Phishing detection: hotmail-session-npxtxkjz-74ectpfbf-----4sdlycfflk.kharwadejewellers.com

Microsoft
https://hotmail-session-npxtxkjz-74ectpfbf-----4sdlycfflk.kharwadejewellers.com Access site
Screenshot
Screenshot of hotmail-session-npxtxkjz-74ectpfbf-----4sdlycfflk.kharwadejewellers.com
Investigate
Domain hotmail-session-npxtxkjz-74ectpfbf-----4sdlycfflk.kharwadejewellers.com1 CT host on apex
URL https://hotmail-session-npxtxkjz-74ectpfbf-----4sdlycfflk.k…
Phishunt analysis Beta
28 low suspicionheuristic risk score · not a probability
Keyword matchLong domainHyphens
16 signals fired · detector v2.0.0
AI analysis AIBeta
Credential harvesting

Hotmail credential harvesting page using a randomized per-victim subdomain under a compromised jewellery domain hosted at RouterHosting LLC. Flagged as social engineering by Google Safe Browsing and confirmed malicious by OpenPhish. Part of a large coordinated campaign sharing a single IP.

OpenPhishGoogle Safe BrowsingKeyword match
AI-generated from stored detector signals - the AI never visited the site. · 2026-08-20 · confidence 85%
Domain & Network
Whois
Registrar GoDaddy.com, LLC
Network
Country United StatesUnited States
ASN AS14956
TLS Cert -
External detection Google Safe Browsing OpenPhish
GSB category: SOCIAL_ENGINEERING
CleanPhishTank · TweetFeed · urlscan.io
Report this phishing

Tracked from 2026-08-20 01:02 UTC  ·  Last refreshed 2026-08-20 01:30 UTC