GrizzlyGrizzly
Recent phishing
Phishing

Impersonating Microsoft

Intent: Credential collection

  • Domain is not operated by Microsoft
  • TLS certificate has no organization information
  • Domain not registered through Microsoft's usual registrar
  • SPF record does not reference Microsoft's infrastructure

Microsoft-branded sign-in page with email/phone and password fields

Scanned 37 days ago · Aug 24, 2026, 12:28 UTC

Think this verdict is wrong?

Check a suspicious URL yourself — free to try.

Scan a URL
Phishing: www.login.microsoftonline.com-common-oauth2.agro-broker.com — Grizzly