www.office.com - URL scan, 20 Jul 2026
MalwareAnalyzer by Cyble scanned www.office.com and returned a benign verdict (score 0). The page resolved to 23.103.236.19. 56 domains and 15 IPs were contacted, over 66 HTTP requests. This is a point-in-time observation from 20 Jul 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 10%
- Scanned URL:
https://www.office.com/ - Domain: www.office.com · IP: 23.103.236.19
- Server: Microsoft-HTTPAPI/2.0
- Page title: Microsoft 365 | Write, Create & Collaborate with AI
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 RSA CA OCSP 10 · valid to Feb 12 19: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=portal.office.com
- Evidenced operator: Microsoft Corporation
- HTTP requests captured: 66 · cookies set: 15 · outgoing links: 180
- Scan tier: standard · observed 2026-07-20 19:25:50 UTC
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Observed indicators
- www.office.com
- res.cdn.office.net
- www.microsoft.com
- portal.office.com
- outlook.office.com
- login.microsoftonline.com
- shell.cdn.office.net
- appsforoffice.microsoft.com
- ocws.officeapps.live.com
- graph.microsoft.com
- substrate.office.com
- arc.msn.com
- uhf.microsoft.com
- m365.cloud.microsoft
- copilot.cloud.microsoft
- azure.microsoft.com
- copilot.microsoft.com
- www.xbox.com
- support.microsoft.com
- apps.microsoft.com
Other scans of www.office.com (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Jul 2026 - benign
- 20 Jul 2026 - benign
- 20 Jul 2026 - benign
Questions about www.office.com
- Is www.office.com safe?
- The scan of www.office.com on 20 Jul 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- How was www.office.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.office.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan