m365.cloud.microsoft - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned m365.cloud.microsoft and returned a malicious verdict (score 72), categorised as phishing. The page resolved to 13.107.6.156 on Microsoft Corporation in US. The domain was registered 3981 days ago through MarkMonitor Inc.. 17 domains and 14 IPs were contacted, over 58 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 72) · Confidence 78%
- Scanned URL:
https://m365.cloud.microsoft/ - Domain: m365.cloud.microsoft · IP: 13.107.6.156 · AS8068 · US
- Page title: OK
- HTTP status: 200 · text/html
- Registrar: MarkMonitor Inc. · domain age 3981 days · created 2015-09-25
- Registrant country: US
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 RSA CA OCSP 10 · valid to Nov 29 23: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=m365.cloud.microsoft
- Evidenced operator: Microsoft Corporation
- HTTP requests captured: 58 · cookies set: 15 · outgoing links: 207
- Scan tier: standard · observed 2026-08-20 06:25:54 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Runtime data beacon to y.clarity.ms
- Domain impersonates icloud (typosquat)
Contacted infrastructure
- 13.107.6.156 - AS8068 Microsoft Corporation (United States)
- 13.107.246.31 - AS8075 Microsoft Corporation (United States)
- 150.171.109.24 - AS8075 Microsoft Corporation (United States)
- 52.123.252.203 - AS8075 Microsoft Corporation (Australia)
- 20.190.167.66 - AS8075 Microsoft Corporation (Australia)
- 4.150.223.108 - AS8075 Microsoft Corporation (United States)
Observed indicators
- m365.cloud.microsoft
- res.cdn.office.net
- www.microsoft.com
- uhf.microsoft.com
- mem.gfx.ms
- www.clarity.ms
- c.s-microsoft.com
- login.microsoftonline.com
- scripts.clarity.ms
- js.monitor.azure.com
- aadcdn.msauth.net
- config.edge.skype.com
- admin.microsoft.com
- y.clarity.ms
- login.live.com
- logincdn.msauth.net
- browser.events.data.microsoft.com
- 13.107.6.156
- 23.40.52.76
- 104.68.18.169
Other scans of m365.cloud.microsoft (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Jul 2026 - benign ·
https://www.office.com/ - 20 Jul 2026 - suspicious ·
https://m365.cloud.microsoft/?origindomain=microsoft365
Questions about m365.cloud.microsoft
- Is m365.cloud.microsoft safe?
- No. MalwareAnalyzer scanned m365.cloud.microsoft on 20 Aug 2026 and returned a malicious verdict with a score of 72 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was m365.cloud.microsoft checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of m365.cloud.microsoft
Scanned on MalwareAnalyzer by Cyble · Open interactive scan