www.reddit.com - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.reddit.com and returned a unknown verdict (score -4). The page resolved to 151.101.29.140 on Fastly, Inc. in AU. 2 domains and 2 IPs were contacted. 6 malware samples communicate with this URL (CobaltStrike, Mirai, Ursu). The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -4) · Confidence 10%
- Scanned URL:
https://reddit.com/ - Domain: www.reddit.com · IP: 151.101.29.140 · AS54113 · AU
- Server: snooserv
- HTTP status: 403 · text/html
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Feb 16 23: · subject C=US, ST=California, L=San Francisco, O=Reddit, Inc., CN=*.reddit.com
- Evidenced operator: Reddit, Inc.
- Scan tier: fast · observed 2026-08-22 02:57:51 UTC
Redirect chain
https://reddit.com/https://www.reddit.com/
Malware communicating with this URL (6)
These samples were observed contacting or being served from www.reddit.com. Each links to its full analysis.
- CobaltStrike - referenced ·
df060921eb2175d7fce9526fa889076f· first seen 2026-08-21 - CobaltStrike - referenced ·
dcc4e2ebb2c69d5628eba4664649fef0· first seen 2026-08-20 - 6ad2ee4bcd07718f7a8f4d3aa0661824e3ae16202440944a000085964598f457 - referenced ·
6ad2ee4bcd07718f7a8f4d3aa0661824· first seen 2026-08-17 - Mirai - referenced ·
ced43dcacd9725ccd26fe1e8be625d8d· first seen 2026-08-17 - Mirai - referenced ·
992132cce0a25055e5d6edc69fa4ef83· first seen 2026-08-17 - Ursu - referenced ·
e922a5842b5e5576be7e6a2301794495· first seen 2026-08-13
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Contacted infrastructure
- 151.101.29.140 - AS54113 Fastly, Inc. (Australia)
- 151.101.65.140 - AS54113 Fastly, Inc. (United States)
Observed indicators
- www.reddit.com
- support.reddithelp.com
- 151.101.29.140
- 151.101.65.140
- https://www.reddit.com/
- https://support.reddithelp.com/hc/en-us/requests/new?ticket_form_id=21879292693140
Other scans of www.reddit.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://opensource.org/license/mit - 23 Aug 2026 - unknown ·
https://www.cpanel.net/privacy-policy/ - 23 Aug 2026 - unknown ·
https://www.cpanel.net/blog/ - 23 Aug 2026 - unknown ·
https://opensource.org/license/mit - 22 Aug 2026 - unknown ·
https://www.ip2location.com/ - 22 Aug 2026 - unknown ·
https://www.ip2location.com/ - 22 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 22 Aug 2026 - unknown ·
https://opensource.org/license/mit - 22 Aug 2026 - unknown ·
https://www.pcgamer.com/mod-of-the-week-helgen-reborn-for-skyrim/ - 22 Aug 2026 - unknown ·
https://opensource.org/license/mit
Questions about www.reddit.com
- Is www.reddit.com safe?
- The scan of www.reddit.com on 22 Aug 2026 reached no verdict either way (score -4). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.reddit.com?
- 6 analysed samples communicate with this URL, including CobaltStrike, Mirai, Ursu.
- How was www.reddit.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.reddit.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan