connect.facebook.net - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned connect.facebook.net and returned a unknown verdict (score 2). The page resolved to 157.240.15.13 on Facebook, Inc. in SG. 1 domain and 1 IP were contacted. 93 malware samples communicate with this URL (Obfus). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 2) · Confidence 8%
- Scanned URL:
https://connect.facebook.net/en_US/fbevents.js - Domain: connect.facebook.net · IP: 157.240.15.13 · AS32934 · SG
- HTTP status: 200 · application/x-javascript; charset=utf-8
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Aug 27 23: · subject C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com
- Evidenced operator: Meta Platforms, Inc.
- Scan tier: fast · observed 2026-08-19 19:33:56 UTC
Malware communicating with this URL (93)
These samples were observed contacting or being served from connect.facebook.net. Each links to its full analysis.
- Obfus - referenced ·
990dff7ba8267b11d35402e8acab13d6· first seen 2026-08-19 - 3c82da6cc4cc2feb20242656e6e0eda087b38ff6d2532ac7e0afe671969817c1 - referenced ·
3c82da6cc4cc2feb20242656e6e0eda0· first seen 2026-08-19 - 984772ded921b432769d1690bf3e0d80909da241f902ed5d9e2ee91038ce6d5a - referenced ·
984772ded921b432769d1690bf3e0d80· first seen 2026-08-19 - e342d1a5ca701c959295444750b46a8420bc0f617cf941e41485545d512dc052 - referenced ·
e342d1a5ca701c959295444750b46a84· first seen 2026-08-19 - ffe73f4359a037ecf75f93ba8b73971e116ac939d3cc64e484b44b8b8d53be1f - referenced ·
ffe73f4359a037ecf75f93ba8b73971e· first seen 2026-08-19 - virussign.com_a914e6ceabd08d83094d21f2ee432400.vir - referenced ·
cdd4a1addfc9100345c2bbf1dce8b834· first seen 2026-08-19 - 7c288b1214c057ec81f1b4d2f592add488049bcf23dfeb407e70aedc359b75fb - referenced ·
7c288b1214c057ec81f1b4d2f592add4· first seen 2026-08-19 - 6add2b4f8e0bad4c3bc186c63dd004bb44d1d5d84faa9ea1ebb4b2103c5dff37 - referenced ·
6add2b4f8e0bad4c3bc186c63dd004bb· first seen 2026-08-19 - 6ad87c8b9d3a75a65292a0c23e628dfdb0b25bd8c22905de37bee5055cd8770d - referenced ·
6ad87c8b9d3a75a65292a0c23e628dfd· first seen 2026-08-19 - 60a8a5d0242d70cfd70be8248d655934ba3a1ee9b2e2c4c492e64d5b6d83aa7b - referenced ·
60a8a5d0242d70cfd70be8248d655934· first seen 2026-08-19 - caf60a1de4f988a3d7bec90a2e8c0075d0a501d285154dd268fd1b4cbd4cadb7 - referenced ·
caf60a1de4f988a3d7bec90a2e8c0075· first seen 2026-08-17 - d27dd342cde9b0bf2733cc4161453b5011b10b262d86b03a8331b8c90ec40e77 - referenced ·
d27dd342cde9b0bf2733cc4161453b50· first seen 2026-08-17 - 6ad3c90a7486d34b88fc80f912bcadde049ccf7c440072051b50e5214292de59 - referenced ·
6ad3c90a7486d34b88fc80f912bcadde· first seen 2026-08-17 - 266d130c395ff3a97e979971f85e65048802a43388ffc9c1bd597cbb9b6c3f72 - referenced ·
266d130c395ff3a97e979971f85e6504· first seen 2026-08-17 - 6ad6adbc2e1a6e47bf8aaab1f2e0be8a07266e28c3a901ce5bb99fa330ee0f6a - referenced ·
6ad6adbc2e1a6e47bf8aaab1f2e0be8a· first seen 2026-08-17
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- File download routed to the malware sandbox (fbevents.js)
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 157.240.15.13 - AS32934 Facebook, Inc. (Singapore)
Files served by this page
- fbevents.js ·
5d8d4bb1186f740b55e9d632b68acc0b
Observed indicators
- connect.facebook.net
- 157.240.15.13
- https://connect.facebook.net/en_US/fbevents.js
Other scans of connect.facebook.net (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://www.soratemplates.com/ - 24 Aug 2026 - unknown ·
https://manhremhoangvan.com/wp-content/uploads/files/zezumemesodetoros.pdf - 24 Aug 2026 - suspicious ·
https://manhremhoangvan.com/wp-content/uploads/files/zezumemesodetoros.pdf - 24 Aug 2026 - unknown ·
https://www.kiteschule-eckernfoerde.de/wp-content/plugins/formcraft/file-upload/server/content/files - 24 Aug 2026 - unknown ·
http://phimhddd.blogspot.com/search/label/M%C3%83%C2%83%C3%82%C2%83%C3%83%C2%82%C3%82%C2%83%C3%83%C2 - 24 Aug 2026 - unknown ·
http://istana-sepeda.blogspot.com/2012/04/fork-rst-first-platinum-travel-100.html - 24 Aug 2026 - unknown ·
https://alompar.hu/uploads/content_files/files/41377062345.pdf - 24 Aug 2026 - unknown ·
https://alompar.hu/uploads/content_files/files/41377062345.pdf - 24 Aug 2026 - unknown ·
http://selintasdunia.blogspot.com/2011/02/10-isi-kepala-perempuan-yang-perlu.html - 24 Aug 2026 - unknown ·
https://loca-granderoue-montaletang.com/ckfinder/userfiles/files/77399895396.pdf
Questions about connect.facebook.net
- Is connect.facebook.net safe?
- The scan of connect.facebook.net on 19 Aug 2026 reached no verdict either way (score 2). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with connect.facebook.net?
- 93 analysed samples communicate with this URL, including Obfus.
- How was connect.facebook.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of connect.facebook.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan