opensource.org - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned opensource.org and returned a unknown verdict (score 14). The page resolved to 104.20.30.15 on Cloudflare, Inc. in US. The domain was registered 10419 days ago through Gandi SAS. 18 domains and 2 IPs were contacted, over 34 HTTP requests. 44 malware samples communicate with this URL (Genpack). The request followed 4 redirects before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 14) · Confidence 26%
- Scanned URL:
http://www.opensource.org/licenses/mit-license.php - Domain: opensource.org · IP: 104.20.30.15 · AS13335 · US
- Server: cloudflare
- Page title: The MIT License – Open Source Initiative
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Gandi SAS · domain age 10419 days · created 1998-02-11
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 10 16: · subject CN=opensource.org
- HTTP requests captured: 34
- Scan tier: fast · observed 2026-08-22 16:23:13 UTC
Redirect chain
http://www.opensource.org/licenses/mit-license.phphttps://www.opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mit-license.phphttps://opensource.org/licenses/mithttps://opensource.org/license/mit
Malware communicating with this URL (44)
These samples were observed contacting or being served from opensource.org. Each links to its full analysis.
- 03cf3b788540276f332862439abd78cc7f8cd273d6340d2393e7a471b70de324 - referenced ·
03cf3b788540276f332862439abd78cc· first seen 2026-08-22 - f9967f752c58162309bcef6479767c076ef73fc5e9c907610d4cff1fe1b12dfb - referenced ·
f9967f752c58162309bcef6479767c07· first seen 2026-08-22 - 7e921b0e6504812a1688d260e8a33fb3bfc5ca16b7168780fedb213f78576b86 - referenced ·
7e921b0e6504812a1688d260e8a33fb3· first seen 2026-08-22 - a6d622955c2bab36867a9fd7ba0928d62a26e436b1c5155f186b64cc7e9459da - referenced ·
a6d622955c2bab36867a9fd7ba0928d6· first seen 2026-08-22 - Genpack - referenced ·
0a00af95eeff9f2b4cb2bf1d6e1043ab· first seen 2026-08-22 - d32ce15309765186e5fd3a257b4c1cfbff65b7ff225f980ac26189e9dd5a0a1b - referenced ·
d32ce15309765186e5fd3a257b4c1cfb· first seen 2026-08-22 - 855217f6c5df51a140950b996c4012480079e63f4a81b24a6854091806a0cce4 - referenced ·
855217f6c5df51a140950b996c401248· first seen 2026-08-22 - be1d2d89603182c19507a2c8a80afa45cab9aa9b228db4eb88e4a5c335b11668 - referenced ·
be1d2d89603182c19507a2c8a80afa45· first seen 2026-08-21 - 3f7899ba69ccc7a23a418c62625e579ea9d406b1d02e28768d5cf8b18bc1d7d6 - referenced ·
3f7899ba69ccc7a23a418c62625e579e· first seen 2026-08-21 - a1be19891b68ad0da52007a4aeca67dc004dc1332706c5718628a1a62ea1d833 - referenced ·
a1be19891b68ad0da52007a4aeca67dc· first seen 2026-08-21 - 462a50436a95cd4fae493b5b52cee8a799bb281f35e1b38ea0ff1d9efa6d92d2 - referenced ·
462a50436a95cd4fae493b5b52cee8a7· first seen 2026-08-21 - 323b09a0dc664b18338036d2546899d907c218fdea8ed75bcf0d3452640d0aa2 - referenced ·
323b09a0dc664b18338036d2546899d9· first seen 2026-08-21 - b57ea7bf37f3f96df24e0b90bb5bf09f4ef7dea56f619fa32a717feef695abf7 - referenced ·
b57ea7bf37f3f96df24e0b90bb5bf09f· first seen 2026-08-21 - df066392d67063967325fcddf0440399235a135700429a5a238539f363b2ef67 - referenced ·
df066392d67063967325fcddf0440399· first seen 2026-08-21 - df0798f47b2ec938c54deac325a2198d27b40844de30a017f1092b791bd63ba4 - referenced ·
df0798f47b2ec938c54deac325a2198d· first seen 2026-08-21
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Long redirect chain (4 hops)
- Cross-host redirect chain
Detected technologies
- Cloudflare
- WordPress
- jQuery
Contacted infrastructure
- 104.20.30.15 - AS13335 Cloudflare, Inc. (United States)
- 172.66.171.169 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- opensource.org
- gmpg.org
- unpkg.com
- i0.wp.com
- c0.wp.com
- js.stripe.com
- social.opensource.org
- twitter.com
- www.linkedin.com
- www.reddit.com
- go.opensource.org
- discuss.opensource.org
- opensource.net
- web.archive.org
- wordpress.com
- pressable.com
- cookiedatabase.org
- stats.wp.com
- 104.20.30.15
- 172.66.171.169
Other scans of opensource.org (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown ·
http://ianlunn.github.io/Hover/ - 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown ·
https://brm.io/jquery-match-height/ - 21 Aug 2026 - unknown
- 19 Aug 2026 - unknown ·
https://opensource.org/license/MIT - 19 Aug 2026 - unknown
Questions about opensource.org
- Is opensource.org safe?
- The scan of opensource.org on 22 Aug 2026 reached no verdict either way (score 14). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with opensource.org?
- 44 analysed samples communicate with this URL, including Genpack.
- How was opensource.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of opensource.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan