atomic.store - URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned atomic.store and returned a unknown verdict (score -12). The page resolved to 23.227.38.65 on Shopify, Inc. in CA. 4 domains and 1 IP were contacted, over 50 HTTP requests. 2 malware samples communicate with this URL (HUILoader, Rozena). This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://atomic.store/ - Domain: atomic.store · IP: 23.227.38.65 · AS13335 · CA
- Server: cloudflare
- Page title: ATOMIC.Store | Official ATOMIC Merchandise
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE2 · valid to Oct 18 17: · subject CN=atomic.store
- HTTP requests captured: 50
- Scan tier: fast · observed 2026-08-17 04:29:32 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from atomic.store. Each links to its full analysis.
- HUILoader - referenced ·
4b7d75f5c35d8d326af5723fb77c44d7· first seen 2026-08-17 - Rozena - referenced ·
b83e92827a774505824298a442c6d9d7· first seen 2026-08-16
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
- Shopify
Contacted infrastructure
- 23.227.38.65 - AS13335 Shopify, Inc. (Canada)
Observed indicators
- atomic.store
- shop.app
- cdn.shopify.com
- monorail-edge.shopifysvc.com
- 23.227.38.65
- https://atomic.store/
- https://atomic.store/cdn/shop/files/ATOMIC-Favicon.jpg?crop=center&height=32&v=1779230551&width=32
- https://atomic.store/cdn/shop/t/1/assets/overflow-list.css?v=16727044177065489451778597193
- https://atomic.store/cdn/shop/t/1/assets/base.css?v=110558660533795380521778597193
- https://atomic.store/cdn/fonts/inter/inter_n4.b2a3f24c19b4de56e8871f609e73ca7f6d2e2bb9.woff2
- https://atomic.store/cdn/fonts/inter/inter_n5.d7101d5e168594dd06f56f290dd759fba5431d97.woff2
- https://atomic.store/cdn/fonts/oswald/oswald_n4.7760ed7a63e536050f64bb0607ff70ce07a480bd.woff2
- https://atomic.store/cdn/fonts/inter/inter_n7.02711e6b374660cfc7915d1afc1c204e633421e4.woff2
- https://atomic.store/cdn/shopifycloud/importmap-polyfill/es-modules-shim.2.4.0.js
- https://atomic.store/cdn/shop/t/1/assets/view-transitions.js?v=7106414069516106341778597193
- https://atomic.store/cdn/shop/t/1/assets/utilities.js?v=28506172887375975941778597193
- https://atomic.store/cdn/shop/t/1/assets/component.js?v=184240237101443119871778597193
- https://atomic.store/cdn/shop/t/1/assets/section-renderer.js?v=123311117485513785771778597193
- https://atomic.store/cdn/shop/t/1/assets/section-hydration.js?v=108434990705342316311778597193
- https://atomic.store/cdn/shop/t/1/assets/morph.js?v=104045809772310330131778597193
Other scans of atomic.store (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 16 Aug 2026 - unknown
Questions about atomic.store
- Is atomic.store safe?
- The scan of atomic.store on 17 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with atomic.store?
- 2 analysed samples communicate with this URL, including HUILoader, Rozena.
- How was atomic.store checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of atomic.store
Scanned on MalwareAnalyzer by Cyble · Open interactive scan