opensource.org - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned opensource.org and returned a unknown verdict (score 14). The page resolved to 104.20.30.15 on Cloudflare, Inc. in US. The domain was registered 10420 days ago through Gandi SAS. 18 domains and 2 IPs were contacted, over 34 HTTP requests. 57 malware samples communicate with this URL. The request followed 4 redirects before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 14) · Confidence 26%
- Scanned URL:
http://www.opensource.org/licenses/mit-license.php - Domain: opensource.org · IP: 104.20.30.15 · AS13335 · US
- Server: cloudflare
- Page title: The MIT License – Open Source Initiative
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Gandi SAS · domain age 10420 days · created 1998-02-11
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 10 16: · subject CN=opensource.org
- HTTP requests captured: 34
- Scan tier: fast · observed 2026-08-24 02:23:36 UTC
Redirect chain
http://www.opensource.org/licenses/mit-license.phphttps://www.opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mithttps://opensource.org/license/mit
Malware communicating with this URL (57)
These samples were observed contacting or being served from opensource.org. Each links to its full analysis.
- 65b670b781a1a80ee787445215a1e3fc292f4eb45a618c232eafa70e47cf9b57 - referenced ·
65b670b781a1a80ee787445215a1e3fc· first seen 2026-08-24 - b6e9587584884b0cff27204efbd740ccda5d47deb27e6261685d373974ca73e3 - referenced ·
b6e9587584884b0cff27204efbd740cc· first seen 2026-08-24 - fe9ec242c8e1d01a9b0e63da9b01c8c9044a88e50b5727c1aa556e3aa7f97242 - referenced ·
fe9ec242c8e1d01a9b0e63da9b01c8c9· first seen 2026-08-23 - 5bc6601ea04292c5bc86692f54bd73174586c6b28f73fe648221c298c7455748 - referenced ·
5bc6601ea04292c5bc86692f54bd7317· first seen 2026-08-23 - 13d72132cc2b9a165a1e171e407a3b15b637e1e55a6c20fadd8833e4f5662cd2 - referenced ·
13d72132cc2b9a165a1e171e407a3b15· first seen 2026-08-23 - 266a6f3275bd09c8426cbd673f609a3b8955046528b38f70f8b671b1a3c9be46 - referenced ·
266a6f3275bd09c8426cbd673f609a3b· first seen 2026-08-23 - f826174d982c8dbf3715cfc31a19fc2f43a304efb669d6c5435e41f79d17fcb3 - referenced ·
f826174d982c8dbf3715cfc31a19fc2f· first seen 2026-08-23 - dbb3beb00e49113bf09df27a712a3fb637424462b1dcfab72465992853534d4d - referenced ·
dbb3beb00e49113bf09df27a712a3fb6· first seen 2026-08-23 - 9d34868f2fb6d47fda998eb01879746c137e267e3e92a5768a19676daa1b6106 - referenced ·
9d34868f2fb6d47fda998eb01879746c· first seen 2026-08-22 - c828ed8736a781c9cab0cfecae84fcdcabd89320767c19272f9e06c0166b8079 - referenced ·
c828ed8736a781c9cab0cfecae84fcdc· first seen 2026-08-22 - f82c0702ca42c3b4a78b9ed5eeafbe4f3f2ae1c22970ed14d2c2752ce536fac8 - referenced ·
f82c0702ca42c3b4a78b9ed5eeafbe4f· first seen 2026-08-22 - f726976d12111292e490c45fb23970af9bf5db2b387c2ce9fd02af82a4a42ed8 - referenced ·
f726976d12111292e490c45fb23970af· first seen 2026-08-22 - c0febc254fa7aa3480ffe9f56bdf41052b2f2671dd9bb80a68bbc344b7e45979 - referenced ·
c0febc254fa7aa3480ffe9f56bdf4105· first seen 2026-08-22 - 03cf3b788540276f332862439abd78cc7f8cd273d6340d2393e7a471b70de324 - referenced ·
03cf3b788540276f332862439abd78cc· first seen 2026-08-22 - f9967f752c58162309bcef6479767c076ef73fc5e9c907610d4cff1fe1b12dfb - referenced ·
f9967f752c58162309bcef6479767c07· first seen 2026-08-22
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Long redirect chain (4 hops)
- Cross-host redirect chain
Detected technologies
- Cloudflare
- WordPress
- jQuery
Contacted infrastructure
- 104.20.30.15 - AS13335 Cloudflare, Inc. (United States)
- 172.66.171.169 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- opensource.org
- gmpg.org
- unpkg.com
- i0.wp.com
- c0.wp.com
- js.stripe.com
- social.opensource.org
- twitter.com
- www.linkedin.com
- www.reddit.com
- go.opensource.org
- discuss.opensource.org
- opensource.net
- web.archive.org
- wordpress.com
- pressable.com
- cookiedatabase.org
- stats.wp.com
- 104.20.30.15
- 172.66.171.169
Other scans of opensource.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://ianlunn.github.io/Hover/ - 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown ·
https://brm.io/jquery-match-height/ - 21 Aug 2026 - unknown
- 19 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 19 Aug 2026 - unknown
Questions about opensource.org
- Is opensource.org safe?
- The scan of opensource.org on 24 Aug 2026 reached no verdict either way (score 14). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with opensource.org?
- 57 analysed samples communicate with this URL.
- How was opensource.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of opensource.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan