www.instagram.com - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.instagram.com and returned a unknown verdict (score 14), categorised as credential-harvest. The page resolved to 157.240.8.174 on Facebook, Inc. in AU. The domain was registered 8112 days ago through RegistrarSafe, LLC. 9 domains and 2 IPs were contacted, over 12 HTTP requests. 36 malware samples communicate with this URL (Fromcharcode). The request followed 3 redirects before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 14) · Confidence 64%
- Scanned URL:
http://instagram.com/nuta_hair - Domain: www.instagram.com · IP: 157.240.8.174 · AS32934 · AU
- Page title: Instagram
- HTTP status: 200 · text/html; charset="utf-8"
- Registrar: RegistrarSafe, LLC · domain age 8112 days · created 2004-06-04
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Aug 27 23: · subject C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.www.instagram.com
- Evidenced operator: Meta Platforms, Inc.
- HTTP requests captured: 12
- Scan tier: fast · observed 2026-08-20 21:42:19 UTC
Redirect chain
http://instagram.com/nuta_hairhttps://instagram.com/nuta_hairhttps://www.instagram.com/nuta_hairhttps://www.instagram.com/accounts/login/?next=https%3A%2F%2Fwww.instagram.com%2Fnuta_hair&is_from_rle
Malware communicating with this URL (36)
These samples were observed contacting or being served from www.instagram.com. Each links to its full analysis.
- Fromcharcode - referenced ·
05c06067501ee8d6deeb80a58ef04885· first seen 2026-08-20 - ef4daa063f78b2ffcae16a7f01dd0506b58d1c8c76118c13beabe773f2f8f0d5 - referenced ·
ef4daa063f78b2ffcae16a7f01dd0506· first seen 2026-08-20 - 63b5c39c8d25d7adf702d78d31ea768097967eec978db3a8f1a77d141383fd72 - referenced ·
63b5c39c8d25d7adf702d78d31ea7680· first seen 2026-08-20 - 29801844242682134cdbe875d3caf647c4a752e833e0993d3f6c3a748566ab39 - referenced ·
29801844242682134cdbe875d3caf647· first seen 2026-08-20 - 5eb6f3d81081997ecb17f86f50073304fee03c9eb2ccd0ae5fc113abad0233e0 - referenced ·
5eb6f3d81081997ecb17f86f50073304· first seen 2026-08-20 - 3e45dd6f1e5cd1cebed108e753617320eef7f051f37ee33c6b166719088a1b6a - referenced ·
3e45dd6f1e5cd1cebed108e753617320· first seen 2026-08-19 - fbevents.js - referenced ·
5d8d4bb1186f740b55e9d632b68acc0b· first seen 2026-08-19 - d09d1513d4697e5c1a1d5b197e0b9e7df6b03e0ce3e0ae9d7e4d689a5d479c37 - referenced ·
d09d1513d4697e5c1a1d5b197e0b9e7d· first seen 2026-08-19 - e713bf20c3287d2225e86fa544195eb8c22709c8db1f96ded8b52f570134ed9c - referenced ·
e713bf20c3287d2225e86fa544195eb8· first seen 2026-08-19 - 30b343c7bb1167b2cf2b47e7d8165bf7d575df293fc532c7228b2a8abd34d382 - referenced ·
30b343c7bb1167b2cf2b47e7d8165bf7· first seen 2026-08-19 - dd8c3c9a8bc6e01a4da5524caf6ef57ef3091baa8014ee5bdf7e766e0348c2ab - referenced ·
dd8c3c9a8bc6e01a4da5524caf6ef57e· first seen 2026-08-17 - 9fff1a774a85a191dd95c19f580cb9c108a3b15f35b81ca6026a59449a74f33f - referenced ·
9fff1a774a85a191dd95c19f580cb9c1· first seen 2026-08-17 - c784eeea9a0a5ecb90039885358e4119e68abbda6593743152433e67db81051e - referenced ·
c784eeea9a0a5ecb90039885358e4119· first seen 2026-08-16 - 26bdfef1eb14e1cf9759db00a65a1844542d3d2387e89eb52d7898fb5d72744b - referenced ·
26bdfef1eb14e1cf9759db00a65a1844· first seen 2026-08-16 - 78836e06e64fb9fd787a16bc263f0d2460531a53adc4720e493ff23c423bbcdf - referenced ·
78836e06e64fb9fd787a16bc263f0d24· first seen 2026-08-16
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Contacted infrastructure
- 157.240.8.174 - AS32934 Facebook, Inc. (Australia)
- 157.240.13.174 - AS32934 Facebook, Inc. (Singapore)
Observed indicators
- www.instagram.com
- static.cdninstagram.com
- about.meta.com
- about.instagram.com
- help.instagram.com
- developers.facebook.com
- www.meta.ai
- www.threads.com
- www.facebook.com
- 157.240.8.174
- 157.240.13.174
- https://www.instagram.com/accounts/login/?next=https%3A%2F%2Fwww.instagram.com%2Fnuta_hair&is_from_rle
- https://static.cdninstagram.com/rsrc.php/yr/r/rzWiSjZRxk5.webp
- https://static.cdninstagram.com/rsrc.php/yj/r/f01UdNyJjJj.webp
- https://static.cdninstagram.com/rsrc.php/yL/r/mMvhX4currF.webp
- https://static.cdninstagram.com/rsrc.php/yY/r/5OCV_xUyQ5h.webp
- https://static.cdninstagram.com/rsrc.php/y9/r/MptwNl-B2pS.webp
- https://static.cdninstagram.com/rsrc.php/yw/r/icwX0xAk0pz.webp
- https://static.cdninstagram.com/rsrc.php/y4/r/QaBlI0OZiks.ico
- https://www.instagram.com/accounts/login/?next=https%3A%2F%2Fwww.instagram.com%2Fnuta_hair&is_from_rle
Other scans of www.instagram.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://serge-valentin.net/ckfinder/userfiles/files/vatigewuv.pdf - 24 Aug 2026 - unknown ·
http://serge-valentin.net/ckfinder/userfiles/files/vatigewuv.pdf - 24 Aug 2026 - unknown ·
https://au.norton.com/ - 24 Aug 2026 - unknown ·
https://au.norton.com/ - 24 Aug 2026 - unknown ·
https://www.lsv-wittlage.de/ckfinder/userfiles/files/rigefivijafiziw.pdf - 24 Aug 2026 - unknown ·
https://www.lsv-wittlage.de/ckfinder/userfiles/files/rigefivijafiziw.pdf - 24 Aug 2026 - unknown ·
http://www.nuricomuvakfi.org/wp-content/plugins/super-forms/uploads/php/files/4c35mk778f40i8dmtv3nkn - 24 Aug 2026 - unknown ·
https://m-styleauto.com/js/upload/files/suxomajapako.pdf - 24 Aug 2026 - unknown ·
https://alompar.hu/uploads/content_files/files/41377062345.pdf - 24 Aug 2026 - unknown ·
https://www.le-nora.com/
Questions about www.instagram.com
- Is www.instagram.com safe?
- The scan of www.instagram.com on 20 Aug 2026 reached no verdict either way (score 14). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.instagram.com?
- 36 analysed samples communicate with this URL, including Fromcharcode.
- How was www.instagram.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.instagram.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan