html5shim.googlecode.com - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned html5shim.googlecode.com and returned a suspicious verdict (score 31), categorised as phishing. The page resolved to 74.125.24.82 on Google LLC in SG. The domain was registered 7837 days ago through MarkMonitor Inc.. 1 domain and 1 IP were contacted. 8 malware samples communicate with this URL (Fromcharcode, Coinminer). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 31) · Confidence 37%
- Scanned URL:
http://html5shim.googlecode.com/svn/trunk/html5.js - Domain: html5shim.googlecode.com · IP: 74.125.24.82 · AS15169 · SG
- Page title: Error 404 (Not Found)!!1
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: MarkMonitor Inc. · domain age 7837 days · created 2005-03-09
- Scan tier: fast · observed 2026-08-23 06:27:30 UTC
Malware communicating with this URL (8)
These samples were observed contacting or being served from html5shim.googlecode.com. Each links to its full analysis.
- Fromcharcode - referenced ·
12ec07adae3a921b1d5b3579019bb34e· first seen 2026-08-23 - d323891d1fb8884fe9f02488f96d7267aef35bd2872ae764b438a9bfd32a7329 - referenced ·
d323891d1fb8884fe9f02488f96d7267· first seen 2026-08-22 - 8d43f46054f9b1dc357918d84d13eed94d09726e63154d0d5e054ee2d39631c6 - referenced ·
8d43f46054f9b1dc357918d84d13eed9· first seen 2026-08-21 - Coinminer - referenced ·
257d36184d5745398fb026d060de4531· first seen 2026-08-19 - 6ad582ed79bcdac21eb4ef346b37a25e5bea34fdbf58d9c49a2cca6718e56640 - referenced ·
6ad582ed79bcdac21eb4ef346b37a25e· first seen 2026-08-17 - 8d02a9a7a9b9efe0895ddbaf363903f642ca8eaa6489744cf46ff26d5de7cf85 - referenced ·
8d02a9a7a9b9efe0895ddbaf363903f6· first seen 2026-08-15 - eb77b160696fc529a48697476dbe4f1a53feeb5dfd491179bcf6b9baf626984c - referenced ·
eb77b160696fc529a48697476dbe4f1a· first seen 2026-08-14 - 50264756b385609ebb4516d20023528a7b0cc59f71845df7e2f47f7c072f765c - referenced ·
50264756b385609ebb4516d20023528a· first seen 2026-08-14
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Domain impersonates google (combosquat)
- Served over plaintext HTTP
Contacted infrastructure
- 74.125.24.82 - AS15169 Google LLC (Singapore)
Observed indicators
- html5shim.googlecode.com
- 74.125.24.82
- http://html5shim.googlecode.com/svn/trunk/html5.js
Other scans of html5shim.googlecode.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/16138e09be0f83- - 23 Aug 2026 - unknown ·
https://codes-sources.commentcamarche.net/so - 23 Aug 2026 - suspicious ·
https://status.forticlient.forticloud.com/ - 23 Aug 2026 - unknown ·
https://www.everhouse.lt/wp-content/plugins/formcraft/file-upload/server/content/files/1608499a34c2f - 23 Aug 2026 - unknown ·
http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/16084e6fe1bbb5- - 22 Aug 2026 - unknown ·
http://aliancegroup.su/wp-content/plugins/formcraft/file-upload/server/content/files/1615b19b26991a- - 22 Aug 2026 - unknown ·
https://mousike.it/img_ins/files/21424705859.pdf - 22 Aug 2026 - unknown ·
https://www.d-table.com/wp-content/plugins/super-forms/uploads/php/files/37d00fcd026813d95c9371da640 - 22 Aug 2026 - malicious ·
https://status.forticlient.forticloud.com/ - 22 Aug 2026 - malicious ·
https://9ecbthiemiechaseiqui.iifgurnx.ggziosky.wccheck-4123a9a2-b.members.gospelfortheleast.duckdns.
Questions about html5shim.googlecode.com
- Is html5shim.googlecode.com safe?
- No. MalwareAnalyzer scanned html5shim.googlecode.com on 23 Aug 2026 and returned a suspicious verdict with a score of 31 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with html5shim.googlecode.com?
- 8 analysed samples communicate with this URL, including Fromcharcode, Coinminer.
- How was html5shim.googlecode.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of html5shim.googlecode.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan