learn.microsoft.com - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned learn.microsoft.com and returned a unknown verdict (score 4). The page resolved to 23.221.133.219 on Akamai Technologies, Inc. in AU. The domain was registered 12894 days ago through MarkMonitor Inc.. 8 domains and 2 IPs were contacted, over 3 HTTP requests. 3 malware samples communicate with this URL (Lazy, HUILoader). The request followed 2 redirects before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 4) · Confidence 43%
- Scanned URL:
https://aka.ms/GlobalizationInvariantMode - Domain: learn.microsoft.com · IP: 23.221.133.219 · AS16625 · AU
- Page title: Globalization config settings - .NET | Microsoft Learn
- HTTP status: 200 · text/html
- Registrar: MarkMonitor Inc. · domain age 12894 days · created 1991-05-02
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 ECC CA OCSP 02 · valid to Dec 11 02: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=learn.microsoft.com
- Evidenced operator: Microsoft Corporation
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-21 02:58:53 UTC
Redirect chain
https://aka.ms/GlobalizationInvariantModehttps://learn.microsoft.com/en-us/dotnet/core/run-time-config/globalization?ranMID=46131&ranEAID=a1LgFw09t88&ranSiteID=a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg&epi=a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg&irgwc=1&OCID=AID2000142_aff_7806_1243925&tduid=%28ir__mrdukhopi0kfqxeykk0sohzifv2xuvvxe2xvqk3y00%29%287806%29%281243925%29%28a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg%29%28%29&irclickid=_mrdukhopi0kfqxeykk0sohzifv2xuvvxe2xvqk3y00#invariant-modehttps://learn.microsoft.com/en-us/dotnet/core/runtime-config/globalization?ranMID=46131&ranEAID=a1LgFw09t88&ranSiteID=a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg&epi=a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg&irgwc=1&OCID=AID2000142_aff_7806_1243925&tduid=%28ir__mrdukhopi0kfqxeykk0sohzifv2xuvvxe2xvqk3y00%29%287806%29%281243925%29%28a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg%29%28%29&irclickid=_mrdukhopi0kfqxeykk0sohzifv2xuvvxe2xvqk3y00
Malware communicating with this URL (3)
These samples were observed contacting or being served from learn.microsoft.com. Each links to its full analysis.
- Lazy - referenced ·
2cba01a2b8c4d45a37e70cdd96dc1eb1· first seen 2026-08-21 - HUILoader - referenced ·
c3bd9003c2a8b57c18442587a4d35f1b· first seen 2026-08-17 - Lazy - referenced ·
613dd576ff9f6b44e958e1f7df34123b· first seen 2026-08-16
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Contacted infrastructure
- 23.221.133.219 - AS16625 Akamai Technologies, Inc. (Australia)
- 23.35.101.160 - AS16625 Akamai Technologies, Inc. (Japan)
Observed indicators
- learn.microsoft.com
- wcpstatic.microsoft.com
- js.monitor.azure.com
- go.microsoft.com
- github.com
- aka.ms
- techcommunity.microsoft.com
- www.microsoft.com
- 23.221.133.219
- 23.35.101.160
- https://learn.microsoft.com/en-us/dotnet/core/runtime-config/globalization?ranMID=46131&ranEAID=a1LgFw09t88&ranSiteID=a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg&epi=a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg&irgwc=1&OCID=AID2000142_aff_7806_1243925&tduid=%28ir__mrdukhopi0kfqxeykk0sohzifv2xuvvxe2xvqk3y00%29%287806%29%281243925%29%28a1LgFw09t88-TL.gIntYvAARbx7QNuWPjg%29%28%29&irclickid=_mrdukhopi0kfqxeykk0sohzifv2xuvvxe2xvqk3y00
- https://learn.microsoft.com/en-us/dotnet/core/runtime-config/globalization
- https://learn.microsoft.com/static/assets/0.4.03512.8135-66b9c479/styles/site.css
- https://wcpstatic.microsoft.com/mscc/lib/v2/wcp-consent.js
- https://js.monitor.azure.com/scripts/c/ms.jsll-4.min.js
- https://learn.microsoft.com/static/assets/0.4.03512.8135-66b9c479/scripts/en-us/index-docs.js
- https://go.microsoft.com/fwlink/p/?LinkID=2092881
- https://learn.microsoft.com/en-us/lifecycle/faq/internet-explorer-microsoft-edge
- https://github.com/dotnet/docs/blob/main/docs/core/runtime-config/globalization.md
- https://github.com/dotnet/runtime/blob/main/docs/design/features/globalization-invariant-mode.md
Other scans of learn.microsoft.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://dotnet.microsoft.com/en-us/download/dotnet?cid=getdotnetcore - 23 Aug 2026 - benign ·
https://www.microsoft.com/nl-nl/ - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/ - 22 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/ - 22 Aug 2026 - unknown ·
https://www.nuget.org/packages/Newtonsoft.Json.Bson - 21 Aug 2026 - suspicious ·
https://umicrosoft.com/ - 21 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/ - 21 Aug 2026 - unknown ·
https://learn.microsoft.com/en-us/sysinternals/
Questions about learn.microsoft.com
- Is learn.microsoft.com safe?
- The scan of learn.microsoft.com on 21 Aug 2026 reached no verdict either way (score 4). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with learn.microsoft.com?
- 3 analysed samples communicate with this URL, including Lazy, HUILoader.
- How was learn.microsoft.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of learn.microsoft.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan