opensource.org - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned opensource.org and returned a unknown verdict (score 0). The page resolved to 172.66.171.169 on Cloudflare, Inc. in US. The domain was registered 10419 days ago through Gandi SAS. 18 domains and 2 IPs were contacted, over 34 HTTP requests. 5 malware samples communicate with this URL (Fromcharcode). The request followed 2 redirects before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 6%
- Scanned URL:
http://opensource.org/licenses/MIT - Domain: opensource.org · IP: 172.66.171.169 · AS13335 · US
- Server: cloudflare
- Page title: The MIT License – Open Source Initiative
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Gandi SAS · domain age 10419 days · created 1998-02-11
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 10 16: · subject CN=opensource.org
- HTTP requests captured: 34
- Scan tier: fast · observed 2026-08-22 21:13:16 UTC
Redirect chain
http://opensource.org/licenses/MIThttps://opensource.org/licenses/MIThttps://opensource.org/license/MIT
Malware communicating with this URL (5)
These samples were observed contacting or being served from opensource.org. Each links to its full analysis.
- f3bc02b1c0926908438063a3a28cf1a5ee38bdae609afea6e27834677f6132d6 - referenced ·
f3bc02b1c0926908438063a3a28cf1a5· first seen 2026-08-22 - 282b46086b107433df22398e4aed6774a7ab45d0489c0dbd000bf3f2fd270b88 - referenced ·
282b46086b107433df22398e4aed6774· first seen 2026-08-19 - popper.min.js - referenced ·
e290dc4993b9ae7d34440db26be412b4· first seen 2026-08-15 - 9ec3f1c174a58929296ade5ee480108d74f1c29298c7b8a53a4f4680614f370a - referenced ·
9ec3f1c174a58929296ade5ee480108d· first seen 2026-08-15 - Fromcharcode - referenced ·
9316a4ad6336d042939e1d4c05e7ec84· first seen 2026-08-14
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Cloudflare
- WordPress
- jQuery
Contacted infrastructure
- 172.66.171.169 - AS13335 Cloudflare, Inc. (United States)
- 104.20.30.15 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- opensource.org
- gmpg.org
- unpkg.com
- i0.wp.com
- c0.wp.com
- js.stripe.com
- social.opensource.org
- twitter.com
- www.linkedin.com
- www.reddit.com
- go.opensource.org
- discuss.opensource.org
- opensource.net
- web.archive.org
- wordpress.com
- pressable.com
- cookiedatabase.org
- stats.wp.com
- 172.66.171.169
- 104.20.30.15
Other scans of opensource.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://opensource.org/license/mit - 23 Aug 2026 - unknown ·
http://ianlunn.github.io/Hover/ - 23 Aug 2026 - unknown ·
https://opensource.org/license/mit - 22 Aug 2026 - unknown ·
https://opensource.org/license/mit - 22 Aug 2026 - unknown ·
https://opensource.org/license/mit - 21 Aug 2026 - unknown ·
https://opensource.org/license/mit - 21 Aug 2026 - unknown ·
https://brm.io/jquery-match-height/ - 21 Aug 2026 - unknown ·
https://opensource.org/license/mit - 19 Aug 2026 - unknown
- 19 Aug 2026 - unknown ·
https://opensource.org/license/mit
Questions about opensource.org
- Is opensource.org safe?
- The scan of opensource.org on 22 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with opensource.org?
- 5 analysed samples communicate with this URL, including Fromcharcode.
- How was opensource.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of opensource.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan