player.vimeo.com - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned player.vimeo.com and returned a suspicious verdict (score 27). The page resolved to 162.159.128.61 on Cloudflare, Inc. in US. The domain was registered 7917 days ago through MarkMonitor Inc.. 1 domain and 1 IP were contacted. 19 malware samples communicate with this URL (Maldoc, Gootloader). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 27) · Confidence 36%
- Scanned URL:
https://player.vimeo.com/api/player.js - Domain: player.vimeo.com · IP: 162.159.128.61 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/javascript;charset=utf-8
- Registrar: MarkMonitor Inc. · domain age 7917 days · created 2004-12-15
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Oct 4 13: · subject CN=vimeo.com
- Scan tier: fast · observed 2026-08-19 22:58:14 UTC
Malware communicating with this URL (19)
These samples were observed contacting or being served from player.vimeo.com. Each links to its full analysis.
- 43bb3e10b43659a0d45331d299e564b02e6ba9d97c6b60811a1052504562bfe6 - referenced ·
43bb3e10b43659a0d45331d299e564b0· first seen 2026-08-19 - Maldoc - referenced ·
2d1ec17083ea606da07bf3a9ec8b23e2· first seen 2026-08-19 - 904ba9cedd81e5b19dec43b57661f80cd50fc8f8581c17b2454dc5d7ce59932d - referenced ·
904ba9cedd81e5b19dec43b57661f80c· first seen 2026-08-19 - fe47c899d05a1f5bafd6f9432e67c58fb6091399d6387b70a0fcb541895896b4 - referenced ·
fe47c899d05a1f5bafd6f9432e67c58f· first seen 2026-08-19 - Gootloader - referenced ·
f1cbe5f24bb5373e39fa3abb363f16cf· first seen 2026-08-19 - 26bdfef1eb14e1cf9759db00a65a1844542d3d2387e89eb52d7898fb5d72744b - referenced ·
26bdfef1eb14e1cf9759db00a65a1844· first seen 2026-08-16 - 6ee6fc892de79953ab678b447151f27578fed64fb77f618c1dc6dcd611c08b11 - referenced ·
6ee6fc892de79953ab678b447151f275· first seen 2026-08-16 - froogaloop2.min.js - referenced ·
f0a7e38d3da10f50c1f5f4ed4e50d920· first seen 2026-08-16 - 68e42b78678bd68a1b09387bc0347aeaaa9899539c2c4c91080d29467eb62fa4 - referenced ·
68e42b78678bd68a1b09387bc0347aea· first seen 2026-08-16 - 2fdfbdc3767a5c79731d3a5a89e0b4903040d31bb71659453cd74d8241cffc4f - referenced ·
2fdfbdc3767a5c79731d3a5a89e0b490· first seen 2026-08-16 - 6ac3ce57086282eb62630e06168c93fda0d043e1dbe974e8fcadb949a0709c8f - referenced ·
6ac3ce57086282eb62630e06168c93fd· first seen 2026-08-16 - 11ba9e6c2091a692ffc734431fc130be39b3103c60eaa07c0548bab50de11687 - referenced ·
11ba9e6c2091a692ffc734431fc130be· first seen 2026-08-16 - da4b31ce51bdfcb864659c6c45eeb1a9e76f875191b29e05b32f623fbd5a7f02 - referenced ·
da4b31ce51bdfcb864659c6c45eeb1a9· first seen 2026-08-15 - f96015543a8000c00cdee75ab4ba334b270eaf0e5093e68bdc2fbd0d05fc41ac - referenced ·
f96015543a8000c00cdee75ab4ba334b· first seen 2026-08-14 - 521a940c7302b8ce2b5a55bd7beb3e2583c073b5b101453a4d34c39d88197220 - referenced ·
521a940c7302b8ce2b5a55bd7beb3e25· first seen 2026-08-14
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (player.js) is known suspicious in the corpus
- File download routed to the malware sandbox (player.js)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
- Fastly
Contacted infrastructure
- 162.159.128.61 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- player.js ·
718e1ff73387fc5fd0455ca05339e322
Observed indicators
- player.vimeo.com
- 162.159.128.61
- https://player.vimeo.com/api/player.js
Other scans of player.vimeo.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://case.edu/ - 23 Aug 2026 - unknown ·
http://ventensis.lt/public/ckfinder/userfiles/files/53821040745.pdf - 23 Aug 2026 - suspicious ·
https://case.edu/ - 23 Aug 2026 - unknown ·
https://vimeo.com/features - 23 Aug 2026 - unknown ·
https://vimeo.com/ - 23 Aug 2026 - unknown ·
https://danielfelber.ch/userfiles/file/wimifovodozazoliv.pdf - 23 Aug 2026 - unknown ·
https://danielfelber.ch/userfiles/file/wimifovodozazoliv.pdf - 23 Aug 2026 - malicious ·
https://chaseregrets.com/ - 23 Aug 2026 - suspicious ·
https://case.edu/ - 23 Aug 2026 - unknown ·
https://vimeo.com/features
Questions about player.vimeo.com
- Is player.vimeo.com safe?
- No. MalwareAnalyzer scanned player.vimeo.com on 19 Aug 2026 and returned a suspicious verdict with a score of 27 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with player.vimeo.com?
- 19 analysed samples communicate with this URL, including Maldoc, Gootloader.
- How was player.vimeo.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of player.vimeo.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan