this.to - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned this.to and returned a unknown verdict (score -12). The page resolved to 216.150.1.1 on Vercel, Inc in US. 1 domain and 1 IP were contacted, over 10 HTTP requests. 21 malware samples communicate with this URL (Smuggling). This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://this.to/ - Domain: this.to · IP: 216.150.1.1 · AS16509 · US
- Server: Vercel
- Page title: this.to — the simplest way to create a searchable member vault
- HTTP status: 500 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 1 09: · subject CN=this.to
- HTTP requests captured: 10
- Scan tier: fast · observed 2026-08-24 04:23:26 UTC
Malware communicating with this URL (21)
These samples were observed contacting or being served from this.to. Each links to its full analysis.
- 9252ffad534f64285bbce0739ebd109e296e0195032dcab560bee6e55b2b3756 - referenced ·
9252ffad534f64285bbce0739ebd109e· first seen 2026-08-24 - 1edddbb1f62b69c632c5a558b8a24a4e6531fa5c286a915c854ec865150d5c5b - referenced ·
1edddbb1f62b69c632c5a558b8a24a4e· first seen 2026-08-23 - c828ed8736a781c9cab0cfecae84fcdcabd89320767c19272f9e06c0166b8079 - referenced ·
c828ed8736a781c9cab0cfecae84fcdc· first seen 2026-08-22 - Smuggling - referenced ·
0c32e55d652bb8e2994a2a58fe36dc81· first seen 2026-08-22 - cbe851a67755891aa5a083490a3656b2d990c55ee247d7be0a30c57db44e7475 - referenced ·
cbe851a67755891aa5a083490a3656b2· first seen 2026-08-22 - 582e11f2123922332199be9553d4d4945545efcc1337f94b9f004ba997abf4a9 - referenced ·
582e11f2123922332199be9553d4d494· first seen 2026-08-22 - 6048eb85c29c9852a1075997add5a4b00201efd11e0a68ed59f896dfa4ce5dc8 - referenced ·
6048eb85c29c9852a1075997add5a4b0· first seen 2026-08-22 - e476e9b003f635fe92e5a6a389bd242e55b6e96a376803d525c9649dabdbbdbc - referenced ·
e476e9b003f635fe92e5a6a389bd242e· first seen 2026-08-21 - 5e9d8d758a6195b29c57ca50480475e708ff3474ad797abd3738128ede0bb2f1 - referenced ·
5e9d8d758a6195b29c57ca50480475e7· first seen 2026-08-20 - 983801b612f719bd839b1085b0d45e4dd333e8757b5192bbdfa4d921b0406d93 - referenced ·
983801b612f719bd839b1085b0d45e4d· first seen 2026-08-19 - 904ba9cedd81e5b19dec43b57661f80cd50fc8f8581c17b2454dc5d7ce59932d - referenced ·
904ba9cedd81e5b19dec43b57661f80c· first seen 2026-08-19 - fe47c899d05a1f5bafd6f9432e67c58fb6091399d6387b70a0fcb541895896b4 - referenced ·
fe47c899d05a1f5bafd6f9432e67c58f· first seen 2026-08-19 - 243872184-lbx__pt_br.js - referenced ·
1d643e4b93da79c302afdc8dab7b357a· first seen 2026-08-16 - 3618766451-lbx__en_gb.js - referenced ·
88b4eee071a3e2d8836be1b02ec5b3e1· first seen 2026-08-14 - 521a940c7302b8ce2b5a55bd7beb3e2583c073b5b101453a4d34c39d88197220 - referenced ·
521a940c7302b8ce2b5a55bd7beb3e25· first seen 2026-08-14
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Vercel
- Next.js
Contacted infrastructure
- 216.150.1.1 - AS16509 Vercel, Inc (United States)
Observed indicators
- this.to
- 216.150.1.1
- https://this.to/
- https://this.to/_next/static/chunks/f0f16363684401dd.js
- https://this.to/_next/static/chunks/d9a1ac7dac50a49f.js
- https://this.to/_next/static/chunks/bd4ab1517efdc1c3.js
- https://this.to/_next/static/chunks/5476504fbe1f5f80.js
- https://this.to/_next/static/chunks/da1ebc61b4c2a760.js
- https://this.to/_next/static/chunks/e3c56e37a20391eb.js
- https://this.to/_next/static/chunks/turbopack-b212ddb74bc6bb80.js
- https://this.to/_next/static/chunks/8a07e07106d6caa4.js
- https://this.to/_next/static/chunks/6412a65c4350f826.js
- https://this.to/_next/static/chunks/a6dad97d9634a72d.js
- https://this.to/icon-light-32x32.png
- https://this.to/icon-dark-32x32.png
- https://this.to/icon.svg
- https://this.to/apple-icon.png
Other scans of this.to (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown
- 14 Aug 2026 - unknown
- 12 Aug 2026 - unknown
Questions about this.to
- Is this.to safe?
- The scan of this.to on 24 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with this.to?
- 21 analysed samples communicate with this URL, including Smuggling.
- How was this.to checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of this.to
Scanned on MalwareAnalyzer by Cyble · Open interactive scan