Phishing detection: microsoft-advertising-authentification.sgn-1.com

Microsoft
http://microsoft-advertising-authentification.sgn-1.com/signin/login.html Access site
Screenshot
Screenshot of microsoft-advertising-authentification.sgn-1.com

Screenshot captured by urlscan.io on 2026-09-11T13:01 UTC: our own render of this page came back blank.

Investigate
Domain microsoft-advertising-authentification.sgn-1.com4 CT hosts on apex
URL http://microsoft-advertising-authentification.sgn-1.com/sig…
Phishunt analysis Beta
32 medium suspicion suspiciousheuristic risk score · not a probability
Why?
  • +6.1 Google Safe Browsing
  • +5.3 Keyword match
  • +4.1 Site cluster
  • +3.0 OpenPhish
  • +2.6 Brand in subdomain
  • +2.2 Country mismatch
  • +1.7 Shared IP cluster
  • +1.1 No CSP header
  • +1.1 No HSTS header
  • +0.8 Young domain
  • +0.7 Brand typo
  • +0.6 Long domain
  • +0.6 Login text in screenshot
  • +0.6 Registrar reputation
  • +0.6 Script exfil endpoint
  • +0.4 Credential path
  • +0.3 Hyphens
  • +0.2 Suspicious TLD
  • +0.1 Deep subdomain
21 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Impersonates Microsoft Advertising via a fake authentication page hosted in the Netherlands. Google Safe Browsing flags it as social engineering, a script exfiltration endpoint confirms active credential theft, and the server IP is shared with another high-confidence phishing site.

Google Safe BrowsingScript exfil endpointOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-11 · confidence 94%
Domain & Network
Whois
Network
Country The NetherlandsThe Netherlands
ASN AS14956
TLS Cert -
External detection Google Safe Browsing OpenPhish
GSB category: SOCIAL_ENGINEERING
CleanPhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-09-11 13:02 UTC  ·  Last refreshed 2026-09-11 15:30 UTC