www.binance.com - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.binance.com and returned a malicious verdict (score 100). The page resolved to 108.158.20.16 on Amazon.com, Inc. in AU. The domain was registered 3428 days ago through MarkMonitor Inc.. 11 domains and 9 IPs were contacted, over 155 HTTP requests. 3 malware samples communicate with this URL. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 100) · Confidence 100%
- Scanned URL:
https://www.binance.com/ - Domain: www.binance.com · IP: 108.158.20.16 · AS16509 · AU
- Server: CloudFront
- HTTP status: 202 · text/html; charset=UTF-8
- Registrar: MarkMonitor Inc. · domain age 3428 days · created 2017-04-01
- TLS issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=GeoTrust TLS RSA CA G1 · valid to Jan 9 23: · subject C=KY, L=GEORGE TOWN, O=Binance Holdings Limited, CN=*.binance.com
- Evidenced operator: Binance Holdings Limited
- HTTP requests captured: 155 · cookies set: 4 · outgoing links: 130
- Scan tier: standard · observed 2026-08-21 11:04:08 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from www.binance.com. Each links to its full analysis.
- c285743be1d2f01eb3d134750b71571797eb5d18affd0715ba2286da23580763.exe - referenced ·
c285743be1d2f01eb3d134750b715717· first seen 2026-08-17 - fcf3ceac44b1c95dcc7442ddac5b286f64954c00cc09a265eeedd4638dbfac2e.exe - referenced ·
fcf3ceac44b1c95dcc7442ddac5b286f· first seen 2026-08-16 - 40a1831b2c77c3026e01b6eb0e9846dd3c909ced0f55cb396165d23d9e5926c9.exe - referenced ·
40a1831b2c77c3026e01b6eb0e9846dd· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Runtime data beacon to fe4385362baa.79a973b7.ap-southeast-2.token.awswaf.com
- Runtime data beacon to o529943.ingest.sentry.io
- Runtime data beacon to api.saasexch.co
Detected technologies
- Amazon CloudFront
Contacted infrastructure
- 108.158.20.16 - AS16509 Amazon.com, Inc. (Australia)
- 151.101.130.217 - AS54113 Fastly, Inc. (United States)
Observed indicators
- www.binance.com
- fe4385362baa.79a973b7.ap-southeast-2.token.awswaf.com
- bin.bnbstatic.com
- public.bnbstatic.com
- js.sentry-cdn.com
- cdn.cookielaw.org
- browser.sentry-cdn.com
- o529943.ingest.sentry.io
- geolocation.onetrust.com
- api.saasexch.co
- accounts.google.com
- 108.158.20.16
- 3.175.115.89
- 18.65.244.31
- 18.65.244.82
- 104.18.87.42
- 151.101.130.217
- 34.160.81.0
- 172.64.155.119
- 52.193.185.16
Other scans of www.binance.com (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 17 Aug 2026 - benign ·
https://www.binance.com/ - 16 Aug 2026 - benign ·
https://www.binance.com/ - 12 Aug 2026 - benign ·
https://www.binance.com/
Questions about www.binance.com
- Is www.binance.com safe?
- No. MalwareAnalyzer scanned www.binance.com on 21 Aug 2026 and returned a malicious verdict with a score of 100 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.binance.com?
- 3 analysed samples communicate with this URL.
- How was www.binance.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.binance.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan