Phishing detection: office365.rricrosoft-offices.org

Microsoft
https://office365.rricrosoft-offices.org/i/df3667320560f4a8a9918ef9f3f4c4383 Access site
Screenshot
Screenshot of office365.rricrosoft-offices.org
Investigate
Domain office365.rricrosoft-offices.org1 CT host on apex
URL https://office365.rricrosoft-offices.org/i/df3667320560f4a8…
Phishunt analysis Beta
17 noiseheuristic risk score · not a probability
Why?
  • +5.3 Keyword match
  • +3.0 OpenPhish
  • +2.2 Country mismatch
  • +1.4 ASN reputation
  • +1.1 No HSTS header
  • +1.0 Site cluster
  • +0.6 Brand impersonation in path
  • +0.6 Long domain
  • +0.6 Login text in screenshot
  • +0.3 Free CA
  • +0.2 Suspicious TLD
  • +0.1 Hyphens
  • +0.1 Deep subdomain
16 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting

Impersonates Microsoft Office 365 via a domain typosquatting 'microsoft' with a double-r substitution. Login keywords detected in page text and the domain is hosted on Microsoft Azure in Ireland. Flagged by OpenPhish as malicious.

Brand impersonation in pathLogin text in screenshotOpenPhish
AI-generated from stored detector signals - the AI never visited the site. · 2026-07-23 · confidence 85%
Domain & Network
Whois
Registrar Dynadot Inc
Network
Country IrelandIreland
ASN AS8075
TLS Cert R12
External detection OpenPhish
CleanGoogle Safe Browsing · PhishTank · TweetFeed · urlscan.io
Report this phishing
Network / ASN Microsoft Corporation
Registrar Dynadot Inc

Tracked from 2026-06-17 01:06 UTC  ·  Last refreshed 2026-09-05 03:30 UTC