flickr.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned flickr.com and returned a suspicious verdict (score 38), categorised as credential-harvest. The page resolved to 18.67.110.48 on Amazon.com, Inc. in AU. 25 domains and 1 IP were contacted, over 8 HTTP requests. 12 malware samples communicate with this URL (Obfus). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 38) · Confidence 47%
- Scanned URL:
https://flickr.com/ - Domain: flickr.com · IP: 18.67.110.48 · AS16509 · AU
- Page title: Flickr | The best place to be a photographer online.
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M01 · valid to Jan 2 23: · subject CN=flickr.com
- HTTP requests captured: 8
- Scan tier: fast · observed 2026-08-20 23:48:26 UTC
Malware communicating with this URL (12)
These samples were observed contacting or being served from flickr.com. Each links to its full analysis.
- f242e25f4083267344721a0c7b5452796d0f9db6ec269b3fb3674b20b4f6c307 - referenced ·
f242e25f4083267344721a0c7b545279· first seen 2026-08-20 - Obfus - referenced ·
990d351d210f4076b9e87421855cb1f2· first seen 2026-08-20 - 243872184-lbx__pt_br.js - referenced ·
1d643e4b93da79c302afdc8dab7b357a· first seen 2026-08-16 - 129205357-lbx__pt_br.js - referenced ·
7957d117a68d99b69544472996d943f9· first seen 2026-08-15 - 945919205-lbx__pt_br.js - referenced ·
97d3352db3608186c89704e39cf04023· first seen 2026-08-15 - 3618766451-lbx__en_gb.js - referenced ·
88b4eee071a3e2d8836be1b02ec5b3e1· first seen 2026-08-14 - 3903731066-lbx__pt_br.js - referenced ·
f7e2bc3ee0d4f9ae4d1267999a73f2e2· first seen 2026-08-12 - 1957234192-lbx__pt_br.js - referenced ·
3fd4edfa4121016e4536c4c49e1bd813· first seen 2026-08-14 - 201988111-lbx__pt_br.js - referenced ·
d31bce676025d141cccecf7dcad29d2a· first seen 2026-08-14 - 3766621756-lbx__pt_br.js - referenced ·
e5823aed4ddaed520ef63a3ab556cae7· first seen 2026-08-12 - 2028442393-lbx__pt_br.js - referenced ·
d99d1b9d9e7ba7705e74cb4c3c1ef382· first seen 2026-08-13 - 4142632578-lbx__pt_br.js - referenced ·
78184f664658e232bcc5a34df70420a8· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
Detected technologies
- Amazon CloudFront
- Google Analytics
- jQuery
Contacted infrastructure
- 18.67.110.48 - AS16509 Amazon.com, Inc. (Australia)
Observed indicators
- flickr.com
- cdn.prod.website-files.com
- combo.staticflickr.com
- fonts.googleapis.com
- fonts.gstatic.com
- ajax.googleapis.com
- cmp.osano.com
- www.googletagmanager.com
- cdn.weglot.com
- www.flickr.com
- blog.flickr.net
- www.flickrads.com
- modefestival.com
- www.flickr.org
- identity.flickr.com
- www.modefestival.com
- www.instagram.com
- www.facebook.com
- www.youtube.com
- www.greatplacetowork.com
Other scans of flickr.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://s.ai/ - 23 Aug 2026 - unknown ·
https://s.ai/ - 22 Aug 2026 - unknown ·
https://cnte.org.br/images/hot-to-get-robux-for-free.pdf - 22 Aug 2026 - unknown ·
https://s.ai/ - 22 Aug 2026 - unknown ·
https://s.ai/ - 20 Aug 2026 - unknown ·
https://meyerweb.com/eric/tools/css/reset/ - 19 Aug 2026 - unknown ·
https://remysharp.com/ - 16 Aug 2026 - suspicious ·
https://flickr.com/photos/ - 16 Aug 2026 - unknown ·
https://remysharp.com/ - 15 Aug 2026 - suspicious ·
https://flickr.com/photos/
Questions about flickr.com
- Is flickr.com safe?
- No. MalwareAnalyzer scanned flickr.com on 20 Aug 2026 and returned a suspicious verdict with a score of 38 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with flickr.com?
- 12 analysed samples communicate with this URL, including Obfus.
- How was flickr.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of flickr.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan