h.me - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned h.me and returned a unknown verdict (score -12). The page resolved to 159.89.90.207 on DigitalOcean, LLC in US. 11 domains and 1 IP were contacted, over 4 HTTP requests. 5 malware samples communicate with this URL. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://h.me/ - Domain: h.me · IP: 159.89.90.207 · AS14061 · US
- Server: Caddy
- Page title: Need ideas? Try our free AI for name inspiration.
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Sep 26 23: · subject CN=h.me
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-19 11:46:01 UTC
Malware communicating with this URL (5)
These samples were observed contacting or being served from h.me. Each links to its full analysis.
- moxa-uport-1200-1400-1600-series-windows-7-10-windows-server-2008-r2-2019-whql-certified-driver-v3.2.exe - referenced ·
8e826841b93a60e12f85a660515cc209· first seen 2026-08-19 - 129205357-lbx__pt_br.js - referenced ·
7957d117a68d99b69544472996d943f9· first seen 2026-08-15 - 3618766451-lbx__en_gb.js - referenced ·
88b4eee071a3e2d8836be1b02ec5b3e1· first seen 2026-08-14 - 1957234192-lbx__pt_br.js - referenced ·
3fd4edfa4121016e4536c4c49e1bd813· first seen 2026-08-14 - 3766621756-lbx__pt_br.js - referenced ·
e5823aed4ddaed520ef63a3ab556cae7· first seen 2026-08-12
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Caddy
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 159.89.90.207 - AS14061 DigitalOcean, LLC (United States)
Observed indicators
- h.me
- cdn.jsdelivr.net
- ajax.googleapis.com
- www.googletagmanager.com
- domain.me
- www.facebook.com
- www.youtube.com
- www.instagram.com
- www.linkedin.com
- www.tiktok.com
- twitter.com
- 159.89.90.207
- https://h.me/
- https://h.me/images/DotMe-32x32.png
- https://h.me/images/DotMe-192x192.png
- https://h.me/images/DotMe-180x180.png
- https://h.me/css/style.css
- https://h.me/css/namegenie.css
- https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/css/bootstrap.min.css
- https://ajax.googleapis.com/ajax/libs/jquery/3.7.1/jquery.min.js
Questions about h.me
- Is h.me safe?
- The scan of h.me on 19 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with h.me?
- 5 analysed samples communicate with this URL.
- How was h.me checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of h.me
Scanned on MalwareAnalyzer by Cyble · Open interactive scan