wwwmicrosaftonlinecheck.lat
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of wwwmicrosaftonlinecheck.lat
This domain appears to host a login page designed to resemble a Microsoft account sign-in screen. The page title is "Sign In," and the screenshot shows a familiar email/phone/Skype login prompt with Microsoft-style branding elements, suggesting the site is attempting to present itself as an online account access portal.
Based on the domain name, however, the site does not appear to be an official Microsoft-owned domain. The string "wwwmicrosaftonlinecheck" closely imitates Microsoft's brand while using a misspelled variation of the company name and an unrelated country-code top-level domain. No legitimate organizational details or operator information were provided in the scan data, which makes the true ownership unclear.
Safety Assessment for wwwmicrosaftonlinecheck.lat
Several risk indicators were present at the time of this scan. The domain was flagged by 2 out of 91 security engines, and a major blacklist database listed it for social-engineering activity. In addition, the page content appears to imitate a Microsoft sign-in experience while using a domain name that closely resembles the Microsoft brand but does not match the company's official web properties.
The domain is also extremely new, with a recorded age of 0 days, and it is not ranked among widely visited sites. Newly created domains that mimic well-known login portals may be used in credential-harvesting campaigns before broader detection catches up. Although the malware scan did not identify malicious files during this check, phishing pages often contain little or no overt malware and instead rely on deceptive branding and login forms.
Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was reachable over HTTPS with a valid Let's Encrypt certificate expiring on 2026-08-20. It appears to be served by nginx from an IP address hosted by Evoxt in Los Angeles, United States. DNSSEC was not enabled, and the domain uses registrar-provided nameservers.
From a technical standpoint, the infrastructure is fairly minimal and recently provisioned. The combination of a brand-imitating domain, very recent registration, and a simple login-style page may be consistent with short-lived phishing infrastructure, even though no malicious files were detected at the time of the scan.
Share your experience with this website. Was it safe? Did you encounter any issues?