Scan report · 16 days agoPublic

apps.microsoft.com

13.107.213.53AS8075 · US
Verdict

Looks safe

Automated

Our automated checks did not find known threat signals on this site at the time of the scan.

What to do

No action needed. Stay alert as usual — a clean result reflects this scan only, and sites can change after they are checked.

A clean result means no known threat signals were found in this scan — it is not an absolute guarantee, and a site can change after it is checked.

Findings

Strongest first
SupportingPage hands the visitor an installer from another domain
https://the.earth.li/~sgtatham/putty/0.85/w64/putty-64bit-0.85-installer.msi

The page's own script names an executable installer hosted on a different domain, rather than offering it as an ordinary download link.

Analyst noteThe URL was read from an inline script, so it is what the page INTENDS to deliver — a download may not have been observed. Check who operates the instance in the URL, and treat a remote-access tool offered by an unrelated lure page as a compromise attempt.

InfoCross-domain scripts injected at runtime
2 script(s)

The page dynamically injected scripts from other domains. This is extremely common on legitimate sites (CDNs, analytics, asset domains) and is shown for context only.

Analyst noteNoisy by itself — a CDN/asset domain (e.g. a brand's own *.githubassets.com) is normal. Only meaningful if the source domain is unrelated/suspicious.

Infrastructure

IP
13.107.213.53MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US · AS8075US
TLS
CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US · expires Dec 21, 2026
5 malicious6 suspicious

Hashes & fingerprints

Page capture

Live

Title “PuTTY - Download and install on Windows | Microsoft Store”

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
PuTTY - Download and install on Windows | Microsoft Store
Load
4.65 s · 124 requests
Stack · 9Azure Front DoorAzure MonitorHSTSMicrosoft ASP.NETOpen GraphPriority Hints