opensource.org - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned opensource.org and returned a unknown verdict (score 14). The page resolved to 172.66.171.169 on Cloudflare, Inc. in US. The domain was registered 10418 days ago through Gandi SAS. 18 domains and 2 IPs were contacted, over 34 HTTP requests. 37 malware samples communicate with this URL. The request followed 4 redirects before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 14) · Confidence 26%
- Scanned URL:
http://www.opensource.org/licenses/mit-license.php - Domain: opensource.org · IP: 172.66.171.169 · AS13335 · US
- Server: cloudflare
- Page title: The MIT License – Open Source Initiative
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Gandi SAS · domain age 10418 days · created 1998-02-11
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 10 16: · subject CN=opensource.org
- HTTP requests captured: 34
- Scan tier: fast · observed 2026-08-21 20:03:28 UTC
Redirect chain
http://www.opensource.org/licenses/mit-license.phphttps://www.opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mithttps://opensource.org/license/mit
Malware communicating with this URL (37)
These samples were observed contacting or being served from opensource.org. Each links to its full analysis.
- be1d2d89603182c19507a2c8a80afa45cab9aa9b228db4eb88e4a5c335b11668 - referenced ·
be1d2d89603182c19507a2c8a80afa45· first seen 2026-08-21 - 3f7899ba69ccc7a23a418c62625e579ea9d406b1d02e28768d5cf8b18bc1d7d6 - referenced ·
3f7899ba69ccc7a23a418c62625e579e· first seen 2026-08-21 - a1be19891b68ad0da52007a4aeca67dc004dc1332706c5718628a1a62ea1d833 - referenced ·
a1be19891b68ad0da52007a4aeca67dc· first seen 2026-08-21 - 462a50436a95cd4fae493b5b52cee8a799bb281f35e1b38ea0ff1d9efa6d92d2 - referenced ·
462a50436a95cd4fae493b5b52cee8a7· first seen 2026-08-21 - 323b09a0dc664b18338036d2546899d907c218fdea8ed75bcf0d3452640d0aa2 - referenced ·
323b09a0dc664b18338036d2546899d9· first seen 2026-08-21 - b57ea7bf37f3f96df24e0b90bb5bf09f4ef7dea56f619fa32a717feef695abf7 - referenced ·
b57ea7bf37f3f96df24e0b90bb5bf09f· first seen 2026-08-21 - df066392d67063967325fcddf0440399235a135700429a5a238539f363b2ef67 - referenced ·
df066392d67063967325fcddf0440399· first seen 2026-08-21 - df0798f47b2ec938c54deac325a2198d27b40844de30a017f1092b791bd63ba4 - referenced ·
df0798f47b2ec938c54deac325a2198d· first seen 2026-08-21 - df0d093b69189150a507865b74bef77ada93cb7dcd8299383c9eb0f4d53f598b - referenced ·
df0d093b69189150a507865b74bef77a· first seen 2026-08-21 - df0ef9309df98dff8135bfe1a08588dd8a29cbb51370642265d9bb2a8b1911fa - referenced ·
df0ef9309df98dff8135bfe1a08588dd· first seen 2026-08-21 - dccd5ed4fef50ccbdb992852e285b8134f728057d1751746e07837666e50f982 - referenced ·
dccd5ed4fef50ccbdb992852e285b813· first seen 2026-08-20 - bd551bcf712734ec3228165e2745f34e6ded5e1a14b12c22a067d4f6fbb1a9ed - referenced ·
bd551bcf712734ec3228165e2745f34e· first seen 2026-08-20 - 99069d33ec4f87abf797c9591435e7a3d904d138ed0098fb5e78b72a9b9bf8df - referenced ·
99069d33ec4f87abf797c9591435e7a3· first seen 2026-08-20 - 20dea0f84d69105e868c53819f774345a3e31b72b90fba757c23d76c7c5d0195 - referenced ·
20dea0f84d69105e868c53819f774345· first seen 2026-08-20 - 5cf79f8b58b946bd938e5343eb2becbbc12fd8e786f65248baa10fff56c6aa44 - referenced ·
5cf79f8b58b946bd938e5343eb2becbb· first seen 2026-08-20
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Long redirect chain (4 hops)
- Cross-host redirect chain
Detected technologies
- Cloudflare
- WordPress
- jQuery
Contacted infrastructure
- 172.66.171.169 - AS13335 Cloudflare, Inc. (United States)
- 104.20.30.15 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- opensource.org
- gmpg.org
- unpkg.com
- i0.wp.com
- c0.wp.com
- js.stripe.com
- social.opensource.org
- twitter.com
- www.linkedin.com
- www.reddit.com
- go.opensource.org
- discuss.opensource.org
- opensource.net
- web.archive.org
- wordpress.com
- pressable.com
- cookiedatabase.org
- stats.wp.com
- 172.66.171.169
- 104.20.30.15
Other scans of opensource.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ianlunn.github.io/Hover/ - 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown ·
https://brm.io/jquery-match-height/ - 21 Aug 2026 - unknown
- 19 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 19 Aug 2026 - unknown
Questions about opensource.org
- Is opensource.org safe?
- The scan of opensource.org on 21 Aug 2026 reached no verdict either way (score 14). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with opensource.org?
- 37 analysed samples communicate with this URL.
- How was opensource.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of opensource.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan