Skip to content
Latest
Russian Auth-Flow Phishing Shows MFA Can Be Bypassed Without ExploitsFake AI Tools Show Brand Trust Has Become Malware DeliveryStopAndProtect Shows Why WordPress Sites Are Attack InfrastructureMacSync Stealer Shows Why Behavioral Pivots Beat Rotating DomainsPurpleDelta Shows Why Remote Hiring Is Now an Insider-Risk ControlGitLab GraphQL Flaw Shows Why DevSecOps Platforms Need Emergency Patch RunbooksForminator RCE Shows Why WordPress Plugin Risk Needs Runtime ControlsC2Looper Shows Why GitHub-Based C2 Belongs in Ransomware TriageVMware vCenter Exploitation Shows Why Patching Is Not Incident ClosureRansomware’s Long Tail Means Defenders Need Faster TriageAzure Directory Dumps Show Why Identity Data Is Attack InfrastructureSigned ClickOnce Shows Fake Interviews Are Now a Credential-Theft Delivery SystemDropcatch Domains Show Why Reputation Is Not TrustCaptiveCrunch Shows Why Travel Wi-Fi Is an Identity Attack Surface

Indicator of Compromise

ms365-device[.]com

Domain Seen in 2 reports Watch this →

A domain observed in malicious infrastructure. Block or monitor it in DNS and web proxies. Shown defanged for safe viewing; use Copy live value for the functional form.

Included in the Domains feed (live, machine-readable).

Related indicators

Indicators that appear alongside this one in the same reporting, often shared infrastructure or the same campaign.

104[.]194[.]159[.]150 31[.]57[.]243[.]154 38[.]146[.]28[.]75 be99857449d2856dd5a84e21c8a3d5e0e01456adb44062ddec5a6b4970d8d42c m365-owa[.]com ms365-live[.]com owa-ms365[.]com 107[.]189[.]18[.]7107[.]189[.]26[.]194125752ad7c20d715920a3b2fb0fdde660f07b3f2b053665cf38c2d6d9de86e1e196[.]251[.]107[.]1711d9299799a7b8da67c44ebec064d64542c27645f8e84de4a22ca3f6cbc843e3c1e3ee845fde739fcd3ca9ce62c7f142a7c501d11db4c4fb294d4939f12d0f91620e20b074967ed6f6e04d609ccec5ff7492665ef25f894c90c2ddc92fa47ac38213[.]145[.]86[.]11228f622028e690c943f7fa9aca426c07cab52b5aaba757ef8a3328609c0b3bec32c7f4165967d6f7737b3fef87959846920b57a5368b531ad1427c7214d4c41a238[.]146[.]28[.]132403b624e35777cbc07dbe66398b21bba70396a20b859c880732338ce1dd1f41f5b8d50c2e8cc3038b7c6e6dbf1219f6e814930a1e3c0053143a1191ae67f8ffc6f7090895c1c3dee30de6b3f098ca3a788dc198646e5293a8b1210430b0add97918fa52ae45ed60ba7cc8bdc99c3cbe9ab92e0375ec31fc05d0d4513be11c593a06a8fd1b6fa1924199a4540cf16d089217ce8f78c617739946f145fd1fc88c1bounce@chamber-ua[.]orgc5826032207d623a7f6caec8465af7364eccc355f9a48897da2a54f3e4420265ca3be5885afb3eb3bb19341e2653212200c568f3f900e0b2f04de9ba209aed25chamber-ua[.]org CVE-2026-21509 dosportal[.]appdrive[.]google[.]verify-drive[.]comfewfwfwfwfwf[.]infofinishoperations[.]comfinishoperations[.]orgfoc-share[.]comfoc-share[.]orgforeignrelations[.]usglobsec[.]netinternal-share[.]commail[.]kiis[.]co[.]ukmioisiskwowiwjowuwjwolab[.]club

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.