Who did this?

66 views
Skip to first unread message

Bruno Postle

unread,
Apr 12, 2026, 4:17:34 AM (5 days ago) Apr 12
to hugin and other free panoramic software
This website looks to be LLM generated (but nevertheless very impressive). There is a single MSI installer download, which isn't a link to the sourceforge file, should we be concerned? https://huginpanorama.com/

Bruno

David W. Jones

unread,
Apr 12, 2026, 4:24:25 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
Well, I'd be concerned that the installer file offered for download is loaded with malware...


On April 11, 2026 10:17:10 PM HST, Bruno Postle <br...@postle.net> wrote:
This website looks to be LLM generated (but nevertheless very impressive). There is a single MSI installer download, which isn't a link to the sourceforge file, should we be concerned? https://huginpanorama.com/

Bruno


--
David W. Jones
gnome...@gmail.com
exploring the landscape of god
http://dancingtreefrog.com

Sent from my Android device with F/LOSS K-9 Mail.

Bruno Postle

unread,
Apr 12, 2026, 4:35:08 AM (5 days ago) Apr 12
to hugin and other free panoramic software
Me too, does anyone have resources to investigate? - Bruno

On Sun, 12 Apr 2026, 09:24 David W. Jones wrote:
Well, I'd be concerned that the installer file offered for download is loaded with malware...

On April 11, 2026 10:17:10 PM HST, Bruno Postle wrote:
This website looks to be LLM generated (but nevertheless very impressive). There is a single MSI installer download, which isn't a link to the sourceforge file, should we be concerned? https://huginpanorama.com/

Bruno

Maarten Verberne

unread,
Apr 12, 2026, 4:58:54 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
well, i'm not sure this will help, but you could:

Report abuse to the hosting provider with evidence (screenshots, links,
malware).
the domain is new, report it to the registrar (e.g., GoDaddy, Namecheap)
for impersonation.
Report the site to Google, Bing, etc., as a phishing/malware site via
their Safe Browsing reporting tools.
https://safebrowsing.google.com/report-phish/

if that's help i do not know, but it should at least give attention to
this problem.
Maarten

huginpanorama.com
Registered to User #92f61d80 Privacy
Email pwp-09b064efdb0b4e...@privacyguardian.org
Last Updated Apr 10, 2026
Expires On Apr 09, 2027
Registrar NameSilo, LLC
Name Servers crystal.ns.cloudflare.com viddy.ns.cloudflare.com


Type
Domain Name
TTL
Address
A huginpanorama.com/ 300
104.21.79.217Check IP Blacklist

Owner: CloudFlare Inc. [United States of America] WHOIS AS13335
A huginpanorama.com/ 300
172.67.171.141Check IP Blacklist

Owner: CloudFlare Inc. [United States of America] WHOIS AS13335
AAAA
[Show Raw]
Type
Domain Name
TTL
Address
AAAA huginpanorama.com/ 300
2606:4700:3034::ac43:ab8d

Owner: CloudFlare Inc. [United States of America] WHOIS
AAAA huginpanorama.com/ 300
2606:4700:3037::6815:4fd9

Owner: CloudFlare Inc. [United States of America] WHOIS



Op 12-4-2026 om 10:17 schreef Bruno Postle:
> This website looks to be LLM generated (but nevertheless very
> impressive). There is a single MSI installer download, which isn't a
> link to the sourceforge file, should we be concerned? https://
> huginpanorama.com/ <https://huginpanorama.com/>
>
> Bruno
>
> --
> A list of frequently asked questions is available at: http://
> wiki.panotools.org/Hugin_FAQ <http://wiki.panotools.org/Hugin_FAQ>
> ---
> You received this message because you are subscribed to the Google
> Groups "hugin and other free panoramic software" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to hugin-ptx+...@googlegroups.com <mailto:hugin-
> ptx+uns...@googlegroups.com>.
> To view this discussion visit https://groups.google.com/d/msgid/hugin-
> ptx/
> CAJV99Zj27jeA%3DTE%2BHik2GT3%2B6F0HWEOyX4geiz%2BOe__sEBLgWA%40mail.gmail.com <https://groups.google.com/d/msgid/hugin-ptx/CAJV99Zj27jeA%3DTE%2BHik2GT3%2B6F0HWEOyX4geiz%2BOe__sEBLgWA%40mail.gmail.com?utm_medium=email&utm_source=footer>.

Maarten Verberne

unread,
Apr 12, 2026, 5:03:21 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
Oh, and I'd also post a !!WARNING!! SECURITY NOTICE on the sourceforge
page, the readme, possible forums and other places you have access to,
that there is a fake website.

and you could submit the malware link to:
https://www.virustotal.com/
or
https://www.hybrid-analysis.com/
for public analysis



Op 12-4-2026 om 10:17 schreef Bruno Postle:
> This website looks to be LLM generated (but nevertheless very
> impressive). There is a single MSI installer download, which isn't a

Bruno Postle

unread,
Apr 12, 2026, 5:08:46 AM (5 days ago) Apr 12
to hugin and other free panoramic software
I'm not sure it is a problem, it should be ok to create a 'fan' site like this, but the download link *is* suspicious. There is no reason not to link to the sourceforge download - Bruno


On Sun, 12 Apr 2026, 09:58 Maarten Verberne wrote:
well, i'm not sure this will help, but you could:

Report abuse to the hosting provider with evidence (screenshots, links,
malware).
the domain is new, report it to the registrar (e.g., GoDaddy, Namecheap)
for impersonation.
Report the site to Google, Bing, etc., as a phishing/malware site via
their Safe Browsing reporting tools.
https://safebrowsing.google.com/report-phish/

if that's help i do not know, but it should at least give attention to
this problem.
Maarten

Bruno

Maarten Verberne

unread,
Apr 12, 2026, 5:11:52 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
you could submit the link to VirusTotal or Hybrid Analysis for public
analysis, if one of those flags the link, i suspect it's not a fan site

Op 12-4-2026 om 11:08 schreef Bruno Postle:
> I'm not sure it is a problem, it should be ok to create a 'fan' site
> like this, but the download link *is* suspicious. There is no reason not
> to link to the sourceforge download - Bruno
>
> On Sun, 12 Apr 2026, 09:58 Maarten Verberne wrote:
>
> well, i'm not sure this will help, but you could:
>
> Report abuse to the hosting provider with evidence (screenshots, links,
> malware).
> the domain is new, report it to the registrar (e.g., GoDaddy,
> Namecheap)
> for impersonation.
> Report the site to Google, Bing, etc., as a phishing/malware site via
> their Safe Browsing reporting tools.
> https://safebrowsing.google.com/report-phish/ <https://
> safebrowsing.google.com/report-phish/>
>
> if that's help i do not know, but it should at least give attention to
> this problem.
> Maarten
>
> Bruno
>
> --
> A list of frequently asked questions is available at: http://
> wiki.panotools.org/Hugin_FAQ <http://wiki.panotools.org/Hugin_FAQ>
> ---
> You received this message because you are subscribed to the Google
> Groups "hugin and other free panoramic software" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to hugin-ptx+...@googlegroups.com <mailto:hugin-
> ptx+uns...@googlegroups.com>.
> To view this discussion visit https://groups.google.com/d/msgid/hugin-
> ptx/
> CAJV99ZgtbmTCszjkuDSNcgbFK1g%2BdHmOcferNbWfORcZoPGLzw%40mail.gmail.com
> <https://groups.google.com/d/msgid/hugin-ptx/
> CAJV99ZgtbmTCszjkuDSNcgbFK1g%2BdHmOcferNbWfORcZoPGLzw%40mail.gmail.com?
> utm_medium=email&utm_source=footer>.

Maarten Verberne

unread,
Apr 12, 2026, 5:20:43 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
on virustotal it there were a lot of unrated, but that's no proof of
malware. so if you want to dig deeper, i guess submitting that specific
link to public is your best bet.

https://huginpanorama.com/
huginpanorama.com
results:
No security vendors flagged this URL as malicious

Abusix
Clean
Acronis
Clean
ADMINUSLabs
Clean
AILabs (MONITORAPP)
Clean
AlienVault
Clean
Antiy-AVL
Clean
benkow.cc
Clean
BitDefender
Clean
BlockList
Clean
Blueliv
Clean
Certego
Clean
CINS Army
Clean
CMC Threat Intelligence
Clean
CRDF
Clean
Criminal IP
Clean
Cyble
Clean
CyRadar
Clean
desenmascara.me
Clean
DNS8
Clean
Dr.Web
Clean
EmergingThreats
Clean
Emsisoft
Clean
ESET
Clean
ESTsecurity
Clean
Fortinet
Clean
G-Data
Clean
Google Safebrowsing
Clean
GreenSnow
Clean
Heimdal Security
Clean
IPsum
Clean
Juniper Networks
Clean
LevelBlue
Clean
Lionic
Clean
Malwared
Clean
MalwarePatrol
Clean
malwares.com URL checker
Clean
OpenPhish
Clean
Phishing Database
Clean
Phishtank
Clean
PREBYTES
Clean
Quick Heal
Clean
Quttera
Clean
Rising
Clean
Sangfor
Clean
Scantitan
Clean
SCUMWARE.org
Clean
Seclookup
Clean
securolytics
Clean
Sophos
Clean
Spam404
Clean
StopForumSpam
Clean
Sucuri SiteCheck
Clean
ThreatHive
Clean
URLhaus
Clean
Viettel Threat Intelligence
Clean
ViriBack
Clean
VX Vault
Clean
Webroot
Clean
Yandex Safebrowsing
Clean
ZeroCERT
Clean
0xSI_f33d
Unrated
alphaMountain.ai
Unrated
AlphaSOC
Unrated
ArcSight Threat Intelligence
Unrated
AutoShun
Unrated
Bfore.Ai PreCrime
Unrated
Bkav
Unrated
ChainPatrol
Unrated
Chong Lua Dao
Unrated
Cluster25
Unrated
CSIS Security Group
Unrated
Cyan
Unrated
Ermes
Unrated
Forcepoint ThreatSeeker
Unrated
GCP Abuse Intelligence
Unrated
GreyNoise
Unrated
Gridinsoft
Unrated
Guardpot
Unrated
Hunt.io Intelligence
Unrated
Kaspersky
Unrated
Lumu
Unrated
MalwareURL
Unrated
Mimecast
Unrated
Netcraft
Unrated
PhishFort
Unrated
PhishLabs
Unrated
PrecisionSec
Unrated
SafeToOpen
Unrated
Sansec eComscan
Unrated
Snort IP sample list
Unrated
SOCRadar
Unrated
URLQuery
Unrated
VIPRE
Unrated
Xcitium Verdict Cloud
Unrated
ZeroFox
Unrated

Op 12-4-2026 om 11:08 schreef Bruno Postle:
> I'm not sure it is a problem, it should be ok to create a 'fan' site
> like this, but the download link *is* suspicious. There is no reason not
> to link to the sourceforge download - Bruno
>
> On Sun, 12 Apr 2026, 09:58 Maarten Verberne wrote:
>
> well, i'm not sure this will help, but you could:
>
> Report abuse to the hosting provider with evidence (screenshots, links,
> malware).
> the domain is new, report it to the registrar (e.g., GoDaddy,
> Namecheap)
> for impersonation.
> Report the site to Google, Bing, etc., as a phishing/malware site via
> their Safe Browsing reporting tools.
> https://safebrowsing.google.com/report-phish/ <https://
> safebrowsing.google.com/report-phish/>
>
> if that's help i do not know, but it should at least give attention to
> this problem.
> Maarten
>
> Bruno
>
> --
> A list of frequently asked questions is available at: http://
> wiki.panotools.org/Hugin_FAQ <http://wiki.panotools.org/Hugin_FAQ>
> ---
> You received this message because you are subscribed to the Google
> Groups "hugin and other free panoramic software" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to hugin-ptx+...@googlegroups.com <mailto:hugin-
> ptx+uns...@googlegroups.com>.
> To view this discussion visit https://groups.google.com/d/msgid/hugin-
> ptx/

Frédéric Da Vitoria

unread,
Apr 12, 2026, 5:28:19 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
FWIW, the Windows download link does not seem to work, at least on Firefox. The Linux link leads to a page which gives more information, but the "Latest tarball" link again does not seem to work.

-- 
Frédéric Da Vitoria
--
A list of frequently asked questions is available at: http://wiki.panotools.org/Hugin_FAQ

---
You received this message because you are subscribed to the Google Groups "hugin and other free panoramic software" group.
To unsubscribe from this group and stop receiving emails from it, send an email to hugin-ptx+...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/hugin-ptx/CAJV99ZgtbmTCszjkuDSNcgbFK1g%2BdHmOcferNbWfORcZoPGLzw%40mail.gmail.com.

  

Sans virus.www.avast.com

Frédéric Da Vitoria

unread,
Apr 12, 2026, 5:36:12 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
Correction: I guess one of my privacy extensions was blocking something. It works on MS Edge. Almost, the links lead to Terabox, and I am supposed to login to download. I stop my tests here.
-- 
Frédéric Da Vitoria

Bruno Postle

unread,
Apr 12, 2026, 5:41:32 AM (5 days ago) Apr 12
to hugin and other free panoramic software
I fetched the MSI installer and it is the same file as the latest sourceforge version, so no immediate concern: 

f9dc9c1eca4bee02dc69ec9a1cd2c0524b371c3d downloads/Hugin-2025.0.1-win64.msi

It's still like to know who is responsible and ask them to link directly to the sourceforge download.

Bruno

On Sun, 12 Apr 2026, 10:28 Frédéric Da Vitoria wrote:
FWIW, the Windows download link does not seem to work, at least on Firefox. The Linux link leads to a page which gives more information, but the "Latest tarball" link again does not seem to work.

Marius Loots

unread,
Apr 12, 2026, 6:08:55 AM (5 days ago) Apr 12
to hugin and other free panoramic software
The terabox app seems to be some AI related thing:
TeraBox: Your Personal All-in-One AI Assistant with 1024GB of FREE Cloud Storage!

Couldn't find anything dodgy, for now? 

There's a lot of AI connected apps going around trying to corner some market or make a quick buck.

Groetnis
 Marius                         
 mailto:marius...@up.ac.za
BMedSci (Hons) UP, PGCHE (UP) HCM (FPD)

add some chaos to your life and put the world in order


This message and attachments are subject to a disclaimer.
Please refer to http://upnet.up.ac.za/services/it/documentation/docs/004167.pdf 
for full details.

wirz

unread,
Apr 12, 2026, 6:12:19 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
I compared the linux source folder with our repo and they are identical
(apart from being slightly outdated).

At the moment I assume the point of creating this website is that
terabox pays users for uploading files that are downloaded by many other
users, and in order to download anything from terabox one needs an
account with them. The user who uploaded the files to terabox is
registered as "Ol***r S" with them.

While the files themselves look fine at the moment--this may change--I
still consider this abuse.

lukas wirz
>> <https://groups.google.com/d/msgid/hugin-ptx/CAJV99ZgtbmTCszjkuDSNcgbFK1g%2BdHmOcferNbWfORcZoPGLzw%40mail.gmail.com?utm_medium=email&utm_source=footer>
>> .
>>
>>
>>
>> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient> Sans
>> virus.www.avast.com
>> <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient>
>> <#m_-5463185418033248712_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
>>
>> --
>> A list of frequently asked questions is available at:
>> http://wiki.panotools.org/Hugin_FAQ
>> ---
>> You received this message because you are subscribed to the Google Groups
>> "hugin and other free panoramic software" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to hugin-ptx+...@googlegroups.com.
>> To view this discussion visit
>> https://groups.google.com/d/msgid/hugin-ptx/a6d0f049-fcac-4aa8-8a2a-172c932f0ae1%40gmail.com
>> <https://groups.google.com/d/msgid/hugin-ptx/a6d0f049-fcac-4aa8-8a2a-172c932f0ae1%40gmail.com?utm_medium=email&utm_source=footer>
>> .
>>
>

Steve Wesemeyer

unread,
Apr 12, 2026, 6:20:26 AM (5 days ago) Apr 12
to hugi...@googlegroups.com

Whois just shows that it's someone in Phoenix who registered the domain a few days ago.

There are some contact details but they are pseudonymised.

https://www.whois.com/whois/huginpanorama.com

Googling the provided phone number turns up a few other instances in which alternative sites were created.

So this very much looks like a scam...

Cheers,

 Steve

Maarten Verberne

unread,
Apr 12, 2026, 7:21:35 AM (5 days ago) Apr 12
to hugi...@googlegroups.com
a true fan would have identified themselves by now, since you can't
contact the person i would assume that person is lurking in the dark for
a chance.
probably the link changes to malware when traffic is strong enough.
report to NameSilo for impersonation and sort out if it's a fan when
they contact you.
this can only be done effectively in the start up period, so better safe
than sorry i'd say.

Op 12-4-2026 om 12:17 schreef 'Steve Wesemeyer' via hugin and other free
panoramic software:

PanoSeek

unread,
Apr 12, 2026, 10:51:01 AM (5 days ago) Apr 12
to hugin and other free panoramic software
quick note - the registration is private, so the user may not be based in Phoenix....but that is the source of the private registration service.  
Reply all
Reply to author
Forward
0 new messages