Security Scan Report: excel.dod.online.office365.us.mcas-gov.us

Redirected to:
https://excel.dod.online.office365.us/?
Submitted: Sep 27, 2026, 1:06:50 AMCompleted: Sep 27, 2026, 1:07:44 AMpubliccompleted

This website contacted 4 IPs in 1 country across 3 domains to perform 6 HTTP transactions. The main domain is excel.dod.online.office365.us and was registered 16 years ago.

Submitted URL: https://excel.dod.online.office365.us.mcas-gov.us

Effective URL:

https://excel.dod.online.office365.us/?
Redirected

The Cisco Umbrella rank of the primary domain is #81,576 of the top 1 million websites

AI Security Verdict

High Risk

Confidence: 75%

8
Risk Score

Deceptive DoD/Office 365-themed hostname on unrelated domains (mcas-gov.us -> office365.us) serving a bare 'Click here to continue' gateway. No forms or threat-intel hits found, but the hostname impersonation is a strong phishing signal — avoid.

Risk Factors (3)
Deceptive multi-level subdomain mimicking government and Microsoft Office 365 infrastructure
Redirect from an unrelated registrable domain (mcas-gov.us) to office365.us
Interstitial 'continue' gateway page with no genuine content, characteristic of phishing kit filtering
Domain age information unavailable

Details

Page Title

Continue

Scan Type

public

Domain Name Analysis

You're looking at domain 'excel.dod.online.office365.us.mcas-gov.us' on the United States country-code top-level domain (.us); it also runs on subdomain 'excel.dod.online.office365.us'. The core label 'mcas-gov' covers 8 characters split between two vowels and five consonants, plus 1 hyphen. Segmentation suggests 3 words: mc, as, gov. Median word length comes out to two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://excel.dod.online.office365.us.mcas-gov.us

Page Load Overview

3.41s
Total Load Time
27 KB
Total Size

Language Analysis

Primary Language

🏳️UNKNOWN
Code: unknown
Confidence:0%

Detection Details

Text Length:8 chars
Detector Agreement:0%

Website Classification

Primary Category

unknown0% confidence
Type: static
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
352.235.179.167Azure · CLOUDBoydton, Virginia, United States
AS8075Microsoft Corporation
152.244.239.112Azure · CLOUDPhoenix, Arizona, United States
AS8075Microsoft Corporation
152.127.81.75Boydton, Virginia, United States
AS8070Microsoft Corporation
120.140.151.75San Antonio, Texas, United States
AS8070Microsoft Corporation
64--

Detected Technologies1

40%

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T13B2123992CE254B1BF4345FD54E2B94C793AA22A8208CC207CCC82295FD5BEC1993B8C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

24:kx8SHH+WKA6ydTSEMSp+3NFuNVvPhP7DNUDR8XlV4D:ZPycELp+3jY5jUR8Xl6D

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:1174:FAAAAQQEAAAAAAABAAAAAAAAAAAAAAQABQAAAAwEEAAIAEAAAAAUAAAAAAgACBARAAAAAAAACCgAAQAIAAQAAAAIAAAAAEAA

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:7fffffffffffffff
Perceptual Hash:87070f0f0f0f0f1f
Difference Hash:8000000000000000
Wavelet Hash:70f0f0f0f0f0f0f0
Color Hash:#783f3a

Other Hashes

Crop Resistant:8000000000000000

Scan History

Scan history not available

Unable to load historical scan data