www.spip.net - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.spip.net and returned a suspicious verdict (score 43). The page resolved to 151.80.20.125 on OVH SAS in FR. The domain was registered 8745 days ago through OVH sas. 3 domains and 1 IP were contacted, over 2 HTTP requests. 1 malware sample communicates with this URL. The request followed 2 redirects before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 43) · Confidence 49%
- Scanned URL:
http://www.spip.net/ - Domain: www.spip.net · IP: 151.80.20.125 · AS16276 · FR
- Server: Apache
- Page title: SPIP
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: OVH sas · domain age 8745 days · created 2002-09-11
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 19 05: · subject CN=spip.net
- HTTP requests captured: 2
- Scan tier: fast · observed 2026-08-21 18:27:24 UTC
Redirect chain
http://www.spip.net/https://www.spip.net/https://www.spip.net/en_rubrique25.html
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.spip.net. Each links to its full analysis.
- 3f75d710f5a2f6449186b8d631698d841bbf4cfe7156d4bdae81610c71ab7458 - referenced ·
3f75d710f5a2f6449186b8d631698d84· first seen 2026-08-21
Antivirus & YARA (2 of 47 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
- YARA: Stratosphere IPS [yara]: STRATO_Tor_Onion_C2 (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- 2 antivirus/YARA engines flagged the page content: SOPHOS_Gootloader_JS, STRATO_Tor_Onion_C2
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Apache
Contacted infrastructure
- 151.80.20.125 - AS16276 OVH SAS (France)
Observed indicators
- www.spip.net
- mamot.fr
- www.uzine.net
- 151.80.20.125
- https://www.spip.net/en_rubrique25.html
- https://www.spip.net/spip.php?page=backend
- https://www.spip.net/local/cache-css/783b9ba75633bdb6a1537fc091517381.css?1787247022
- https://www.spip.net/local/cache-js/4de948d42be09c8a7cd434eced4e67e1.js?1787249383
- https://www.spip.net/spip.php?page=opensearch.xml
- https://www.spip.net/local/cache-gd2/e1/90951bb7dda1912dd06c731a3c34f0.ico?1787062312
- https://www.spip.net/?page=spipnav.js
- https://www.spip.net/plugins/galactic_spip_net/javascript/jquery.innerfade.js
- https://mamot.fr/@spip
- https://www.spip.net/spip.php?page=sommaire&lang=en
- https://www.spip.net/ar_rubrique34.html
- https://www.spip.net/ast_rubrique568.html
- https://www.spip.net/bg_rubrique198.html
- https://www.spip.net/br_rubrique630.html
- https://www.spip.net/ca_rubrique208.html
- https://www.spip.net/co_rubrique595.html
Questions about www.spip.net
- Is www.spip.net safe?
- No. MalwareAnalyzer scanned www.spip.net on 21 Aug 2026 and returned a suspicious verdict with a score of 43 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.spip.net?
- 1 analysed samples communicate with this URL.
- How was www.spip.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.spip.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan