wordpress.org - URL scan, 16 Aug 2026
MalwareAnalyzer by Cyble scanned wordpress.org and returned a unknown verdict (score 2), categorised as suspicious-infrastructure. The page resolved to 66.6.42.252 on TUMBLR, INC. in US. 187 domains and 2 IPs were contacted, over 5 HTTP requests. 12 malware samples communicate with this URL (Obfus, Emotet). The request followed 1 redirect before landing. This is a point-in-time observation from 16 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 2) · Confidence 8%
- Scanned URL:
https://s.w.org/ - Domain: wordpress.org · IP: 66.6.42.252 · AS2635 · US
- Server: nginx
- Page title: Blog Tool, Publishing Platform, and CMS – WordPress.org
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Oct 23 19: · subject CN=wordpress.org
- HTTP requests captured: 5
- Scan tier: fast · observed 2026-08-16 11:21:55 UTC
Redirect chain
https://s.w.org/https://wordpress.org/
Malware communicating with this URL (12)
These samples were observed contacting or being served from wordpress.org. Each links to its full analysis.
- 4428af99334a60a896a7e5ec54e945f6d9f3f9bc97d6aa42f0c4a30907d00685 - referenced ·
4428af99334a60a896a7e5ec54e945f6· first seen 2026-08-16 - 425450a99fb2ebbbf22b140ee2553588af341ff6f0820b70c03a7543100f9fe6 - referenced ·
425450a99fb2ebbbf22b140ee2553588· first seen 2026-08-16 - 68e42b78678bd68a1b09387bc0347aeaaa9899539c2c4c91080d29467eb62fa4 - referenced ·
68e42b78678bd68a1b09387bc0347aea· first seen 2026-08-16 - f55e87ef3a13299a5ae7dfe5116790b5cc2925cbc4c4050ea1346c10ec2fb6bb - referenced ·
f55e87ef3a13299a5ae7dfe5116790b5· first seen 2026-08-15 - Obfus - referenced ·
f555608a5f067cd37a7da087d8577cbf· first seen 2026-08-15 - 70618060cc2eb58fcaf5dd8c85c95325c980687337be146e486513fc3ac1ed09 - referenced ·
70618060cc2eb58fcaf5dd8c85c95325· first seen 2026-08-15 - 5a41a9bf94afd3b76e643309261e432b14af2a38338b7d01fe3a9c72e6026203 - referenced ·
5a41a9bf94afd3b76e643309261e432b· first seen 2026-08-14 - 502612a9757c1e7582fb441f325c7cf227e273ab3bf183b889ad055c73300696 - referenced ·
502612a9757c1e7582fb441f325c7cf2· first seen 2026-08-14 - 0e50d1cd1fcfd58c762767dcf94ff6fe06a1dcc02e84411f0fe3331e2ab22db7 - referenced ·
0e50d1cd1fcfd58c762767dcf94ff6fe· first seen 2026-08-14 - 2b763dac587beb086c826817d81040b9e910d581082c1c1df393d4e1921d4248 - referenced ·
2b763dac587beb086c826817d81040b9· first seen 2026-08-14 - Emotet - referenced ·
25fd44c523c2023fb7dccbc6e6f90972· first seen 2026-08-13 - 2999e70d571c1163dfcdf4d171ec8e9244251026634b20ac94c855571507b6c5 - referenced ·
2999e70d571c1163dfcdf4d171ec8e92· first seen 2026-08-12
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- suspicious-infrastructure
Why this verdict
- Algorithmically-generated (DGA-like) hostname
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- WordPress
- Google Analytics
Contacted infrastructure
- 66.6.42.252 - AS2635 TUMBLR, INC. (United States)
- 192.0.77.48 - AS2635 Automattic, Inc (United States)
Observed indicators
- wordpress.org
- www.googletagmanager.com
- i0.wp.com
- w.org
- fonts.googleapis.com
- fonts.gstatic.com
- af.wordpress.org
- am.wordpress.org
- arg.wordpress.org
- ar.wordpress.org
- as.wordpress.org
- az.wordpress.org
- az-tr.wordpress.org
- bel.wordpress.org
- bg.wordpress.org
- bn.wordpress.org
- bn-in.wordpress.org
- bo.wordpress.org
- bre.wordpress.org
- bs.wordpress.org
Other scans of wordpress.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://jqueryui.com/demos/effect/easing.html - 24 Aug 2026 - unknown ·
https://www.alexoloughlinonline.com/author/admin/ - 24 Aug 2026 - unknown ·
https://www.alexoloughlinonline.com/hawaii-five-0-pilot-clip/ - 24 Aug 2026 - unknown ·
https://www.alexoloughlinonline.com/ - 24 Aug 2026 - unknown ·
https://www.zaantraining.nl/wp-content/plugins/formcraft/file-upload/server/content/files/16134a968e - 24 Aug 2026 - unknown ·
http://www.bzip.org/ - 24 Aug 2026 - suspicious ·
https://developer.wordpress.org/rest-api/ - 23 Aug 2026 - unknown ·
https://khaskhaan.mn/uploads/userfiles/files/41612758929.pdf - 23 Aug 2026 - unknown ·
http://nagyberki.hu/sites/default/files/fck_uploads/file/xapezewituvata.pdf - 23 Aug 2026 - unknown ·
https://jquery.com/license/
Questions about wordpress.org
- Is wordpress.org safe?
- The scan of wordpress.org on 16 Aug 2026 reached no verdict either way (score 2). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with wordpress.org?
- 12 analysed samples communicate with this URL, including Obfus, Emotet.
- How was wordpress.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of wordpress.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan