www.coca-cola.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.coca-cola.com and returned a suspicious verdict (score 28). The page resolved to 3.175.115.58 on Amazon.com, Inc. in US. 8 domains and 2 IPs were contacted, over 10 HTTP requests. 1 malware sample communicates with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://www.coca-cola.com/ - Domain: www.coca-cola.com · IP: 3.175.115.58 · AS16509 · US
- Server: CEP
- Page title: Coca-Cola Australia - Home Page | Coca-Cola AU
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M04 · valid to Dec 30 23: · subject CN=*.coca-cola.com
- HTTP requests captured: 10
- Scan tier: fast · observed 2026-08-21 20:42:19 UTC
Redirect chain
https://www.coca-cola.com/https://www.coca-cola.com/au/en
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.coca-cola.com. Each links to its full analysis.
- f83ada020399dddcfc3f0716b83c3397f03c8836b6cddf631b03f6e69988968b - referenced ·
f83ada020399dddcfc3f0716b83c3397· first seen 2026-08-21
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Amazon CloudFront
- Google Analytics
Contacted infrastructure
- 3.175.115.58 - AS16509 Amazon.com, Inc. (United States)
- 3.175.115.68 - AS16509 Amazon.com, Inc. (United States)
Observed indicators
- www.coca-cola.com
- rum.hlx.page
- cdn.cookielaw.org
- cdn.global.gcds.coke.com
- www.googletagmanager.com
- www.google.com
- datatrust.coca-cola.com
- www.linkedin.com
- 3.175.115.58
- 3.175.115.68
- https://www.coca-cola.com/au/en
- https://rum.hlx.page/.rum/@adobe/helix-rum-js@%5E2/dist/micro.js
- https://www.coca-cola.com/onexp-theme/310fbcb9db69f4253cc3bf75d90404f4855b45ff6f39e9c32d657820991005f8/theme.css
- https://cdn.cookielaw.org/scripttemplates/otSDKStub.js
- https://www.coca-cola.com/onexp-theme/310fbcb9db69f4253cc3bf75d90404f4855b45ff6f39e9c32d657820991005f8/resources/splash-screens/iPhone_16_Pro_Max_landscape.png
- https://www.coca-cola.com/onexp-theme/310fbcb9db69f4253cc3bf75d90404f4855b45ff6f39e9c32d657820991005f8/resources/splash-screens/iPhone_16_Pro_landscape.png
- https://www.coca-cola.com/onexp-theme/310fbcb9db69f4253cc3bf75d90404f4855b45ff6f39e9c32d657820991005f8/resources/splash-screens/iPhone_16_Pl__iPhone_15_Pro_Max__iPhone_15_Pl__iPhone_14_Pro_Max_land.png
- https://www.coca-cola.com/onexp-theme/310fbcb9db69f4253cc3bf75d90404f4855b45ff6f39e9c32d657820991005f8/resources/splash-screens/iPhone_16__iPhone_15_Pro__iPhone_15__iPhone_14_Pro_landscape.png
- https://www.coca-cola.com/onexp-theme/310fbcb9db69f4253cc3bf75d90404f4855b45ff6f39e9c32d657820991005f8/resources/splash-screens/iPhone_14_Plus__iPhone_13_Pro_Max__iPhone_12_Pro_Max_landscape.png
- https://www.coca-cola.com/onexp-theme/310fbcb9db69f4253cc3bf75d90404f4855b45ff6f39e9c32d657820991005f8/resources/splash-screens/iPhone_14__iPhone_13_Pro__iPhone_13__iPhone_12_Pro__iPhone_12_land.png
Questions about www.coca-cola.com
- Is www.coca-cola.com safe?
- No. MalwareAnalyzer scanned www.coca-cola.com on 21 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.coca-cola.com?
- 1 analysed samples communicate with this URL.
- How was www.coca-cola.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.coca-cola.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan