javascriptweblog.wordpress.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned javascriptweblog.wordpress.com and returned a suspicious verdict (score 40), categorised as suspicious-infrastructure, credential-harvest. The page resolved to 192.0.78.13 on Automattic, Inc in US. The domain was registered 9666 days ago through MarkMonitor Inc.. 82 domains and 2 IPs were contacted, over 11 HTTP requests. 2 malware samples communicate with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 40) · Confidence 52%
- Scanned URL:
https://goo.gl/pxwQGp - Domain: javascriptweblog.wordpress.com · IP: 192.0.78.13 · AS2635 · US
- Server: nginx
- Page title: Fixing the JavaScript typeof operator – JavaScript, JavaScript…
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: MarkMonitor Inc. · domain age 9666 days · created 2000-03-03
- TLS issuer: C=US, O=Let's Encrypt, CN=YE2 · valid to Oct 4 19: · subject CN=wordpress.com
- HTTP requests captured: 11
- Scan tier: fast · observed 2026-08-20 14:28:35 UTC
Redirect chain
https://goo.gl/pxwQGphttps://javascriptweblog.wordpress.com/2011/08/08/fixing-the-javascript-typeof-operator/
Malware communicating with this URL (2)
These samples were observed contacting or being served from javascriptweblog.wordpress.com. Each links to its full analysis.
- c799acfa523e8b9d8626faeaeae566cf7b1a842a33427a0ac66944da81f3af91 - referenced ·
c799acfa523e8b9d8626faeaeae566cf· first seen 2026-08-20 - 79aa5df2543989721f9cae3d93b07f0fbca54e8b301ad1faafcebf1d687902e0 - referenced ·
79aa5df2543989721f9cae3d93b07f0f· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- suspicious-infrastructure
- credential-harvest
Why this verdict
- Credential-harvesting form
- Algorithmically-generated (DGA-like) hostname
- Valid TLS, no impersonation or off-origin credential post
- Submitted via URL shortener (goo.gl) — expanded before scan
Detected technologies
- Nginx
- WordPress
- Google Analytics
Contacted infrastructure
- 192.0.78.13 - AS2635 Automattic, Inc (United States)
- 142.251.222.14 - AS15169 Google LLC (Japan)
Observed indicators
- javascriptweblog.wordpress.com
- gmpg.org
- s1.wp.com
- s2.wp.com
- widgets.wp.com
- fonts-api.wp.com
- s0.wp.com
- af.pubmine.com
- wp.me
- public-api.wordpress.com
- wordpress.com
- github.githubassets.com
- ecma262-5.com
- perfectionkills.com
- erik.eae.net
- www.prototypejs.org
- twitter.com
- 0.gravatar.com
- 1.gravatar.com
- mathiasbynens.be
Other scans of javascriptweblog.wordpress.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - suspicious
Questions about javascriptweblog.wordpress.com
- Is javascriptweblog.wordpress.com safe?
- No. MalwareAnalyzer scanned javascriptweblog.wordpress.com on 20 Aug 2026 and returned a suspicious verdict with a score of 40 out of 100, categorised as suspicious-infrastructure and credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with javascriptweblog.wordpress.com?
- 2 analysed samples communicate with this URL.
- How was javascriptweblog.wordpress.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of javascriptweblog.wordpress.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan