Scan report · about 2 months agoPublic

www.microsoft365.com

13.107.6.156AS8068 · US
Engine tags
Verdict

What happened

Step by step, from what the scanner recorded.
Load 5.5 s · 67 requests
01 · Visitor openswww.microsoft365.com
02 · Redirected · 1 hopm365.cloud.microsoft
03 · Page shown
Microsoft 365 Copilot - Sign instyled as Microsoft · high
04 · OutcomeCredential phishingA login page wearing a brand it does not own.

Be careful — warning signs found

Automated

It presents itself as Microsoft while being hosted somewhere Microsoft does not own. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.

What to do

Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.

"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.

Findings

Strongest first
SupportingBrand impersonation detected
Microsoft · high

The page presents itself as a known brand (brand keywords/branding detected).

Analyst noteHigh confidence: brand keywords AND a password field — classic credential phishing.

InfoCross-domain scripts injected at runtime
6 script(s)

The page dynamically injected scripts from other domains. This is extremely common on legitimate sites (CDNs, analytics, asset domains) and is shown for context only.

Analyst noteNoisy by itself — a CDN/asset domain (e.g. a brand's own *.githubassets.com) is normal. Only meaningful if the source domain is unrelated/suspicious.

Infrastructure

IP
13.107.6.156MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US · AS8068US
TLS
CN=Microsoft TLS G2 RSA CA OCSP 10, O=Microsoft Corporation, C=US · expires Nov 29, 2026
Redirects
1 hop · / → /

WHOIS

Registrar
MarkMonitor Inc.
Created
Apr 8, 2010
Expires
Apr 8, 2027
Nameservers
ns1-33.azure-dns.comns2-33.azure-dns.netns3-33.azure-dns.orgns4-33.azure-dns.info
3 malicious18 suspicious

Hashes & fingerprints

Page capture

Live

Title “Microsoft 365 Copilot - Sign in” · brand shown: Microsoft (high)

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
Microsoft 365 Copilot - Sign in
Load
5.49 s · 67 requests
Stack · 4Azure MonitorCart FunctionalityHSTSAzure