h.name - URL scan, 13 Aug 2026
MalwareAnalyzer by Cyble scanned h.name and returned a unknown verdict (score 0). 1 domain and 0 IPs were contacted. 13 malware samples communicate with this URL (Brocoiner). This is a point-in-time observation from 13 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 3%
- Scanned URL:
https://h.name/ - Domain: h.name
- Scan tier: fast · observed 2026-08-13 15:15:24 UTC
Malware communicating with this URL (13)
These samples were observed contacting or being served from h.name. Each links to its full analysis.
- 3432011497-widgets.js - referenced ·
645849c850c103e72d0365d4ead1d3fb· first seen 2026-08-13 - 3766621756-lbx__pt_br.js - referenced ·
e5823aed4ddaed520ef63a3ab556cae7· first seen 2026-08-12 - 3903731066-lbx__pt_br.js - referenced ·
f7e2bc3ee0d4f9ae4d1267999a73f2e2· first seen 2026-08-12 - 0337bd78c3020279e99046c4b32f85fa84e0a6991c5fcacb6a39a56ced7c690f - referenced ·
0337bd78c3020279e99046c4b32f85fa· first seen 2026-08-13 - 2028442393-lbx__pt_br.js - referenced ·
d99d1b9d9e7ba7705e74cb4c3c1ef382· first seen 2026-08-13 - 5a735ce69b448a32f1aa63f86c0e9ef8078f61b74fd0d73fdbdce637935d7dd0 - referenced ·
5a735ce69b448a32f1aa63f86c0e9ef8· first seen 2026-08-13 - 4142632578-lbx__pt_br.js - referenced ·
78184f664658e232bcc5a34df70420a8· first seen 2026-08-12 - 74a08ff8a64c5573a1f6e5884d9b6c90cd5db5a830d04833c026e2a39fba9f77 - referenced ·
74a08ff8a64c5573a1f6e5884d9b6c90· first seen 2026-08-12 - b13518cd2f7fa6eb751c99a877b11899cb32f5992c7c14344333c5174841ff73 - referenced ·
b13518cd2f7fa6eb751c99a877b11899· first seen 2026-08-12 - c70b0da999a78c95c52a603284e86cab39dc8d78d8dd83c3fc057d5011566f2e - referenced ·
c70b0da999a78c95c52a603284e86cab· first seen 2026-08-12 - 5ebc875512530cd47daa8279d5d5bbfb43a6aff374f12162fb3cdd858504f0bf - referenced ·
5ebc875512530cd47daa8279d5d5bbfb· first seen 2026-08-11 - 5f6f867b239d6b7a2e15f15d26ff51376474b294bda9fa67ae8dd503b6657f2c - referenced ·
5f6f867b239d6b7a2e15f15d26ff5137· first seen 2026-08-11 - Brocoiner - referenced ·
66265f3a8fa4ef98de98874eb986fbed· first seen 2026-08-11
Why this verdict
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- h.name
- https://h.name/
Other scans of h.name (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - unknown
- 15 Aug 2026 - unknown
Questions about h.name
- Is h.name safe?
- The scan of h.name on 13 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with h.name?
- 13 analysed samples communicate with this URL, including Brocoiner.
- How was h.name checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of h.name
Scanned on MalwareAnalyzer by Cyble · Open interactive scan