terrebleue.org - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned terrebleue.org and returned a suspicious verdict (score 28). The page resolved to 213.186.33.19 on OVH SAS in FR. 3 domains and 1 IP were contacted, over 6 HTTP requests. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://terrebleue.org/userfiles/file/lanugadurajalemod.pdf - Domain: terrebleue.org · IP: 213.186.33.19 · AS16276 · FR
- Server: Apache
- Page title: Page non trouvée - Terre Bleue
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 5 18: · subject CN=terrebleue.org
- HTTP requests captured: 6
- Scan tier: standard · observed 2026-08-21 15:35:57 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from terrebleue.org. Each links to its full analysis.
- Phishing - referenced ·
cb6016590e39b06e3af65e91cda77003· first seen 2026-08-15 - Phishing - referenced ·
768a6d133716c479ec6d7beaee8df6e0· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: JPCERT_LODEINFO
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Apache
- PHP
- WordPress
Contacted infrastructure
- 213.186.33.19 - AS16276 OVH SAS (France)
Observed indicators
- terrebleue.org
- fonts.googleapis.com
- fonts.gstatic.com
- 213.186.33.19
- https://terrebleue.org/userfiles/file/lanugadurajalemod.pdf
- https://fonts.googleapis.com/
- https://fonts.gstatic.com/
- https://terrebleue.org/feed/
- https://terrebleue.org/comments/feed/
- https://terrebleue.org/wp-includes/css/dist/block-library/style.min.css?ver=6.8.8
- https://terrebleue.org/wp-content/themes/impeka/css/font-awesome.min.css?ver=6.7.2
- https://terrebleue.org/wp-content/themes/impeka/css/font-awesome-v4-shims.min.css?ver=6.7.2
- https://terrebleue.org/wp-content/themes/impeka/css/theme-style.min.css?ver=2.1.1
- https://terrebleue.org/wp-content/plugins/impeka-wpb-extension/assets/css/wpb-grid.min.css?ver=2.1.0
- https://terrebleue.org/wp-content/plugins/impeka-wpb-extension/assets/css/ext-style.min.css?ver=2.1.0
- https://fonts.googleapis.com/css?family=Inter%3A400%2C600%2C500%2C900%7CLibre+Bodoni%3A400%2C600%2C400italic%7CLa+Belle+Aurore%3A400&subset=latin&display=swap&ver=1732518332
- https://terrebleue.org/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://terrebleue.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://terrebleue.org/wp-json/
- https://terrebleue.org/xmlrpc.php?rsd
Other scans of terrebleue.org (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - suspicious
Questions about terrebleue.org
- Is terrebleue.org safe?
- No. MalwareAnalyzer scanned terrebleue.org on 21 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with terrebleue.org?
- 2 analysed samples communicate with this URL, including Phishing.
- How was terrebleue.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of terrebleue.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan