Security Scan Report: microsoftgeek.com

Site favicon
Submitted: Sep 14, 2026, 8:47:27 AMCompleted: Sep 14, 2026, 8:48:00 AMpubliccompleted

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

Long-established Microsoft tech blog appears compromised: primary domain and a loaded resource match 'iclickfix' malware, with a CRITICAL EtherHiding blockchain-exfiltration IDS alert. No credential/payment forms. Avoid interaction.

Risk Factors
Content-malware Indicators of Compromise on the primary domain (iclickfix malware, single unverified source)
External loaded resource xaz2.com independently flagged as malware by two feeds
CRITICAL IDS malware alert indicating EtherHiding exfiltration over blockchain
Live blockchain RPC connection from page scripts (ethereum-sepolia-rpc.publicnode.com)
Domain age information unavailable

Details

Page Title

Microsoft Geek – A Drink of Technology for the Thirsty Mind

Scan Type

public

Domain Name Analysis

Within the commercial generic top-level domain (.com), 'microsoftgeek.com' is registered with no subdomain. Count 13 characters in 'microsoftgeek' with five vowels and eight consonants. Segmentation suggests two words: microsoft, geek. The median word length lands at 6.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://microsoftgeek.com

Page Load Overview

10.91s
Total Load Time
982 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en-US
Text Length:11,179 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software66% confidence
Type: spa
Method: ml+structural

All Detected Categories

technology software
66%
forum
20%

Detected Features

Search

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
6142.250.154.95Google · CDNUnited States
AS15169Google LLC
6162.210.96.124United States
AS14555LiquidNet US LLC
6192.0.73.2San Francisco, California, United States
AS2635Automattic, Inc
6192.178.183.94Google · CDNUnited States
AS15169Google LLC
6188.114.96.9Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6104.20.24.117Cloudflare · WAFUnited States
AS13335Cloudflare, Inc.
6192.0.77.48San Francisco, California, United States
AS2635Automattic, Inc
427--

Detected Technologies7

WordPressv7.0.2
100%
JQueryv3.7.1
100%
Bootstrapv7.0.2
100%
50%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T15823FA32D36814E23A1DD72D72E172B45854AD15DA6327B6F1BF70988808DAB08E7F1F

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

768:09i5Q62I/xE6x4g5bn/EWDpPKZdyp3a0eU4hKNteLCo:iiCrOpPyypK0eQeLCo

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:45569:sAAEZYAYOFWDCGGQRCD4SAEA0BAUsr5oQhMQkAIBIjIkYgwpTwB4zEiLCkkxkgwDAxeJIMwAUkCAAAoIc3CiMAXGVqlA9rEC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Scan History

Scan history not available

Unable to load historical scan data