learn.microsoft.com - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned learn.microsoft.com and returned a unknown verdict (score 4). The page resolved to 23.221.133.219 on Akamai Technologies, Inc. in AU. The domain was registered 12894 days ago through MarkMonitor Inc.. 11 domains and 3 IPs were contacted, over 3 HTTP requests. 15 malware samples communicate with this URL (Container, QQpass, Swisyn, Genpack). The request followed 3 redirects before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 4) · Confidence 43%
- Scanned URL:
http://www.sysinternals.com/ - Domain: learn.microsoft.com · IP: 23.221.133.219 · AS16625 · AU
- Page title: Sysinternals - Sysinternals | Microsoft Learn
- HTTP status: 200 · text/html
- Registrar: MarkMonitor Inc. · domain age 12894 days · created 1991-05-02
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 ECC CA OCSP 02 · valid to Dec 11 02: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=learn.microsoft.com
- Evidenced operator: Microsoft Corporation
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-20 21:27:29 UTC
Redirect chain
http://www.sysinternals.com/https://docs.microsoft.com/sysinternals/https://learn.microsoft.com/sysinternals/https://learn.microsoft.com/en-us/sysinternals/
Malware communicating with this URL (15)
These samples were observed contacting or being served from learn.microsoft.com. Each links to its full analysis.
- Container - referenced ·
b88dda60f19be903d7f42edb65211e73· first seen 2026-08-20 - QQpass - referenced ·
69cb6171f3bbfc5bbb6a46911a8e6bcf· first seen 2026-08-20 - Swisyn - referenced ·
62cdc5525f13a9d7f6fb926b9c409452· first seen 2026-08-20 - QQpass - referenced ·
f3bac5e643a73868a612f68e7bbcef11· first seen 2026-08-19 - Genpack - referenced ·
b82767b5c45e796aea0f186decd5799a· first seen 2026-08-18 - Swisyn - referenced ·
341457750464b93dbf1932696f5d882c· first seen 2026-08-17 - Ulise - referenced ·
6c96e1f0ffd6a47d1997947c0c418c15· first seen 2026-08-16 - QQpass - referenced ·
812f5128071874e5333f08808fa30fd6· first seen 2026-08-15 - Swisyn - referenced ·
457f72c50d741f2f8d01062a8b8d1c63· first seen 2026-08-13 - Barys - referenced ·
702e2b42f58ac93fa622db6161bdd116· first seen 2026-08-13 - Swisyn - referenced ·
acbc0d6710b1d4e3f35eb2337487263e· first seen 2026-08-13 - Swisyn - referenced ·
e59d67e4c6db1fb4a19186f7856ade9e· first seen 2026-08-13 - Emotet - referenced ·
f2912ad18a8a68b6f427c01b3287f1e8· first seen 2026-08-13 - Swisyn - referenced ·
723d62f72c4ed628424e20858480c7fe· first seen 2026-08-12 - RootkitRevealer - referenced ·
53a3c7cb7644d82a4c64f584a0e8572b· first seen 2026-08-11
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Contacted infrastructure
- 23.221.133.219 - AS16625 Akamai Technologies, Inc. (Australia)
- 20.231.239.246 - AS8075 Microsoft Corporation (United States)
- 184.27.40.221 - AS16625 Akamai Technologies, Inc. (Australia)
Observed indicators
- learn.microsoft.com
- wcpstatic.microsoft.com
- js.monitor.azure.com
- go.microsoft.com
- blogs.technet.microsoft.com
- techcommunity.microsoft.com
- www.youtube.com
- aka.ms
- live.sysinternals.com
- github.com
- www.microsoft.com
- 23.221.133.219
- 20.231.239.246
- 184.27.40.221
- https://learn.microsoft.com/en-us/sysinternals/
- https://learn.microsoft.com/static/assets/0.4.03512.8135-66b9c479/styles/site.css
- https://wcpstatic.microsoft.com/mscc/lib/v2/wcp-consent.js
- https://js.monitor.azure.com/scripts/c/ms.jsll-4.min.js
- https://learn.microsoft.com/static/assets/0.4.03512.8135-66b9c479/scripts/en-us/index-docs.js
- https://go.microsoft.com/fwlink/p/?LinkID=2092881
Other scans of learn.microsoft.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://dotnet.microsoft.com/en-us/download/dotnet?cid=getdotnetcore - 23 Aug 2026 - benign ·
https://www.microsoft.com/nl-nl/ - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://www.nuget.org/packages/Newtonsoft.Json.Bson - 21 Aug 2026 - suspicious ·
https://umicrosoft.com/ - 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
Questions about learn.microsoft.com
- Is learn.microsoft.com safe?
- The scan of learn.microsoft.com on 20 Aug 2026 reached no verdict either way (score 4). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with learn.microsoft.com?
- 15 analysed samples communicate with this URL, including Container, QQpass, Swisyn, Genpack.
- How was learn.microsoft.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of learn.microsoft.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan