creativecommons.org - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned creativecommons.org and returned a unknown verdict (score -12). The page resolved to 104.20.6.134 on Cloudflare, Inc. in US. 11 domains and 2 IPs were contacted, over 4 HTTP requests. 373 malware samples communicate with this URL (HUILoader, Autolike, Genpack, QQpass). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
http://creativecommons.org/publicdomain/zero/1.0/ - Domain: creativecommons.org · IP: 104.20.6.134 · AS13335 · US
- Server: cloudflare
- Page title: Deed - CC0 1.0 Universal - Creative Commons
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Oct 1 18: · subject CN=creativecommons.org
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-21 06:22:18 UTC
Redirect chain
http://creativecommons.org/publicdomain/zero/1.0/https://creativecommons.org/publicdomain/zero/1.0/
Malware communicating with this URL (373)
These samples were observed contacting or being served from creativecommons.org. Each links to its full analysis.
- 644545f174841d2b92166b6e69dcf6b965634f0fe4d0c8a861091434e83d5078 - referenced ·
644545f174841d2b92166b6e69dcf6b9· first seen 2026-08-21 - df0b6d5fe59640afed53654288ca772f7eccd8fa37680e6abdd347d6a2e2c701 - referenced ·
df0b6d5fe59640afed53654288ca772f· first seen 2026-08-21 - df066392d67063967325fcddf0440399235a135700429a5a238539f363b2ef67 - referenced ·
df066392d67063967325fcddf0440399· first seen 2026-08-21 - HUILoader - referenced ·
7aeb825de073dffeb0ae5db118d7684d· first seen 2026-08-21 - df05cd3736dd18eb19d506b05d8290e05aa4ee725c0457830f55c6cac87919f9 - referenced ·
df05cd3736dd18eb19d506b05d8290e0· first seen 2026-08-21 - df0d093b69189150a507865b74bef77ada93cb7dcd8299383c9eb0f4d53f598b - referenced ·
df0d093b69189150a507865b74bef77a· first seen 2026-08-21 - df0ef9309df98dff8135bfe1a08588dd8a29cbb51370642265d9bb2a8b1911fa - referenced ·
df0ef9309df98dff8135bfe1a08588dd· first seen 2026-08-21 - df09af1faee3a5b5d585ce268dab72265e0ea36df6f95343e3e0153f5ec755e3 - referenced ·
df09af1faee3a5b5d585ce268dab7226· first seen 2026-08-21 - Autolike - referenced ·
df089f36edf210e4241f16ddf98440fc· first seen 2026-08-21 - e0d37a89f2b813e697057874ea4bc7e854fb0b2a64cabbdd059cafff9d130e5a - referenced ·
e0d37a89f2b813e697057874ea4bc7e8· first seen 2026-08-21 - Autolike - referenced ·
e0dd608c77e678e46f45daedb8f19c1f· first seen 2026-08-21 - Genpack - referenced ·
77ef54e160ac82ccb126fe90090588ec· first seen 2026-08-21 - ede795ed0f1611cf450fbce6f976bf9dde848953fda1074fd712028b194bf426 - referenced ·
ede795ed0f1611cf450fbce6f976bf9d· first seen 2026-08-20 - dcc28efe2e0f47222cac08003fa45892e9131afe766a3ebc7b83f0ce2aee07b6 - referenced ·
dcc28efe2e0f47222cac08003fa45892· first seen 2026-08-20 - QQpass - referenced ·
ff3ce19f5a79b855896c47d3cb63fc4b· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
- WordPress
Contacted infrastructure
- 104.20.6.134 - AS13335 Cloudflare, Inc. (United States)
- 104.20.5.134 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- creativecommons.org
- search.creativecommons.org
- giving.gofundme.com
- stage.creativecommons.org
- creative-commons-shop.fourthwall.com
- bsky.app
- mastodon.social
- www.facebook.com
- www.linkedin.com
- mail.creativecommons.org
- fontawesome.com
- 104.20.6.134
- 104.20.5.134
- https://creativecommons.org/publicdomain/zero/1.0/
- https://creativecommons.org/publicdomain/zero/1.0/deed.en
- https://creativecommons.org/publicdomain/zero/1.0/deed.an
- https://creativecommons.org/publicdomain/zero/1.0/deed.az
- https://creativecommons.org/publicdomain/zero/1.0/deed.id
- https://creativecommons.org/publicdomain/zero/1.0/deed.eu
- https://creativecommons.org/publicdomain/zero/1.0/deed.ca
Other scans of creativecommons.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://autotools.info/index.html - 24 Aug 2026 - unknown ·
http://istana-sepeda.blogspot.com/2012/04/fork-rst-first-platinum-travel-100.html - 24 Aug 2026 - unknown ·
https://getbootstrap.com/ - 24 Aug 2026 - unknown
- 24 Aug 2026 - unknown ·
https://gmpg.org/xfn/11 - 23 Aug 2026 - unknown ·
http://himeaime.blogspot.com/2015/01/jodha-akbar-episode-312.html - 23 Aug 2026 - unknown ·
http://gmpg.org/xfn/11 - 23 Aug 2026 - unknown ·
https://autotools.info/index.html - 23 Aug 2026 - unknown ·
http://pandancoco.blogspot.com/2015/02/scop-281.html - 23 Aug 2026 - unknown
Questions about creativecommons.org
- Is creativecommons.org safe?
- The scan of creativecommons.org on 21 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with creativecommons.org?
- 373 analysed samples communicate with this URL, including HUILoader, Autolike, Genpack, QQpass.
- How was creativecommons.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of creativecommons.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan