Starfield Secure Certificate Authority - G2 · valid for 94 days

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN DPS/2.0.0+sha-eafc77d · AS16509 Amazon.com, Inc.
Репутація IP abuse score 22/100 5 reports checked 13.07.2026
IP-адреса 76.223.105.230 US
ГеолокаціяUS Seattle, US
МережаAS16509 · AWS Global Accelerator (GLOBAL)
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяСтворено 08.05.2026 (93d)
Статус HTTP200
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено08.05.2026
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Сервери іменns18.domaincontrol.com
TLS Fingerprint
TLS Observationvalid from 27.04.2026scanned 08.05.2026
TLS SAN Domainssecureserversites.net
Favicon Hash
Case ID
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

14 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
CyRadar
Fortinet
G-Data
Gridinsoft
«Касперський»
LevelBlue
Lionic
SOCRadar
Sophos
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно
Вбудувати цей звітRead-only HTML widget
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/microsoftauthenticatorappdownload.com"
  title="PhishDestroy threat report for microsoftauthenticatorappdownload.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.