Security Scan Report: www.msftconnecttest.xyz

Redirected to:
https://www.msftconnecttest.xyz/#/404
Submitted: Sep 15, 2026, 7:47:49 PMCompleted: Sep 15, 2026, 7:49:02 PMpubliccompleted

This website contacted 1 IP in 1 country across 1 domain to perform 13 HTTP transactions. The main domain is msftconnecttest.xyz and was registered 1 year 10 months ago.

Submitted URL: https://www.msftconnecttest.xyz

Effective URL:

https://www.msftconnecttest.xyz/#/404
Redirected

AI Security Verdict

Confirmed Scam

Confidence: 88%

9
Risk Score

Domain typosquats Microsoft's msftconnecttest hostname and its domain is flagged with gorat/sparkrat malware Indicators of Compromise across multiple feeds — do not visit.

Risk Factors (4)
Content-malware Indicators of Compromise match against the primary domain (sparkrat / gorat RAT families)
Multi-source malware corroboration on the domain (2 independent feeds)
Typosquatting of Microsoft's msftconnecttest connectivity-test hostname
Domain unranked in Cisco Umbrella with near-zero legitimacy score despite being 652 days old
Domain age information unavailable

Details

Page Title

DControl

Scan Type

public

Domain Name Analysis

Within the open generic top-level domain (.xyz), 'www.msftconnecttest.xyz' is registered; it also runs on subdomain 'www'. The second-level label 'msftconnecttest' is 15 characters long with three vowels and 12 consonants. It segments into 4 words: ms, ft, connect, test. The median word length lands at three characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://www.msftconnecttest.xyz

Page Load Overview

11.42s
Total Load Time
1.0 MB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:62%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:zh-cn
Text Length:55 chars
Detector Agreement:100%
Language mismatch: Declared as zh-cn but detected as en

Website Classification

Primary Category

technology software76% confidence
Type: dynamic
Method: ml+structural

All Detected Categories

technology software
76%
documentation technical
67%
healthcare medical
48%
news media journalism
48%
government public service
47%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13154.31.222.217United States
AS18186Nebula Global LLC
131--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T183E02BA6F8704CEC02008F680C25B9A8044EBC8C71942CA4E4C750A808D0A301C22A88

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

12:ho01/7520wniavtHdaIpm0AAcz6SS/n5kVG:ht1j5ROaYcOcVG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:ffcf1e2129b2e7bdf5fee0eebf8f109a

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:e73ffffffffe7f7f
Perceptual Hash:a323237672767626
Difference Hash:0cd0000000008080
Wavelet Hash:011d0f0f3c3c7c7e
Color Hash:#5e2d86

Other Hashes

Crop Resistant:0cd0000000008080

Scan History

Scan history not available

Unable to load historical scan data