site-1039294.mozfiles.com - URL scan, 13 Aug 2026
MalwareAnalyzer by Cyble scanned site-1039294.mozfiles.com and returned a unknown verdict (score -12). The page resolved to 65.8.180.81 on Amazon.com, Inc. in US. The domain was registered 4437 days ago through Key-Systems GmbH. 1 domain and 1 IP were contacted. 11 malware samples communicate with this URL. This is a point-in-time observation from 13 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://site-1039294.mozfiles.com/files/1039294/73179880935.pdf - Domain: site-1039294.mozfiles.com · IP: 65.8.180.81 · AS16509 · US
- Server: AmazonS3
- HTTP status: 404 · application/xml
- Registrar: Key-Systems GmbH · domain age 4437 days · created 2014-06-19
- TLS issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M01 · valid to Oct 18 23: · subject CN=*.mozfiles.com
- Scan tier: standard · observed 2026-08-13 10:21:06 UTC
Malware communicating with this URL (11)
These samples were observed contacting or being served from site-1039294.mozfiles.com. Each links to its full analysis.
- normal_5f87767def52a.pdf - referenced ·
192d7af595222ab30d4efe1a3f81eb3f· first seen 2026-08-13 - sakibugimakizej.pdf - referenced ·
570702b68b1e11ab48a27c227333effb· first seen 2026-08-13 - 2800097.pdf - referenced ·
d6e9d086e56ecaf53a23d6d27f443cd3· first seen 2026-08-13 - normal_5f8728cbeeb3c.pdf - referenced ·
09cbcf5b2aabad3d0b8ebc41a758e420· first seen 2026-08-12 - 6008746.pdf - referenced ·
7d6164f02e660718fdfb902d99265d7c· first seen 2026-08-12 - 4519161.pdf - referenced ·
9db03c05ff7fd2c2deea01dbf06c47f1· first seen 2026-08-12 - batul_funusasaxewa_xiteji_zapareleju.pdf - referenced ·
57e9ba248896e413287710a762fa3110· first seen 2026-08-12 - xowobali.pdf - referenced ·
c857f0cbe346c5d18ff6c5291811e7df· first seen 2026-08-12 - 3989030.pdf - referenced ·
89d877f58e040253d4b7bf6b31291ce0· first seen 2026-08-12 - 26161973738.pdf - referenced ·
8dcac69984b2cf8f02a9289107f5f36c· first seen 2026-08-12 - majigukugevefob_bojaligodus_nutuw.pdf - referenced ·
de47d86e0656a59c71a69b95bbcf917c· first seen 2026-08-12
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Amazon CloudFront
Contacted infrastructure
- 65.8.180.81 - AS16509 Amazon.com, Inc. (United States)
Observed indicators
- site-1039294.mozfiles.com
- 65.8.180.81
- https://site-1039294.mozfiles.com/files/1039294/73179880935.pdf
Other scans of site-1039294.mozfiles.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/zafisanut.pdf - 16 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/70369412522.pdf - 16 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/buxim.pdf - 15 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/ropof.pdf - 15 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/ropof.pdf - 14 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/70369412522.pdf - 14 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/gifukakalefupesanisetinal.pdf - 14 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/gifukakalefupesanisetinal.pdf - 13 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/gifukakalefupesanisetinal.pdf - 13 Aug 2026 - unknown ·
https://site-1039294.mozfiles.com/files/1039294/68496298157.pdf
Questions about site-1039294.mozfiles.com
- Is site-1039294.mozfiles.com safe?
- The scan of site-1039294.mozfiles.com on 13 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with site-1039294.mozfiles.com?
- 11 analysed samples communicate with this URL.
- How was site-1039294.mozfiles.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of site-1039294.mozfiles.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan