www.linkedin.com - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.linkedin.com and returned a malicious verdict (score 94), categorised as credential-harvest. The page resolved to 172.64.146.215 on Cloudflare, Inc. in US. The domain was registered 8692 days ago through MarkMonitor Inc.. 86 domains and 15 IPs were contacted, over 75 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 94) · Confidence 100%
- Scanned URL:
https://www.linkedin.com/ - Domain: www.linkedin.com · IP: 172.64.146.215 · AS13335 · US
- Server: cloudflare
- Page title: LinkedIn: Log In or Sign Up
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: MarkMonitor Inc. · domain age 8692 days · created 2002-11-02
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Sep 19 23: · subject C=US, ST=California, L=Sunnyvale, O=LinkedIn Corporation, CN=www.linkedin.com
- Evidenced operator: LinkedIn Corporation
- HTTP requests captured: 75 · cookies set: 19 · outgoing links: 160
- Scan tier: standard · observed 2026-08-20 19:24:05 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_Maldoc_VBA_AutoExec
- Runtime data beacon to lnkd.demdex.net
- Runtime data beacon to collector-pxdojv695v.protechts.net
- Credential-harvesting form
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.64.146.215 - AS13335 Cloudflare, Inc. (United States)
- 104.18.41.41 - AS13335 Cloudflare, Inc. (United States)
- 172.64.154.50 - AS13335 Cloudflare, Inc. (United States)
- 151.101.30.133 - AS54113 Fastly, Inc. (Australia)
- 104.18.33.206 - AS13335 Cloudflare, Inc. (United States)
- 74.125.200.84 - AS15169 Google LLC (Singapore)
- 52.62.222.219 - AS16509 Amazon Technologies Inc. (Australia)
- 23.33.238.119 - AS20940 Akamai Technologies, Inc. (Australia)
- 157.240.8.35 - AS32934 Facebook, Inc. (Australia)
- 142.250.195.131 - AS15169 Google LLC (India)
- 142.250.195.162 - AS15169 Google LLC (India)
Observed indicators
- www.linkedin.com
- de.linkedin.com
- ie.linkedin.com
- ua.linkedin.com
- pt.linkedin.com
- il.linkedin.com
- my.linkedin.com
- in.linkedin.com
- bo.linkedin.com
- za.linkedin.com
- cn.linkedin.com
- au.linkedin.com
- id.linkedin.com
- ng.linkedin.com
- ch.linkedin.com
- jp.linkedin.com
- zw.linkedin.com
- jm.linkedin.com
- sv.linkedin.com
- gt.linkedin.com
Other scans of www.linkedin.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://opensource.org/license/mit - 24 Aug 2026 - unknown ·
https://www.oracle.com/java/weblogic/ - 24 Aug 2026 - unknown ·
https://www.healthdata.org/sites/default/files/resumes/mevupuxapiledowitire.pdf - 24 Aug 2026 - unknown ·
https://www.a1touchsolution.nl/en/sites/default/files/95216779236.pdf - 24 Aug 2026 - suspicious ·
https://naatsihwp.org.au/ - 24 Aug 2026 - unknown ·
https://www.a1touchsolution.nl/en/sites/default/files/95216779236.pdf - 24 Aug 2026 - unknown ·
https://www.o-i.com/ - 24 Aug 2026 - unknown ·
https://yoast.com/product/yoast-seo-premium-wordpress/ - 24 Aug 2026 - suspicious ·
https://developer.wordpress.org/rest-api/ - 24 Aug 2026 - suspicious ·
https://case.edu/
Questions about www.linkedin.com
- Is www.linkedin.com safe?
- No. MalwareAnalyzer scanned www.linkedin.com on 20 Aug 2026 and returned a malicious verdict with a score of 94 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- How was www.linkedin.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.linkedin.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan