www.disneyplus.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.disneyplus.com and returned a suspicious verdict (score 34). The page resolved to 23.221.132.223 on Akamai Technologies, Inc. in AU. 14 domains and 2 IPs were contacted, over 18 HTTP requests. 2 malware samples communicate with this URL. The request followed 2 redirects before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 34) · Confidence 43%
- Scanned URL:
http://www.hulu.com/ - Domain: www.disneyplus.com · IP: 23.221.132.223 · AS16625 · AU
- Page title: Disney+ | Stream Movies, TV Shows, Documentaries & More | U.S. Site
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=GB, ST=Greater Manchester, L=Salford, O=COMODO CA Limited, CN=COMODO RSA Organization Validation Secure Server CA · valid to Nov 14 23: · subject C=US, ST=California, O=The Walt Disney Company, CN=*.disneyplus.com
- Evidenced operator: The Walt Disney Company
- HTTP requests captured: 18
- Scan tier: fast · observed 2026-08-21 07:58:24 UTC
Redirect chain
http://www.hulu.com/http://www.disneyplus.com/https://www.disneyplus.com/
Malware communicating with this URL (2)
These samples were observed contacting or being served from www.disneyplus.com. Each links to its full analysis.
- a1be19891b68ad0da52007a4aeca67dc004dc1332706c5718628a1a62ea1d833 - referenced ·
a1be19891b68ad0da52007a4aeca67dc· first seen 2026-08-21 - f242e25f4083267344721a0c7b5452796d0f9db6ec269b3fb3674b20b4f6c307 - referenced ·
f242e25f4083267344721a0c7b545279· first seen 2026-08-20
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Detected technologies
- Next.js
Contacted infrastructure
- 23.221.132.223 - AS16625 Akamai Technologies, Inc. (Australia)
- 23.33.238.103 - AS20940 Akamai Technologies, Inc. (Australia)
Observed indicators
- www.disneyplus.com
- static-assets.bamgrid.com
- disney.images.edge.bamgrid.com
- prod-static.disney-plus.net
- help.disneyplus.com
- cnbl-cdn.bamgrid.com
- perks.disneyplus.com
- www.hulu.com
- privacy.thewaltdisneycompany.com
- x.com
- www.facebook.com
- www.instagram.com
- www.tiktok.com
- www.youtube.com
- 23.221.132.223
- 23.33.238.103
- https://www.disneyplus.com/
- https://static-assets.bamgrid.com/
- https://disney.images.edge.bamgrid.com/
- https://www.disneyplus.com/assets/15c8a283c06b041b30e602d739e0249cb0012294a4a
Other scans of www.disneyplus.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - suspicious ·
https://abcnews.com/Health/Healthday/story?id=4508669 - 21 Aug 2026 - suspicious ·
https://abc.com/
Questions about www.disneyplus.com
- Is www.disneyplus.com safe?
- No. MalwareAnalyzer scanned www.disneyplus.com on 21 Aug 2026 and returned a suspicious verdict with a score of 34 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.disneyplus.com?
- 2 analysed samples communicate with this URL.
- How was www.disneyplus.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.disneyplus.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan