x.gd - malicious URL scan, 12 Aug 2026
MalwareAnalyzer by Cyble scanned x.gd and returned a malicious verdict (score 70), categorised as malicious. The page resolved to 104.21.46.170 on Cloudflare, Inc. in US. The domain was registered 7184 days ago through Dynadot Inc. 6 domains and 2 IPs were contacted, over 21 HTTP requests. 1 malware sample communicates with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 12 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 70) · Confidence 100%
- Scanned URL:
https://data.to/ - Domain: x.gd · IP: 104.21.46.170 · AS13335 · US
- Server: cloudflare
- Page title: URL短縮サービス X.gd
- HTTP status: 200 · text/html
- Registrar: Dynadot Inc · domain age 7184 days · created 2006-12-11
- Registrant country: US
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Oct 5 17: · subject CN=x.gd
- HTTP requests captured: 21
- Scan tier: fast · observed 2026-08-12 22:45:14 UTC
Redirect chain
https://data.to/https://x.gd/
Malware communicating with this URL (1)
These samples were observed contacting or being served from x.gd. Each links to its full analysis.
- codeMirror.plugin.js - referenced ·
534519d5ab2b0875fba6b331b82a6872· first seen 2026-08-12
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Categories
- malicious
Why this verdict
- Listed by threatlens-reputation (malicious)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
- Next.js
- Google Analytics
- Cloudflare Insights
Contacted infrastructure
- 104.21.46.170 - AS13335 Cloudflare, Inc. (United States)
- 172.67.160.159 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- x.gd
- www.googletagmanager.com
- pagead2.googlesyndication.com
- fonts.googleapis.com
- fonts.gstatic.com
- static.cloudflareinsights.com
- 104.21.46.170
- 172.67.160.159
- https://x.gd/
- https://x.gd/_assets/img/image/shorten_image.svg
- https://x.gd/_assets/img/image/analytics_anime_bg1.png
- https://x.gd/_assets/img/image/analytics_anime_bg2.png
- https://x.gd/_assets/img/image/network_bg.svg
- https://x.gd/_next/static/css/9f391a0995a7287c.css
- https://x.gd/_next/static/chunks/webpack-66ac8b504e31bc35.js
- https://x.gd/_next/static/chunks/4bd1b696-d1bba8d2c588b5df.js
- https://x.gd/_next/static/chunks/1684-07faecaa0994d516.js
- https://x.gd/_next/static/chunks/main-app-2faec800178a199d.js
- https://x.gd/_next/static/chunks/3385-b62b2e7688410692.js
- https://x.gd/_next/static/chunks/9148-db0dc6bbd776ecd9.js
Other scans of x.gd (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - malicious
Questions about x.gd
- Is x.gd safe?
- No. MalwareAnalyzer scanned x.gd on 12 Aug 2026 and returned a malicious verdict with a score of 70 out of 100, categorised as malicious. Treat it as hostile until it is re-checked.
- What malware is associated with x.gd?
- 1 analysed samples communicate with this URL.
- How was x.gd checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of x.gd
Scanned on MalwareAnalyzer by Cyble · Open interactive scan