stackoverflow.com - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned stackoverflow.com and returned a unknown verdict (score -12). The page resolved to 198.252.206.1 on Stack Exchange, Inc. in US. The domain was registered 8276 days ago through CSC Corporate Domains, Inc.. 1 domain and 1 IP were contacted. 9 malware samples communicate with this URL (Futurax, Lmir, Vindor, Gootloader). The request followed 1 redirect before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
http://stackoverflow.com/questions/7264899/detect-css-transitions-using-javascript-and-without-modernizr - Domain: stackoverflow.com · IP: 198.252.206.1 · AS36637 · US
- Server: cloudflare
- Page title: Just a moment...
- HTTP status: 403 · text/html; charset=UTF-8
- Registrar: CSC Corporate Domains, Inc. · domain age 8276 days · created 2003-12-26
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 13 12: · subject CN=stackoverflow.com
- Scan tier: fast · observed 2026-08-24 00:13:32 UTC
Redirect chain
http://stackoverflow.com/questions/7264899/detect-css-transitions-using-javascript-and-without-modernizrhttps://stackoverflow.com/questions/7264899/detect-css-transitions-using-javascript-and-without-modernizr
Malware communicating with this URL (9)
These samples were observed contacting or being served from stackoverflow.com. Each links to its full analysis.
- f26487d3240c969ad9a12f1298f953715b41bab74d447f70389535b9debfbef7 - referenced ·
f26487d3240c969ad9a12f1298f95371· first seen 2026-08-24 - Futurax - referenced ·
8111f53495650a9a9324ab3800755ea8· first seen 2026-08-23 - Lmir - referenced ·
0c8928ddda1d6431f0f5f6ecdea8850b· first seen 2026-08-22 - be246b5f45a90c86ba194b2cce0a174b360173cef1d0b6d0b6eae30829c23822 - referenced ·
be246b5f45a90c86ba194b2cce0a174b· first seen 2026-08-22 - Vindor - referenced ·
1d3360a2c60c1596c32b8377e21bd7d4· first seen 2026-08-21 - a138b6e1f54d7a69ea5361529149ed607142893c690bb993b4a15f239c039e2a - referenced ·
a138b6e1f54d7a69ea5361529149ed60· first seen 2026-08-20 - Gootloader - referenced ·
f1cbe5f24bb5373e39fa3abb363f16cf· first seen 2026-08-19 - Vindor - referenced ·
fd8b094127925088c09ce59830d1d30d· first seen 2026-08-15 - Delf - referenced ·
5dfe374d510b4b7a6e1fbf6b52ed61dc· first seen 2026-08-12
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
Contacted infrastructure
- 198.252.206.1 - AS36637 Stack Exchange, Inc. (United States)
Observed indicators
- stackoverflow.com
- 198.252.206.1
- https://stackoverflow.com/questions/7264899/detect-css-transitions-using-javascript-and-without-modernizr
- https://stackoverflow.com/cdn-cgi/challenge-platform/h/b/orchestrate/precursor_interstitial/v1?ray=a2fe26d8abbd3818
Other scans of stackoverflow.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://dimsemenov.com/plugins/magnific-popup/documentation.html - 24 Aug 2026 - suspicious ·
https://dimsemenov.com/plugins/magnific-popup/ - 23 Aug 2026 - unknown ·
https://jquery.com/license/ - 23 Aug 2026 - unknown ·
https://s.ai/ - 23 Aug 2026 - unknown ·
https://stanislavs.org/stopping-command-line-applications-programatically-with-ctrl-c-events-from-ne - 23 Aug 2026 - unknown ·
https://stackoverflow.com/questions/813086/can-i-send-a-ctrl-c-sigint-to-an-application-on-windows/1 - 23 Aug 2026 - suspicious ·
https://dimsemenov.com/plugins/magnific-popup/ - 23 Aug 2026 - unknown ·
https://s.ai/ - 23 Aug 2026 - unknown ·
https://jquery.com/license/ - 23 Aug 2026 - unknown ·
https://jqueryui.com/
Questions about stackoverflow.com
- Is stackoverflow.com safe?
- The scan of stackoverflow.com on 24 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with stackoverflow.com?
- 9 analysed samples communicate with this URL, including Futurax, Lmir, Vindor, Gootloader.
- How was stackoverflow.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of stackoverflow.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan