adr.org - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned adr.org and returned a suspicious verdict (score 28). The page resolved to 159.60.135.2 on F5 Anycast 1 in FR. The domain was registered 11290 days ago through Network Solutions, LLC. 9 domains and 1 IP were contacted, over 7 HTTP requests. 8 malware samples communicate with this URL (Crypted, Razy, Genpack, Obfus). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://adr.org/ - Domain: adr.org · IP: 159.60.135.2 · AS35280 · FR
- Server: volt-adc
- Page title: American Arbitration Association | Arbitration & ADR Services
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: Network Solutions, LLC · domain age 11290 days · created 1995-09-21
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 2 21: · subject CN=adr.org
- HTTP requests captured: 7
- Scan tier: fast · observed 2026-08-19 11:17:30 UTC
Malware communicating with this URL (8)
These samples were observed contacting or being served from adr.org. Each links to its full analysis.
- Crypted - referenced ·
9a1c677c5fa74e3412a244c6cba089e3· first seen 2026-08-19 - Razy - referenced ·
cf1088a123d857c269b99134c5adbd54· first seen 2026-08-16 - Genpack - referenced ·
635e0d1efec862bdb0e38e3d04aab099· first seen 2026-08-15 - Genpack - referenced ·
6a1a732f0bc57727f5070187dbb770d6· first seen 2026-08-14 - Razy - referenced ·
309442c8b925064f719da440df6b03e0· first seen 2026-08-13 - Crypted - referenced ·
0d933b24ef0fd0400dda70d519217bcd· first seen 2026-08-13 - Obfus - referenced ·
01b86593a8bb09809aecbcab15fe39a3· first seen 2026-08-13 - Razy - referenced ·
bfbb329e5c9c05dd07fd6dcc58b18fc8· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Google Analytics
Contacted infrastructure
- 159.60.135.2 - AS35280 F5 Anycast 1 (France)
Observed indicators
- adr.org
- cdn.jsdelivr.net
- cmp.osano.com
- www.googletagmanager.com
- challenges.cloudflare.com
- feature.adr.org
- icdr.org
- www.aaaeducation.org
- forms.adr.org
- 159.60.135.2
- https://adr.org/
- https://adr.org/common.js?matcher
- https://adr.org/common.js?single
- https://adr.org/favicon-96x96.png
- https://adr.org/favicon.svg
- https://adr.org/favicon.ico
- https://adr.org/apple-touch-icon.png
- https://adr.org/site.webmanifest
- https://cdn.jsdelivr.net/npm/bootstrap-icons@1.10.5/font/bootstrap-icons.css
- https://adr.org/dist/css/site.css
Other scans of adr.org (6)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 16 Aug 2026 - suspicious
- 15 Aug 2026 - unknown
- 14 Aug 2026 - suspicious
- 13 Aug 2026 - suspicious
- 13 Aug 2026 - suspicious
- 12 Aug 2026 - suspicious
Questions about adr.org
- Is adr.org safe?
- No. MalwareAnalyzer scanned adr.org on 19 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with adr.org?
- 8 analysed samples communicate with this URL, including Crypted, Razy, Genpack, Obfus.
- How was adr.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of adr.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan