site-1039693.mozfiles.com - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned site-1039693.mozfiles.com and returned a unknown verdict (score -12). The page resolved to 65.8.180.12 on Amazon.com, Inc. in US. The domain was registered 4443 days ago through Key-Systems GmbH. 1 domain and 1 IP were contacted. 21 malware samples communicate with this URL. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://site-1039693.mozfiles.com/files/1039693/13709142262.pdf - Domain: site-1039693.mozfiles.com · IP: 65.8.180.12 · AS16509 · US
- Server: AmazonS3
- HTTP status: 404 · application/xml
- Registrar: Key-Systems GmbH · domain age 4443 days · created 2014-06-19
- TLS issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M01 · valid to Oct 18 23: · subject CN=*.mozfiles.com
- Scan tier: standard · observed 2026-08-19 10:44:15 UTC
Malware communicating with this URL (21)
These samples were observed contacting or being served from site-1039693.mozfiles.com. Each links to its full analysis.
- normal_5f87c4ac8a594.pdf - referenced ·
a1f0df2d0a21d93d3a00d0192d3ab9e1· first seen 2026-08-16 - normal_5f872f9ea99c4.pdf - referenced ·
44607b0ca6b27c29496464bf650a6acf· first seen 2026-08-16 - fewefolagivovajaborapid.pdf - referenced ·
2cf66004fc226c76c1de1945b305f415· first seen 2026-08-15 - gujeg.pdf - referenced ·
31d680a3d776d08935de692c89f29337· first seen 2026-08-15 - 250d194c.pdf - referenced ·
361f1dc37e1acbf5bd96cf4f226ef5ef· first seen 2026-08-15 - 6371123.pdf - referenced ·
d38c96b2f7dbe63a6974a195a7919f36· first seen 2026-08-12 - 69cda82938.pdf - referenced ·
a7bb98541a8b560d547d28145c2d4e36· first seen 2026-08-13 - f4461a2fe20a040.pdf - referenced ·
4592939e4ae2706a4a64c22f0e3a7020· first seen 2026-08-14 - fbbc8e9c.pdf - referenced ·
835e938c261a70925b21bd8eb7fcce16· first seen 2026-08-13 - bozuwifisoritiziju.pdf - referenced ·
02a88f77db2d125eeced3cd91ef1584b· first seen 2026-08-14 - julirovisepimeli.pdf - referenced ·
1a907f5ee7f7714c80ee930db1ee91b2· first seen 2026-08-13 - b1b612.pdf - referenced ·
46db01bc86d681899f9351bb1eb13d8b· first seen 2026-08-13 - digefig.pdf - referenced ·
e8403e51def511a8f3d6d12aaf7eaf49· first seen 2026-08-13 - kesoxitowosur.pdf - referenced ·
e6281f0b77a0e0e601be05be0edf77e2· first seen 2026-08-13 - nijeponot_mejaradew_dexalovati.pdf - referenced ·
50487e16468fb0b15841f951c8ed923c· first seen 2026-08-13
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Amazon CloudFront
Contacted infrastructure
- 65.8.180.12 - AS16509 Amazon.com, Inc. (United States)
Observed indicators
- site-1039693.mozfiles.com
- 65.8.180.12
- https://site-1039693.mozfiles.com/files/1039693/13709142262.pdf
Other scans of site-1039693.mozfiles.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://site-1039693.mozfiles.com/files/1039693/ninefoz.pdf - 19 Aug 2026 - unknown ·
https://site-1039693.mozfiles.com/files/1039693/ninefoz.pdf - 19 Aug 2026 - unknown ·
https://site-1039693.mozfiles.com/files/1039693/remudegupojoledatosa.pdf - 19 Aug 2026 - unknown
- 16 Aug 2026 - unknown ·
https://site-1039693.mozfiles.com/files/1039693/tofurogitowijifex.pdf - 16 Aug 2026 - unknown ·
https://site-1039693.mozfiles.com/files/1039693/detelosej.pdf - 16 Aug 2026 - unknown ·
https://site-1039693.mozfiles.com/files/1039693/detelosej.pdf - 14 Aug 2026 - unknown
- 14 Aug 2026 - unknown
- 14 Aug 2026 - unknown
Questions about site-1039693.mozfiles.com
- Is site-1039693.mozfiles.com safe?
- The scan of site-1039693.mozfiles.com on 19 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with site-1039693.mozfiles.com?
- 21 analysed samples communicate with this URL.
- How was site-1039693.mozfiles.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of site-1039693.mozfiles.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan