opensource.org - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned opensource.org and returned a unknown verdict (score 14). The page resolved to 104.20.30.15 on Cloudflare, Inc. in US. 18 domains and 2 IPs were contacted, over 34 HTTP requests. 53 malware samples communicate with this URL (Genpack). The request followed 4 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 14) · Confidence 26%
- Scanned URL:
http://www.opensource.org/licenses/mit-license.php - Domain: opensource.org · IP: 104.20.30.15 · AS13335 · US
- Server: cloudflare
- Page title: The MIT License – Open Source Initiative
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 10 16: · subject CN=opensource.org
- HTTP requests captured: 34
- Scan tier: fast · observed 2026-08-23 13:58:42 UTC
Redirect chain
http://www.opensource.org/licenses/mit-license.phphttps://www.opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mithttps://opensource.org/license/mit
Malware communicating with this URL (53)
These samples were observed contacting or being served from opensource.org. Each links to its full analysis.
- 13d72132cc2b9a165a1e171e407a3b15b637e1e55a6c20fadd8833e4f5662cd2 - referenced ·
13d72132cc2b9a165a1e171e407a3b15· first seen 2026-08-23 - 266a6f3275bd09c8426cbd673f609a3b8955046528b38f70f8b671b1a3c9be46 - referenced ·
266a6f3275bd09c8426cbd673f609a3b· first seen 2026-08-23 - f826174d982c8dbf3715cfc31a19fc2f43a304efb669d6c5435e41f79d17fcb3 - referenced ·
f826174d982c8dbf3715cfc31a19fc2f· first seen 2026-08-23 - dbb3beb00e49113bf09df27a712a3fb637424462b1dcfab72465992853534d4d - referenced ·
dbb3beb00e49113bf09df27a712a3fb6· first seen 2026-08-23 - 9d34868f2fb6d47fda998eb01879746c137e267e3e92a5768a19676daa1b6106 - referenced ·
9d34868f2fb6d47fda998eb01879746c· first seen 2026-08-22 - c828ed8736a781c9cab0cfecae84fcdcabd89320767c19272f9e06c0166b8079 - referenced ·
c828ed8736a781c9cab0cfecae84fcdc· first seen 2026-08-22 - f82c0702ca42c3b4a78b9ed5eeafbe4f3f2ae1c22970ed14d2c2752ce536fac8 - referenced ·
f82c0702ca42c3b4a78b9ed5eeafbe4f· first seen 2026-08-22 - f726976d12111292e490c45fb23970af9bf5db2b387c2ce9fd02af82a4a42ed8 - referenced ·
f726976d12111292e490c45fb23970af· first seen 2026-08-22 - c0febc254fa7aa3480ffe9f56bdf41052b2f2671dd9bb80a68bbc344b7e45979 - referenced ·
c0febc254fa7aa3480ffe9f56bdf4105· first seen 2026-08-22 - 03cf3b788540276f332862439abd78cc7f8cd273d6340d2393e7a471b70de324 - referenced ·
03cf3b788540276f332862439abd78cc· first seen 2026-08-22 - f9967f752c58162309bcef6479767c076ef73fc5e9c907610d4cff1fe1b12dfb - referenced ·
f9967f752c58162309bcef6479767c07· first seen 2026-08-22 - 7e921b0e6504812a1688d260e8a33fb3bfc5ca16b7168780fedb213f78576b86 - referenced ·
7e921b0e6504812a1688d260e8a33fb3· first seen 2026-08-22 - a6d622955c2bab36867a9fd7ba0928d62a26e436b1c5155f186b64cc7e9459da - referenced ·
a6d622955c2bab36867a9fd7ba0928d6· first seen 2026-08-22 - Genpack - referenced ·
0a00af95eeff9f2b4cb2bf1d6e1043ab· first seen 2026-08-22 - d32ce15309765186e5fd3a257b4c1cfbff65b7ff225f980ac26189e9dd5a0a1b - referenced ·
d32ce15309765186e5fd3a257b4c1cfb· first seen 2026-08-22
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Long redirect chain (4 hops)
- Cross-host redirect chain
Detected technologies
- Cloudflare
- WordPress
- jQuery
Contacted infrastructure
- 104.20.30.15 - AS13335 Cloudflare, Inc. (United States)
- 172.66.171.169 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- opensource.org
- gmpg.org
- unpkg.com
- i0.wp.com
- c0.wp.com
- js.stripe.com
- social.opensource.org
- twitter.com
- www.linkedin.com
- www.reddit.com
- go.opensource.org
- discuss.opensource.org
- opensource.net
- web.archive.org
- wordpress.com
- pressable.com
- cookiedatabase.org
- stats.wp.com
- 104.20.30.15
- 172.66.171.169
Other scans of opensource.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://ianlunn.github.io/Hover/ - 22 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown ·
https://brm.io/jquery-match-height/ - 21 Aug 2026 - unknown
- 19 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 19 Aug 2026 - unknown
- 19 Aug 2026 - unknown
Questions about opensource.org
- Is opensource.org safe?
- The scan of opensource.org on 23 Aug 2026 reached no verdict either way (score 14). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with opensource.org?
- 53 analysed samples communicate with this URL, including Genpack.
- How was opensource.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of opensource.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan