vanadium.github.io - malicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned vanadium.github.io and returned a malicious verdict (score 58). The page resolved to 185.199.108.153 on GitHub, Inc. in US. 3 domains and 2 IPs were contacted, over 3 HTTP requests. 2 malware samples communicate with this URL (Beebone). The request followed 1 redirect before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 58) · Confidence 64%
- Scanned URL:
https://v.io/ - Domain: vanadium.github.io · IP: 185.199.108.153 · AS54113 · US
- Server: GitHub.com
- Page title: Home - Vanadium
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 31 23: · subject CN=*.github.io
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-23 16:12:41 UTC
Redirect chain
https://v.io/https://vanadium.github.io/
Malware communicating with this URL (2)
These samples were observed contacting or being served from vanadium.github.io. Each links to its full analysis.
- Beebone - referenced ·
ff5e076dff03c79a2c70f1719fe66575· first seen 2026-08-23 - 4690042_new__english__file_.pdf - referenced ·
626f7627f105bb6693ec8b9185735218· first seen 2026-08-16
Antivirus & YARA (3 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
- YARA: Stratosphere IPS [yara]: STRATO_Tor_Onion_C2 (page content)
Why this verdict
- 3 antivirus/YARA engines flagged the page content: DLV_Maldoc_VBA_AutoExec, JPCERT_LODEINFO, STRATO_Tor_Onion_C2
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- GitHub Pages
- Fastly
- React
- Google Analytics
Contacted infrastructure
- 185.199.108.153 - AS54113 GitHub, Inc. (United States)
- 44.240.248.160 - AS16509 Amazon.com, Inc. (US)
Observed indicators
- vanadium.github.io
- fonts.googleapis.com
- github.com
- 185.199.108.153
- 44.240.248.160
- https://vanadium.github.io/
- https://fonts.googleapis.com/css?family=Roboto:300,300italic,400,400italic,500,500italic,700,700italic|Source+Code+Pro
- https://vanadium.github.io/css/github.css
- https://vanadium.github.io/css/material.min.css
- https://fonts.googleapis.com/icon?family=Material+Icons
- https://vanadium.github.io/js/react-0.14.3.min.js
- https://vanadium.github.io/js/react-dom-0.14.3.min.js
- https://vanadium.github.io/favicons/apple-touch-icon-57x57.png
- https://vanadium.github.io/favicons/apple-touch-icon-114x114.png
- https://vanadium.github.io/favicons/apple-touch-icon-72x72.png
- https://vanadium.github.io/favicons/apple-touch-icon-144x144.png
- https://vanadium.github.io/favicons/apple-touch-icon-60x60.png
- https://vanadium.github.io/favicons/apple-touch-icon-120x120.png
- https://vanadium.github.io/favicons/apple-touch-icon-76x76.png
- https://vanadium.github.io/favicons/apple-touch-icon-152x152.png
Other scans of vanadium.github.io (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 16 Aug 2026 - unknown
Questions about vanadium.github.io
- Is vanadium.github.io safe?
- No. MalwareAnalyzer scanned vanadium.github.io on 23 Aug 2026 and returned a malicious verdict with a score of 58 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with vanadium.github.io?
- 2 analysed samples communicate with this URL, including Beebone.
- How was vanadium.github.io checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of vanadium.github.io
Scanned on MalwareAnalyzer by Cyble · Open interactive scan