auth-live-doc-ms0365-sharepoint.site
Appeared in the .site zone on Tuesday, September 15, 2026; by the end of that day the census found active website. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
Domain string 'auth-live-doc-ms0365-sharepoint.site' stacks Microsoft identifiers (live, ms0365, SharePoint) with an auth lure, and the hosted page is a classic SharePoint-style 'Proposal & Bid Documents — Secure Access' file-selection gate that funnels victims to a Microsoft 365 credential prompt; Vercel-hosted throwaway infrastructure fits the pattern.
Domain impersonates Microsoft SharePoint with 'ms0365-sharepoint' in the name and uses 'auth-live-doc' lure words to create false urgency around secure document access. The page presents a document-selection interface mimicking SharePoint's file portal, designed to trick users into believing they are accessing legitimate corporate documents on Microsoft infrastructure when they are actually on an attacker-controlled Vercel domain.
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
Same data as JSON: /api/zone/domain/auth-live-doc-ms0365-sharepoint.site. This page is not indexed by search engines and does not link to the site it describes.