learn.microsoft.com - URL scan, 12 Aug 2026
MalwareAnalyzer by Cyble scanned learn.microsoft.com and returned a unknown verdict (score 4). The page resolved to 23.221.133.219 on Akamai Technologies, Inc. in AU. The domain was registered 12886 days ago through MarkMonitor Inc.. 9 domains and 2 IPs were contacted, over 3 HTTP requests. 1 malware sample communicates with this URL (Vindor). The request followed 2 redirects before landing. This is a point-in-time observation from 12 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 4) · Confidence 43%
- Scanned URL:
https://aka.ms/dotnet/app-launch-failed - Domain: learn.microsoft.com · IP: 23.221.133.219 · AS16625 · AU
- Page title: Troubleshoot app launch failures - .NET | Microsoft Learn
- HTTP status: 200 · text/html
- Registrar: MarkMonitor Inc. · domain age 12886 days · created 1991-05-02
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 ECC CA OCSP 02 · valid to Dec 11 02: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=learn.microsoft.com
- Evidenced operator: Microsoft Corporation
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-12 17:37:42 UTC
Redirect chain
https://aka.ms/dotnet/app-launch-failedhttps://learn.microsoft.com/dotnet/core/runtime-discovery/troubleshoot-app-launchhttps://learn.microsoft.com/en-us/dotnet/core/runtime-discovery/troubleshoot-app-launch
Malware communicating with this URL (1)
These samples were observed contacting or being served from learn.microsoft.com. Each links to its full analysis.
- Vindor - referenced ·
95aa37ee6cc9c4272dd703b9457840fa· first seen 2026-08-12
Antivirus & YARA (1 of 44 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Contacted infrastructure
- 23.221.133.219 - AS16625 Akamai Technologies, Inc. (Australia)
Observed indicators
- learn.microsoft.com
- wcpstatic.microsoft.com
- js.monitor.azure.com
- go.microsoft.com
- github.com
- dotnet.microsoft.com
- aka.ms
- techcommunity.microsoft.com
- www.microsoft.com
- 23.221.133.219
- 23.46.201.253
- https://learn.microsoft.com/en-us/dotnet/core/runtime-discovery/troubleshoot-app-launch
- https://learn.microsoft.com/static/assets/0.4.03508.8106-e78dd8a7/styles/site.css
- https://wcpstatic.microsoft.com/mscc/lib/v2/wcp-consent.js
- https://js.monitor.azure.com/scripts/c/ms.jsll-4.min.js
- https://learn.microsoft.com/static/assets/0.4.03508.8106-e78dd8a7/scripts/en-us/index-docs.js
- https://go.microsoft.com/fwlink/p/?LinkID=2092881
- https://learn.microsoft.com/en-us/lifecycle/faq/internet-explorer-microsoft-edge
- https://github.com/dotnet/docs/blob/main/docs/core/runtime-discovery/troubleshoot-app-launch.md
- https://learn.microsoft.com/en-us/dotnet/core/deploying/#publish-as-framework-dependent
Other scans of learn.microsoft.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://dotnet.microsoft.com/en-us/download/dotnet?cid=getdotnetcore - 23 Aug 2026 - benign ·
https://www.microsoft.com/nl-nl/ - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/ - 22 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/ - 22 Aug 2026 - unknown ·
https://www.nuget.org/packages/Newtonsoft.Json.Bson - 21 Aug 2026 - suspicious ·
https://umicrosoft.com/ - 21 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/ - 21 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/
Questions about learn.microsoft.com
- Is learn.microsoft.com safe?
- The scan of learn.microsoft.com on 12 Aug 2026 reached no verdict either way (score 4). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with learn.microsoft.com?
- 1 analysed samples communicate with this URL, including Vindor.
- How was learn.microsoft.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of learn.microsoft.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan