www.bing.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.bing.com and returned a suspicious verdict (score 47), categorised as phishing. The page resolved to 23.33.238.113 on Akamai Technologies, Inc. in AU. The domain was registered 11161 days ago through MarkMonitor Inc.. 13 domains and 2 IPs were contacted, over 3 HTTP requests. 6 malware samples communicate with this URL (DCOM, HUILoader, Dqan, Pioneer). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 47) · Confidence 53%
- Scanned URL:
http://tempuri.org/ - Domain: www.bing.com · IP: 23.33.238.113 · AS20940 · AU
- Page title: Search - Microsoft Bing
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: MarkMonitor Inc. · domain age 11161 days · created 1996-01-29
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 ECC CA OCSP 06 · valid to Feb 13 18: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=r.bing.com
- Evidenced operator: Microsoft Corporation
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-20 23:22:31 UTC
Redirect chain
http://tempuri.org/https://www.bing.com/
Malware communicating with this URL (6)
These samples were observed contacting or being served from www.bing.com. Each links to its full analysis.
- DCOM - referenced ·
7d18fff7b88f96be68f4862a87ab6991· first seen 2026-08-20 - HUILoader - referenced ·
873d4d51b4d4731068282ed3e42187bf· first seen 2026-08-20 - Dqan - referenced ·
4202c770b052b3aa9261f6cefe23e7db· first seen 2026-08-13 - Pioneer - referenced ·
fb5fe7139ff59c789db96368172fab18· first seen 2026-08-13 - Vindor - referenced ·
95aa37ee6cc9c4272dd703b9457840fa· first seen 2026-08-12 - Pioneer - referenced ·
43dca9f3895d301f90ada27c2622b538· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- phishing
Why this verdict
- Domain impersonates ing (typosquat)
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Contacted infrastructure
- 23.33.238.113 - AS20940 Akamai Technologies, Inc. (Australia)
- 20.112.250.133 - AS8075 Microsoft Corporation (United States)
Observed indicators
- www.bing.com
- r.bing.com
- www.msn.com
- outlook.com
- microsoft365.com
- www.onenote.com
- sway.office.com
- onedrive.live.com
- calendar.live.com
- outlook.live.com
- www.microsoft.com
- go.microsoft.com
- support.microsoft.com
- 23.33.238.113
- 20.112.250.133
- https://www.bing.com/
- https://www.bing.com/sa/simg/favicon-trans-bg-blue-mg-png.png
- https://r.bing.com/
- https://www.bing.com/chat?FORM=hpcodx&intent=bing
- https://www.bing.com/images?FORM=Z9LH
Other scans of www.bing.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious ·
https://steam-gifts.ir/ - 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
Questions about www.bing.com
- Is www.bing.com safe?
- No. MalwareAnalyzer scanned www.bing.com on 20 Aug 2026 and returned a suspicious verdict with a score of 47 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with www.bing.com?
- 6 analysed samples communicate with this URL, including DCOM, HUILoader, Dqan, Pioneer.
- How was www.bing.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.bing.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan