crl.globalsign.net - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned crl.globalsign.net and returned a unknown verdict (score 6). The page resolved to 199.232.138.133 on Fastly, Inc. in AU. The domain was registered 10411 days ago through EuroDNS S.A.. 1 domain and 1 IP were contacted. 9 malware samples communicate with this URL (HUILoader, Bulz, Lmir, Tedy). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 9%
- Scanned URL:
http://crl.globalsign.net/root-r3.crl0 - Domain: crl.globalsign.net · IP: 199.232.138.133 · AS54113 · AU
- Server: nginx
- Page title: 404 Not Found
- HTTP status: 404 · text/html; charset=iso-8859-1
- Registrar: EuroDNS S.A. · domain age 10411 days · created 1998-02-18
- Scan tier: fast · observed 2026-08-21 19:37:31 UTC
Malware communicating with this URL (9)
These samples were observed contacting or being served from crl.globalsign.net. Each links to its full analysis.
- HUILoader - referenced ·
9c2da944a4e1cbb7edab5fb6abc65b1b· first seen 2026-08-21 - Bulz - referenced ·
f7c0b73439dbfa2a4418e8c15ca6bbcf· first seen 2026-08-21 - Lmir - referenced ·
02267e4dea62297d743e1a028622c660· first seen 2026-08-20 - Tedy - contacted ·
c47aaed6e7345f32c0e33f8217128642· first seen 2026-08-20 - HUILoader - referenced ·
e69d86cd21bccc9d76d40a1270dae9eb· first seen 2026-08-20 - Badmacro - referenced ·
88174718adac0d95c5c2d87eab47b63d· first seen 2026-08-13 - Filerepmalware - referenced ·
f2cf0477339d3953f0dc4d4fe2959be1· first seen 2026-08-15 - Small - referenced ·
82ff8eef3425ae91f2c68f47cc63ca1f· first seen 2026-08-14 - Vindor - referenced ·
95aa37ee6cc9c4272dd703b9457840fa· first seen 2026-08-12
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Served over plaintext HTTP
Detected technologies
- Nginx
- Fastly
Contacted infrastructure
- 199.232.138.133 - AS54113 Fastly, Inc. (Australia)
Observed indicators
- crl.globalsign.net
- 199.232.138.133
- http://crl.globalsign.net/root-r3.crl0
Other scans of crl.globalsign.net (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 20 Aug 2026 - unknown
- 20 Aug 2026 - unknown
- 17 Aug 2026 - unknown ·
http://crl.globalsign.net/root.crl0 - 15 Aug 2026 - unknown
- 14 Aug 2026 - unknown ·
http://crl.globalsign.net/primobject.crl0 - 14 Aug 2026 - unknown ·
http://crl.globalsign.net/RootSignPartners.crl0 - 14 Aug 2026 - unknown ·
http://crl.globalsign.net/Root.crl0 - 14 Aug 2026 - unknown ·
http://crl.globalsign.net/ObjectSign.crl0
Questions about crl.globalsign.net
- Is crl.globalsign.net safe?
- The scan of crl.globalsign.net on 21 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with crl.globalsign.net?
- 9 analysed samples communicate with this URL, including HUILoader, Bulz, Lmir, Tedy.
- How was crl.globalsign.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of crl.globalsign.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan