connect.facebook.net - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned connect.facebook.net and returned a unknown verdict (score 2). The page resolved to 157.240.8.23 on Facebook, Inc. in AU. 1 domain and 1 IP were contacted. 131 malware samples communicate with this URL (DCOM, Fileinfector). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 2) · Confidence 8%
- Scanned URL:
https://connect.facebook.net/en_US/all.js - Domain: connect.facebook.net · IP: 157.240.8.23 · AS32934 · AU
- HTTP status: 200 · application/x-javascript; charset=utf-8
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Aug 27 23: · subject C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com
- Evidenced operator: Meta Platforms, Inc.
- Scan tier: fast · observed 2026-08-21 01:17:20 UTC
Malware communicating with this URL (131)
These samples were observed contacting or being served from connect.facebook.net. Each links to its full analysis.
- e0d94f55cd28a11f4a0ec27537b291a1f87f98a8cf5a6e1d509e13850a41acc9 - referenced ·
e0d94f55cd28a11f4a0ec27537b291a1· first seen 2026-08-21 - 1e24682882eebdf2ff70792a875675869145c82fa6490296f3954e72009b9808 - referenced ·
1e24682882eebdf2ff70792a87567586· first seen 2026-08-21 - e0da1271a9e432b1e26f41a5df95ac1a0dc3a4b6bbbe0fbbddf43f974976487f - referenced ·
e0da1271a9e432b1e26f41a5df95ac1a· first seen 2026-08-21 - 2de99b563224ba7482bae750f72534199a666cdbf3d5967cc7dbe3ec5a886cca - referenced ·
2de99b563224ba7482bae750f7253419· first seen 2026-08-21 - DCOM - contacted ·
7d18fff7b88f96be68f4862a87ab6991· first seen 2026-08-20 - dccdb8fff9af16095967d9df83c2bb27e784f44f9863e94d5e40fc6d1030ab49 - referenced ·
dccdb8fff9af16095967d9df83c2bb27· first seen 2026-08-20 - Fileinfector - contacted ·
a120bb56775bd34337709b59a91c7a28· first seen 2026-08-20 - fa1a7bae8f976d92c78e190c98b5bc1b0375cc79bcd25c3ccabcea4baa1d7232 - referenced ·
fa1a7bae8f976d92c78e190c98b5bc1b· first seen 2026-08-20 - 8553371fa39c8529660192fe165d8fb73e58c3701ab09fe5e051a293b05c7cb3 - referenced ·
8553371fa39c8529660192fe165d8fb7· first seen 2026-08-20 - dcc655189ea41cb28c4b34b607d7cb3da6021eef6303edafbe7e6d78773cee74 - referenced ·
dcc655189ea41cb28c4b34b607d7cb3d· first seen 2026-08-20 - dcc1053dd00b1bb7f1ee495afa28a6f588a527b93c0500f12c7e5e1df39a285b - referenced ·
dcc1053dd00b1bb7f1ee495afa28a6f5· first seen 2026-08-20 - 82022d85bdd245a5c1b9c0c9600f4332d51ef13ede049baf4641ace36f5cdea5 - referenced ·
82022d85bdd245a5c1b9c0c9600f4332· first seen 2026-08-20 - Fileinfector - contacted ·
8be1f1d3f59476f6988d0a84cbf727ea· first seen 2026-08-20 - dcc900c8d8966d92a7c259d5994b90288ed07b5f6003643aa1ee99fe7225a02a - referenced ·
dcc900c8d8966d92a7c259d5994b9028· first seen 2026-08-20 - 81d599c5d699ada441c86a0a1751dcdb4f30f397ac329ae78ea0319fac20970c - referenced ·
81d599c5d699ada441c86a0a1751dcdb· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- File download routed to the malware sandbox (all.js)
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 157.240.8.23 - AS32934 Facebook, Inc. (Australia)
Files served by this page
- all.js ·
354c1307445d7e869b448db5d6003c23
Observed indicators
- connect.facebook.net
- 157.240.8.23
- https://connect.facebook.net/en_US/all.js
Other scans of connect.facebook.net (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://loca-granderoue-montaletang.com/ckfinder/userfiles/files/77399895396.pdf - 23 Aug 2026 - unknown ·
http://himeaime.blogspot.com/2015/01/jodha-akbar-episode-312.html - 23 Aug 2026 - unknown ·
http://ifconfig.me/ - 23 Aug 2026 - suspicious ·
http://www.medical-psychology.gr/wp-content/plugins/formcraft/file-upload/server/content/files/16088 - 23 Aug 2026 - suspicious ·
http://fnon-el3rb.blogspot.com/2011/08/blog-post_4668.html - 23 Aug 2026 - unknown ·
http://pandancoco.blogspot.com/2015/02/scop-281.html - 23 Aug 2026 - suspicious ·
https://grawerlik.pl/userfiles/file/90347870053.pdf - 23 Aug 2026 - malicious ·
http://letras-hiphop.blogspot.com/2014/04/changes-2pac-traducida-al-espanol.html - 23 Aug 2026 - unknown ·
https://steampower.com/ - 23 Aug 2026 - suspicious ·
https://www.applehillspharmacy.com/
Questions about connect.facebook.net
- Is connect.facebook.net safe?
- The scan of connect.facebook.net on 21 Aug 2026 reached no verdict either way (score 2). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with connect.facebook.net?
- 131 analysed samples communicate with this URL, including DCOM, Fileinfector.
- How was connect.facebook.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of connect.facebook.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan