Phishing detection: microsoftadmin.previewship.net
Microsoft Investigate
Domain
microsoftadmin.previewship.net1 CT host on apex
IP
172.67.147.18
URL
https://microsoftadmin.previewship.net
Cert
WE1
Phishunt analysis Beta
19
noiseheuristic risk score · not a probability
Why?
- +5.3 Keyword match
- +5.1 Site cluster
- +3.0 OpenPhish
- +1.5 ASN reputation
- +1.1 No CSP header
- +0.8 Young domain
- +0.6 Long domain
- +0.6 Login text in screenshot
- +0.6 Script exfil endpoint
- +0.3 Free CA
- +0.2 Suspicious TLD
- +0.1 Deep subdomain
14 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Microsoft admin-themed page on a preview-hosting subdomain fronted by Cloudflare, likely a credential-harvesting lure impersonating Microsoft sign-in. Flagged by OpenPhish, with resources reused across other detections.
OpenPhishShared page assetsKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-30 · confidence 65%
Domain & Network
Whois
Registrar
Cloudflare, Inc.
Network
Country
United States
Hosting
Cloudflare, Inc.
ASN
AS13335
TLS Cert
WE1
External detection
OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise