x.com - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned x.com and returned a benign verdict (score 0). The page resolved to 172.66.0.227 on Cloudflare, Inc. in US. The domain was registered 12195 days ago through GoDaddy.com, LLC. 11 domains and 2 IPs were contacted, over 1 HTTP request. 217 malware samples communicate with this URL (HUILoader). The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 6%
- Scanned URL:
https://window.name/ - Domain: x.com · IP: 172.66.0.227 · AS13335 · US
- Server: cloudflare envoy
- Page title: Dave Vieira-Kurz (@secalert) / X
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: GoDaddy.com, LLC · domain age 12195 days · created 1993-04-02
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 12 17: · subject CN=*.x.com
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-22 16:23:13 UTC
Redirect chain
https://window.name/https://x.com/secalert
Malware communicating with this URL (217)
These samples were observed contacting or being served from x.com. Each links to its full analysis.
- 03cf3b788540276f332862439abd78cc7f8cd273d6340d2393e7a471b70de324 - referenced ·
03cf3b788540276f332862439abd78cc· first seen 2026-08-22 - c954b4692b7b46d5a934bb144e7f1837048372f0e9adfff4fdade7810fbf4f15 - referenced ·
c954b4692b7b46d5a934bb144e7f1837· first seen 2026-08-22 - 7a8e049209f9f70ad8a75173745513a14ea89317549c80b1581a67bfb201ca82 - referenced ·
7a8e049209f9f70ad8a75173745513a1· first seen 2026-08-22 - a50d7439302e7512830117a4adadf69ca5df83b5a9ee413834e13b89669f979e - referenced ·
a50d7439302e7512830117a4adadf69c· first seen 2026-08-22 - 871973f7d76606f7643f6873b6f48b2365654875dc28871c6ff054cdccfed4f1 - referenced ·
871973f7d76606f7643f6873b6f48b23· first seen 2026-08-22 - 545fd6a5f1d01ca0f4c27bc45fba7adcbd3d6a0c560fad6aa269caa317955690 - referenced ·
545fd6a5f1d01ca0f4c27bc45fba7adc· first seen 2026-08-22 - HUILoader - referenced ·
f0c5310b417e17d4aa862aca54dc26b8· first seen 2026-08-22 - 69f292c9e0ef1a8bf08f2ba9940a00fbe920548dcb2d295afc29beb0489c1093 - referenced ·
69f292c9e0ef1a8bf08f2ba9940a00fb· first seen 2026-08-22 - 9b9d633faa688c2503cc949ae15aec7d0a0d7e9f5d3e7f0978ac7c2330e01e2a - referenced ·
9b9d633faa688c2503cc949ae15aec7d· first seen 2026-08-22 - 162962d018f5eb7ba373683259fa878814dc6345b0b7b4a79d0b9fc9c7310d63 - referenced ·
162962d018f5eb7ba373683259fa8788· first seen 2026-08-22 - 9c809c0e13ef8b80f1aed5875d7f57461daa83ecbe663bed648528c3e265dbae - referenced ·
9c809c0e13ef8b80f1aed5875d7f5746· first seen 2026-08-22 - 4cea4ce8e9d4b7166c1690234bffde6f664e2f3f224fc289663cc50b58f85b9e - referenced ·
4cea4ce8e9d4b7166c1690234bffde6f· first seen 2026-08-22 - 2829d845d7c8339fccca8bb14663a84caa859797666f05a1ecb04ae135af96dc - referenced ·
2829d845d7c8339fccca8bb14663a84c· first seen 2026-08-22 - fe36abde5ed5448be7d42b6668a0db8ca4d678a3323b63f24492383d68dd4479 - referenced ·
fe36abde5ed5448be7d42b6668a0db8c· first seen 2026-08-22 - 92fd0e889756dd8a39cfef4c836e387f414c5c36e0c76111d5d2828f4cf8f537 - referenced ·
92fd0e889756dd8a39cfef4c836e387f· first seen 2026-08-22
Antivirus & YARA (1 of 48 engines)
- YARA: Stratosphere IPS [yara]: STRATO_Tor_Onion_C2 (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (STRATO_Tor_Onion_C2) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.66.0.227 - AS13335 Cloudflare, Inc. (United States)
- 3.33.251.168 - AS16509 Amazon Technologies Inc. (United States)
Observed indicators
- x.com
- pbs.twimg.com
- abs.twimg.com
- api.x.com
- t.co
- video.twimg.com
- ton.twimg.com
- cdn.syndication.twimg.com
- support.x.com
- help.x.com
- business.x.com
- 172.66.0.227
- 3.33.251.168
- https://x.com/secalert
- https://pbs.twimg.com/profile_images/885073344101576704/uyowCChm_400x400.jpg
- https://x.com/favicon.ico
- https://x.com/apple-touch-icon.png
- https://x.com/manifest.json
- https://abs.twimg.com/
- https://abs.twimg.com/fonts/subset/Chirp-Regular.c88864db.latin.woff2
Other scans of x.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - benign ·
https://community.dropbox.com/en/ - 24 Aug 2026 - unknown ·
https://hillhouseclassof1961.com/verify-ip?e18112bf-1230-4446-8af4-5acc080b525c - 24 Aug 2026 - unknown ·
https://s.ai/ - 24 Aug 2026 - unknown ·
https://www.wedrivers.ca/ - 24 Aug 2026 - unknown ·
https://www.yahoo.com/ - 24 Aug 2026 - unknown ·
https://getbootstrap.com/ - 24 Aug 2026 - unknown ·
https://www.le-nora.com/ - 24 Aug 2026 - unknown ·
https://www.yahoo.com/ - 24 Aug 2026 - unknown ·
https://www.oracle.com/java/weblogic/ - 24 Aug 2026 - unknown ·
https://www.healthdata.org/sites/default/files/resumes/mevupuxapiledowitire.pdf
Questions about x.com
- Is x.com safe?
- The scan of x.com on 22 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with x.com?
- 217 analysed samples communicate with this URL, including HUILoader.
- How was x.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of x.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan