www.bing.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.bing.com and returned a suspicious verdict (score 47), categorised as phishing. The page resolved to 23.33.238.110 on Akamai Technologies, Inc. in AU. 13 domains and 2 IPs were contacted, over 3 HTTP requests. 13 malware samples communicate with this URL (Msilkrypt). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 47) · Confidence 53%
- Scanned URL:
http://tempuri.org/IUserService/GetUsersT - Domain: www.bing.com · IP: 23.33.238.110 · AS20940 · AU
- Page title: Search - Microsoft Bing
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 ECC CA OCSP 06 · valid to Feb 13 18: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=r.bing.com
- Evidenced operator: Microsoft Corporation
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-21 07:22:11 UTC
Redirect chain
http://tempuri.org/IUserService/GetUsersThttps://www.bing.com/
Malware communicating with this URL (13)
These samples were observed contacting or being served from www.bing.com. Each links to its full analysis.
- Msilkrypt - referenced ·
74d5229d6d688493e35ad361f2a815d6· first seen 2026-08-21 - Msilkrypt - referenced ·
16443babe4ab2a95469c4ac035e97a38· first seen 2026-08-21 - Msilkrypt - referenced ·
bbd6ac6ba7e1fd46ecb3efde63cbf945· first seen 2026-08-21 - Msilkrypt - referenced ·
adc5d19629dc5d21a0d02eae43f91250· first seen 2026-08-20 - Msilkrypt - referenced ·
9bb180849e1348de6dd205caacd0be82· first seen 2026-08-20 - Msilkrypt - referenced ·
297198e6d50620288014600e30f05d14· first seen 2026-08-20 - Msilkrypt - referenced ·
c73d06fdd1ff143df90d69eb517e4726· first seen 2026-08-20 - Msilkrypt - referenced ·
27c401e43bdab43295183c7b716a9a2d· first seen 2026-08-19 - Msilkrypt - referenced ·
a4cc71ad239f95b19ed850551f4a90ac· first seen 2026-08-19 - Msilkrypt - referenced ·
5a8f9f9f3ab696b43484266e8764f7c6· first seen 2026-08-19 - Msilkrypt - referenced ·
185f3d88aad251aeff2a097a7fe22239· first seen 2026-08-15 - Msilkrypt - referenced ·
d5899341d0bed59f68805b265af36748· first seen 2026-08-14 - Msilkrypt - referenced ·
baebbcde8266df90ae90a046d9a83f09· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- phishing
Why this verdict
- Domain impersonates ing (typosquat)
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Contacted infrastructure
- 23.33.238.110 - AS20940 Akamai Technologies, Inc. (Australia)
- 20.236.44.162 - AS8075 Microsoft Corporation (United States)
Observed indicators
- www.bing.com
- r.bing.com
- www.msn.com
- outlook.com
- microsoft365.com
- www.onenote.com
- sway.office.com
- onedrive.live.com
- calendar.live.com
- outlook.live.com
- www.microsoft.com
- go.microsoft.com
- support.microsoft.com
- 23.33.238.110
- 20.236.44.162
- https://www.bing.com/
- https://www.bing.com/sa/simg/favicon-trans-bg-blue-mg-png.png
- https://r.bing.com/
- https://www.bing.com/chat?FORM=hpcodx&intent=bing
- https://www.bing.com/images?FORM=Z9LH
Other scans of www.bing.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious
- 23 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious ·
https://steam-gifts.ir/ - 21 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
Questions about www.bing.com
- Is www.bing.com safe?
- No. MalwareAnalyzer scanned www.bing.com on 21 Aug 2026 and returned a suspicious verdict with a score of 47 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with www.bing.com?
- 13 analysed samples communicate with this URL, including Msilkrypt.
- How was www.bing.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.bing.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan