outlook.live.com - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned outlook.live.com and returned a benign verdict (score 0). The page resolved to 52.98.142.162 on Microsoft Corporation in AU. 1 domain and 3 IPs were contacted. 12 malware samples communicate with this URL (Maldoc, Picsys, Phish). The request followed 2 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 12%
- Scanned URL:
https://hotmail.com/ - Domain: outlook.live.com · IP: 52.98.142.162 · AS8075 · AU
- Server: Microsoft-HTTPAPI/2.0
- HTTP status: 417
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Jan 10 23: · subject C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=outlook.com
- Evidenced operator: Microsoft Corporation
- Scan tier: fast · observed 2026-08-23 04:07:24 UTC
Redirect chain
https://hotmail.com/https://outlook.live.com/owa/https://outlook.live.com/mail/
Malware communicating with this URL (12)
These samples were observed contacting or being served from outlook.live.com. Each links to its full analysis.
- a26adfcd47e2a8af71ceeb309a469f640fef2dcd0112aade04c604f96088a63c - referenced ·
a26adfcd47e2a8af71ceeb309a469f64· first seen 2026-08-23 - af088a66e5f53eda956ebdd8c023a313fb48a792c314f33133e8b7d1727ea25e - referenced ·
af088a66e5f53eda956ebdd8c023a313· first seen 2026-08-22 - 0bc60853b3d8f11d4b45ab77b9264655f665ff4bf1e033850701253e4c2149e0 - referenced ·
0bc60853b3d8f11d4b45ab77b9264655· first seen 2026-08-22 - 2c3bfdc1bd74cb690775958583469ba422b9ed7d541ddfec75cc42a44f7d7cbf - referenced ·
2c3bfdc1bd74cb690775958583469ba4· first seen 2026-08-22 - e0ddc6ff7a872010620a19ad7b3b26f32c45eceef3a04071cfd166d12acd7872 - referenced ·
e0ddc6ff7a872010620a19ad7b3b26f3· first seen 2026-08-21 - fbevents.js - referenced ·
5d8d4bb1186f740b55e9d632b68acc0b· first seen 2026-08-19 - Maldoc - referenced ·
a1ac90a30e2af65819bc80d3b2b795e2· first seen 2026-08-18 - Picsys - referenced ·
1cd707d8da6696fff45be9dc05457b5f· first seen 2026-08-16 - 4089e7a65b1df2d9be13c0462dafe0b713cec69641a214a7fcb6ca1a62525847 - referenced ·
4089e7a65b1df2d9be13c0462dafe0b7· first seen 2026-08-16 - fbevents.js - referenced ·
2cc00eb82ca36588f5678962dc8e19a1· first seen 2026-08-13 - fbevents.js - referenced ·
9b96a7411ab2e41dd12d819f7a4f3273· first seen 2026-08-13 - Phish - referenced ·
e294d7ebb555ee605c53f87cccb6e390· first seen 2026-08-11
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Contacted infrastructure
- 52.98.142.162 - AS8075 Microsoft Corporation (Australia)
- 204.79.197.212 - AS8068 Microsoft Corporation (United States)
- 52.98.14.130 - AS8075 Microsoft Corporation (Australia)
Observed indicators
- outlook.live.com
- 52.98.142.162
- 204.79.197.212
- 52.98.14.130
- https://outlook.live.com/mail/
Other scans of outlook.live.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - benign
- 23 Aug 2026 - suspicious ·
https://www.bing.com/ - 23 Aug 2026 - benign ·
https://www.microsoft.com/nl-nl/ - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - benign ·
https://www.microsoft.com/ja-jp - 23 Aug 2026 - suspicious ·
https://www.bing.com/ - 22 Aug 2026 - suspicious ·
https://www.bing.com/ - 22 Aug 2026 - suspicious ·
https://www.bing.com/ - 21 Aug 2026 - unknown ·
https://booking.endorphinfit.com/v2/ - 21 Aug 2026 - suspicious ·
https://www.bing.com/
Questions about outlook.live.com
- Is outlook.live.com safe?
- The scan of outlook.live.com on 23 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with outlook.live.com?
- 12 analysed samples communicate with this URL, including Maldoc, Picsys, Phish.
- How was outlook.live.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of outlook.live.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan