autoconfig.microsoft-portai.com - malicious URL scan, 22 Aug 2026

MalwareAnalyzer by Cyble scanned autoconfig.microsoft-portai.com and returned a malicious verdict (score 90), categorised as phishing, credential-harvest, impersonating microsoft. The page resolved to 80.81.24.207 on M-net Telekommunikations GmbH in DE. The domain was registered 1023 days ago through EuroDNS S.A.. 1 domain and 1 IP were contacted, over 12 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.

Scan result

Antivirus & YARA (1 of 48 engines)

Categories

Why this verdict

Detected technologies

Contacted infrastructure

Observed indicators

Questions about autoconfig.microsoft-portai.com

Is autoconfig.microsoft-portai.com safe?
No. MalwareAnalyzer scanned autoconfig.microsoft-portai.com on 22 Aug 2026 and returned a malicious verdict with a score of 90 out of 100, categorised as phishing and credential-harvest. Treat it as hostile until it is re-checked.
Does autoconfig.microsoft-portai.com belong to microsoft?
No. This page claims the identity of microsoft but nothing establishes that microsoft operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
How was autoconfig.microsoft-portai.com checked?
A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.

Scanned at the standard tier - see how URL scanning works.

Scan another URL · Latest analyzed threats · All scans of autoconfig.microsoft-portai.com · Other microsoft phishing domains

Scanned on MalwareAnalyzer by Cyble · Open interactive scan