creativecommons.org - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned creativecommons.org and returned a unknown verdict (score -12). The page resolved to 104.20.5.134 on Cloudflare, Inc. in US. The domain was registered 9348 days ago through Gandi SAS. 12 domains and 2 IPs were contacted, over 4 HTTP requests. 358 malware samples communicate with this URL (Autolike, Genpack, QQpass, HUILoader). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
http://creativecommons.org/licenses/by/3.0/ - Domain: creativecommons.org · IP: 104.20.5.134 · AS13335 · US
- Server: cloudflare
- Page title: Deed - Attribution 3.0 Unported - Creative Commons
- HTTP status: 200 · text/html
- Registrar: Gandi SAS · domain age 9348 days · created 2001-01-15
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Oct 1 18: · subject CN=creativecommons.org
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-20 19:57:17 UTC
Redirect chain
http://creativecommons.org/licenses/by/3.0/https://creativecommons.org/licenses/by/3.0/
Malware communicating with this URL (358)
These samples were observed contacting or being served from creativecommons.org. Each links to its full analysis.
- Autolike - referenced ·
dcc66cd907af196603cff7b3fe1bb61e· first seen 2026-08-20 - dccd5ed4fef50ccbdb992852e285b8134f728057d1751746e07837666e50f982 - referenced ·
dccd5ed4fef50ccbdb992852e285b813· first seen 2026-08-20 - Genpack - referenced ·
d77c0ab6a9d9f9585da088d8aac0af2b· first seen 2026-08-20 - Genpack - referenced ·
2b73983c4d944d594d38b2bb783233ba· first seen 2026-08-20 - QQpass - referenced ·
69cb6171f3bbfc5bbb6a46911a8e6bcf· first seen 2026-08-20 - Genpack - referenced ·
db2660a02c76125cdd1b203cfd20bdab· first seen 2026-08-20 - dcc900c8d8966d92a7c259d5994b90288ed07b5f6003643aa1ee99fe7225a02a - referenced ·
dcc900c8d8966d92a7c259d5994b9028· first seen 2026-08-20 - dcc7cb5b07bedb3329bbb525350e7c8130a39221a2c951ebfc55f3edfae8182e - referenced ·
dcc7cb5b07bedb3329bbb525350e7c81· first seen 2026-08-20 - HUILoader - referenced ·
e97db28f8312c4d1182120750f957486· first seen 2026-08-20 - Genpack - referenced ·
fa67ac137d8d4b6c920c4a9da8270399· first seen 2026-08-20 - 99069d33ec4f87abf797c9591435e7a3d904d138ed0098fb5e78b72a9b9bf8df - referenced ·
99069d33ec4f87abf797c9591435e7a3· first seen 2026-08-20 - Ausiv - referenced ·
b51c611a225e65e9e0a3a55694a5dde6· first seen 2026-08-20 - HUILoader - referenced ·
d475a764a3e036a46ad0fab1e2b35dfb· first seen 2026-08-20 - HUILoader - referenced ·
ef1c74ee797131db2d62f5dec3f3fab9· first seen 2026-08-20 - 9908f629a0d0022dac5cb5736c5ae4ec827d2a44df20dbcf7413e3ebb053b580 - referenced ·
9908f629a0d0022dac5cb5736c5ae4ec· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
- WordPress
Contacted infrastructure
- 104.20.5.134 - AS13335 Cloudflare, Inc. (United States)
- 104.20.6.134 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- creativecommons.org
- search.creativecommons.org
- giving.gofundme.com
- wiki.creativecommons.org
- stage.creativecommons.org
- creative-commons-shop.fourthwall.com
- bsky.app
- mastodon.social
- www.facebook.com
- www.linkedin.com
- mail.creativecommons.org
- fontawesome.com
- 104.20.5.134
- 104.20.6.134
- https://creativecommons.org/licenses/by/3.0/
- https://creativecommons.org/licenses/by/3.0/deed.en
- https://creativecommons.org/licenses/by/3.0/deed.an
- https://creativecommons.org/licenses/by/3.0/deed.az
- https://creativecommons.org/licenses/by/3.0/deed.id
- https://creativecommons.org/licenses/by/3.0/deed.eu
Other scans of creativecommons.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://gmpg.org/xfn/11 - 23 Aug 2026 - unknown ·
http://himeaime.blogspot.com/2015/01/jodha-akbar-episode-312.html - 23 Aug 2026 - unknown ·
http://gmpg.org/xfn/11 - 23 Aug 2026 - unknown ·
https://autotools.info/index.html - 23 Aug 2026 - unknown ·
http://pandancoco.blogspot.com/2015/02/scop-281.html - 23 Aug 2026 - unknown ·
https://creativecommons.org/publicdomain/zero/1.0/ - 23 Aug 2026 - unknown ·
https://gmpg.org/xfn/11 - 23 Aug 2026 - unknown ·
https://autotools.info/index.html - 23 Aug 2026 - unknown ·
https://creativecommons.org/publicdomain/zero/1.0/ - 23 Aug 2026 - unknown ·
http://gmpg.org/xfn/11
Questions about creativecommons.org
- Is creativecommons.org safe?
- The scan of creativecommons.org on 20 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with creativecommons.org?
- 358 analysed samples communicate with this URL, including Autolike, Genpack, QQpass, HUILoader.
- How was creativecommons.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of creativecommons.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan