www.mingw-w64.org - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.mingw-w64.org and returned a suspicious verdict (score 20), categorised as suspicious-infrastructure. The page resolved to 185.199.110.153 on GitHub, Inc. in US. 71 domains and 5 IPs were contacted, over 1 HTTP request. 1 malware sample communicates with this URL (Mikey). The request followed 4 redirects before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 32%
- Scanned URL:
http://mingw-w64.sourceforge.net/ - Domain: www.mingw-w64.org · IP: 185.199.110.153 · AS54113 · US
- Server: GitHub.com
- Page title: mingw-w64
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Sep 27 17: · subject CN=www.mingw-w64.org
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-22 05:23:14 UTC
Redirect chain
http://mingw-w64.sourceforge.net/https://mingw-w64.sourceforge.net/http://mingw-w64.org/http://www.mingw-w64.org/https://www.mingw-w64.org/
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.mingw-w64.org. Each links to its full analysis.
- Mikey - referenced ·
dbe6eb8fa069c3edcea4a87b1193539b· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- suspicious-infrastructure
Why this verdict
- Algorithmically-generated (DGA-like) hostname
- Valid TLS, no impersonation or off-origin credential post
- Long redirect chain (4 hops)
- Cross-host redirect chain
Detected technologies
- GitHub Pages
- Fastly
Contacted infrastructure
- 185.199.110.153 - AS54113 GitHub, Inc. (United States)
- 104.18.13.149 - AS13335 Cloudflare, Inc. (United States)
- 104.18.12.149 - AS13335 Cloudflare, Inc. (United States)
- 88.99.69.85 - AS24940 Hetzner Online GmbH (Germany)
- 185.199.111.153 - AS54113 GitHub, Inc. (United States)
Observed indicators
- www.mingw-w64.org
- github.com
- cygwin.com
- reactos.org
- winehq.org
- www.msys2.org
- fedoraproject.org
- npackd.appspot.com
- opensuse.org
- win-builds.org
- code.google.com
- www.blender.org
- www.boost.org
- botan.randombit.net
- www.codeblocks.org
- www.crownengine.org
- daetools.sourceforge.net
- devkitpro.org
- sourceforge.net
- www.ecere.org
Questions about www.mingw-w64.org
- Is www.mingw-w64.org safe?
- No. MalwareAnalyzer scanned www.mingw-w64.org on 22 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100, categorised as suspicious-infrastructure. Treat it as hostile until it is re-checked.
- What malware is associated with www.mingw-w64.org?
- 1 analysed samples communicate with this URL, including Mikey.
- How was www.mingw-w64.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.mingw-w64.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan