Office 365 Phishing Attempt from XBOX.COM

Beware, there is an e-mail going around that supposedly comes from xbox.com, it contains a link to a fake Office 365 login page that is likely harvesting credentials. The link in the e-mail goes to https://srv2.azurewebsites.net/utf8BbNCZ2lu.html#[email protected]

Reported it to M$ but so far nothing has been done, site is still up.

Here is a copy of the e-mail...

From: [email protected] [mailto:[email protected]]
Sent: Monday, August 27, 2018 7:49 AM
To: XXXXXXXXX
Subject: Syncing error - (7) failed messages
Importance: High

This mail is from a trusted sender.

ohjkj.png

Dear [email protected].
Office 365 has prevented the delivery of 7 new emails to your inbox as of Aug 27, 2018 06:00 AM because it identified these messages as spam.

You can review these here and choose what happens to them.

Retrieve Message

Best regards,

© 2018 Microsoft Corporation. All rights reserved. | Acceptable Use Policy | Privacy Notice

I did received the same few days back.

@Rajeshi_Gardner Hi Mate, Few of my bank employees had visited this link as per proxy logs and it shows successful connections.