opensource.org - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned opensource.org and returned a unknown verdict (score 14). The page resolved to 104.20.30.15 on Cloudflare, Inc. in US. 18 domains and 2 IPs were contacted, over 34 HTTP requests. 18 malware samples communicate with this URL. The request followed 4 redirects before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 14) · Confidence 26%
- Scanned URL:
http://www.opensource.org/licenses/mit-license.php - Domain: opensource.org · IP: 104.20.30.15 · AS13335 · US
- Server: cloudflare
- Page title: The MIT License – Open Source Initiative
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 10 16: · subject CN=opensource.org
- HTTP requests captured: 34
- Scan tier: fast · observed 2026-08-19 07:43:00 UTC
Redirect chain
http://www.opensource.org/licenses/mit-license.phphttps://www.opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mithttps://opensource.org/license/mit
Malware communicating with this URL (18)
These samples were observed contacting or being served from opensource.org. Each links to its full analysis.
- jquery.favicon.js - referenced ·
74dde689597c84df5e4adc35bc7145ca· first seen 2026-08-19 - 612cf90b240cf17b455099a35a222f3ed2fb7fe12de122f8c70b2a7193606ca1 - referenced ·
612cf90b240cf17b455099a35a222f3e· first seen 2026-08-17 - ccf1f7f1cc4bc5714bec5686baccc6fc0011e5821ad93d864666126dcd4dd373 - referenced ·
ccf1f7f1cc4bc5714bec5686baccc6fc· first seen 2026-08-16 - 11ba9e6c2091a692ffc734431fc130be39b3103c60eaa07c0548bab50de11687 - referenced ·
11ba9e6c2091a692ffc734431fc130be· first seen 2026-08-16 - 40888f8a1834970f9829c6eac1e687406ef0380b52ae9154e9cc841b3d4df48f - referenced ·
40888f8a1834970f9829c6eac1e68740· first seen 2026-08-16 - f5518ed561cffa3ceda01b75a4b7e3686cc5d7b31b4ef7b0f21d1dd495c73b85 - referenced ·
f5518ed561cffa3ceda01b75a4b7e368· first seen 2026-08-15 - 8f82d1bcd7f950ea7b4de7f7e67b36296e5bfbf31301e95f16d946c97dc446c3 - referenced ·
8f82d1bcd7f950ea7b4de7f7e67b3629· first seen 2026-08-15 - 67d50ba1c9d74e647b7e8137dbfb8ecc02ff8bb2de4c39f8a36c83f5c2062df4 - referenced ·
67d50ba1c9d74e647b7e8137dbfb8ecc· first seen 2026-08-15 - d36c0e1eabe5f7b775755cc5d74d295ec9539b71302b8030c2b0430bed3c34c8 - referenced ·
d36c0e1eabe5f7b775755cc5d74d295e· first seen 2026-08-14 - bb2ae3799510ca93c722c34c1c202da1c336b755b1df87fc800ef041f1412ba9 - referenced ·
bb2ae3799510ca93c722c34c1c202da1· first seen 2026-08-13 - 91a8d3dcccf9beb7e20729c9fc466dd2f0441fb4922f9818568dcf83f144119c - referenced ·
91a8d3dcccf9beb7e20729c9fc466dd2· first seen 2026-08-13 - 80e0acd51c4750b4d3338c71d96154fc40ecf2d382b4656a30180be48e37409f - referenced ·
80e0acd51c4750b4d3338c71d96154fc· first seen 2026-08-13 - 8d7054d585b0915f9c16869522312f4beec3de12aa597d350f05d28960535a43 - referenced ·
8d7054d585b0915f9c16869522312f4b· first seen 2026-08-13 - 80e28ed36855fbe2d4014c04b9db6df7540f644c5dc75853818e8bab77c28eb3 - referenced ·
80e28ed36855fbe2d4014c04b9db6df7· first seen 2026-08-13 - 4110c8d1f595e6b95bcd642d81d93cc092ce9b04d1e715401c658c52bdedf251 - referenced ·
4110c8d1f595e6b95bcd642d81d93cc0· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Long redirect chain (4 hops)
- Cross-host redirect chain
Detected technologies
- Cloudflare
- WordPress
- jQuery
Contacted infrastructure
- 104.20.30.15 - AS13335 Cloudflare, Inc. (United States)
- 172.66.171.169 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- opensource.org
- gmpg.org
- unpkg.com
- i0.wp.com
- c0.wp.com
- js.stripe.com
- social.opensource.org
- twitter.com
- www.linkedin.com
- www.reddit.com
- go.opensource.org
- discuss.opensource.org
- opensource.net
- web.archive.org
- wordpress.com
- pressable.com
- cookiedatabase.org
- stats.wp.com
- 104.20.30.15
- 172.66.171.169
Other scans of opensource.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ianlunn.github.io/Hover/ - 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown ·
https://brm.io/jquery-match-height/ - 21 Aug 2026 - unknown
- 19 Aug 2026 - unknown ·
https://opensource.org/license/MIT
Questions about opensource.org
- Is opensource.org safe?
- The scan of opensource.org on 19 Aug 2026 reached no verdict either way (score 14). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with opensource.org?
- 18 analysed samples communicate with this URL.
- How was opensource.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of opensource.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan