microsoft[.]comunicazioni-sicure[.]it
“microsoft.comunicazioni-sicure.it”
microsoft.comunicazioni-sicure.it — 未验证. 品牌冒充:Microsoft; 诈骗类型:Tech Support Scam. 证据摘要: VirusTotal 10/91 (ADMINUSLabs, Criminal IP, CyRadar, ESET, Fortinet); URLQuery 100 det.; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: Aruba s.p.a.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of microsoft.comunicazioni-sicure.it shows a high‑risk brand‑impersonation infrastructure targeting Microsoft. The domain was registered on October 05, 2023 through Aruba s.p.a. and resolves to 52.212.77.68, an address owned by Amazon.com, Inc. (AS16509) located in Ireland. DNS is served by technorail.com and arubadns.net name servers. The site presents an HTTP 200 response and serves a Sectored DV certificate (Sectigo Limited / Sectigo Public Server Authentication CA DV R36). HSTS is enabled. Security telemetry indicates a Gridinsoft trust score of 0/100 and 19 of 93 VirusTotal scanners flag the domain, placing it on at least one blocklist. PhishDestroy has already blocked the site. The page title mirrors the domain, and the campaign is classified as a Tech Support Scam, explicitly impersonating Microsoft. While the exact content of the page has not been examined, the combination of a brand‑specific title, malicious hosting, low trust score, and multiple vendor detections suggests active malicious intent. Defenders should block the domain and its resolving IP at network perimeter devices, monitor DNS queries for the listed name servers, and add the indicator to threat‑intel feeds. Continuous re‑evaluation is advised in case the infrastructure evolves or additional payloads are observed.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 1 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。