Phishing detection: office365.internal-alerts.com

Microsoft
https://office365.internal-alerts.com/i/d5b9af0d256f14c03ab8396a78d3687bf Access site
Screenshot
Screenshot of office365.internal-alerts.com
Investigate
Domain office365.internal-alerts.com1 CT host on apex
URL https://office365.internal-alerts.com/i/d5b9af0d256f14c03ab…
Phishunt analysis Beta
24 low suspicionheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +5.1 urlscan.io
  • +3.0 OpenPhish
  • +2.2 Country mismatch
  • +2.0 Site cluster
  • +1.5 ASN reputation
  • +1.1 No HSTS header
  • +0.9 Young certificate
  • +0.6 Brand impersonation in path
  • +0.6 Long domain
  • +0.6 Login text in screenshot
  • +0.3 Free CA
  • +0.2 Suspicious TLD
  • +0.1 Hyphens
  • +0.1 Deep subdomain
18 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Site impersonating Microsoft Office 365, hosted under a domain crafted to resemble an internal alert service. Contains login-themed text aimed at stealing credentials. Flagged as phishing by both OpenPhish and urlscan.

Brand impersonation in pathLogin text in screenshotOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-24 · confidence 85%
Domain & Network
Whois
Registrar Dynadot Inc
Network
Country IrelandIreland
ASN AS8075
TLS Cert R13
External detection OpenPhish urlscan.io
CleanGoogle Safe Browsing · PhishTank · TweetFeed
Report this phishing
Network / ASN Microsoft Corporation
Registrar Dynadot Inc

Tracked from 2026-03-28 01:01 UTC  ·  Last refreshed 2026-08-24 09:30 UTC