widgets.amung.us - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned widgets.amung.us and returned a suspicious verdict (score 45). The page resolved to 172.66.172.247 on Cloudflare, Inc. in US. 3 domains and 1 IP were contacted. 58 malware samples communicate with this URL. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 45) · Confidence 54%
- Scanned URL:
http://widgets.amung.us/classic.js - Domain: widgets.amung.us · IP: 172.66.172.247 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/x-javascript
- Scan tier: fast · observed 2026-08-22 22:53:12 UTC
Malware communicating with this URL (58)
These samples were observed contacting or being served from widgets.amung.us. Each links to its full analysis.
- 983ba845db0c03fb41504863ea6f0f54757decbebbca4d6609ec3c000b1e94d4 - referenced ·
983ba845db0c03fb41504863ea6f0f54· first seen 2026-08-22 - f820775db706e77c809941c3b724679358783bbdd618654648baaaa1a0c6b1e4 - referenced ·
f820775db706e77c809941c3b7246793· first seen 2026-08-22 - 225d99f9142a18f15dd0fe54fb2f3855e14b2450a3e08b8d462002ee8c502810 - referenced ·
225d99f9142a18f15dd0fe54fb2f3855· first seen 2026-08-22 - 22598a5e1c1d90013a94117c2e0cdb8ae5692579834fffbdf0b521887d7b0a0f - referenced ·
22598a5e1c1d90013a94117c2e0cdb8a· first seen 2026-08-22 - f9953adad9df1f7ff6b1b603ca05bde7f0e6708bb8494521f8479980423c1c33 - referenced ·
f9953adad9df1f7ff6b1b603ca05bde7· first seen 2026-08-22 - a6d622955c2bab36867a9fd7ba0928d62a26e436b1c5155f186b64cc7e9459da - referenced ·
a6d622955c2bab36867a9fd7ba0928d6· first seen 2026-08-22 - 5a32552292040fdc6472ddd169f9f63c1059c2ec6f4df37fe523ae596a11ef03 - referenced ·
5a32552292040fdc6472ddd169f9f63c· first seen 2026-08-22 - d3285421298a58d3884d35927618706720926578f9d481d6834ed57208ecd1fd - referenced ·
d3285421298a58d3884d359276187067· first seen 2026-08-22 - 3f7508ed6be9e89f851b84a55dc2e62f034d79f72e5a846a84628fc37028d792 - referenced ·
3f7508ed6be9e89f851b84a55dc2e62f· first seen 2026-08-22 - 94344a7ea5b0839462e19af1d2f28ec4b96472cf76d4a202a0c9aab54f0d2299 - referenced ·
94344a7ea5b0839462e19af1d2f28ec4· first seen 2026-08-22 - 3f70ac3b4bdb4fd8b75c5e8c6361f6e63360bf2473703e004ed43a450a42ce91 - referenced ·
3f70ac3b4bdb4fd8b75c5e8c6361f6e6· first seen 2026-08-22 - 3f7e70ef30d0f961888eaefda415bd82a2889a5af6a807f457a6a3d3ead67422 - referenced ·
3f7e70ef30d0f961888eaefda415bd82· first seen 2026-08-21 - e7f588037861e52d4c1fc30ea4891a58b08d8a45a2ba8d302cbd3ca45266c68c - referenced ·
e7f588037861e52d4c1fc30ea4891a58· first seen 2026-08-21 - 3f76b6dcb28c2d15abc29de9cff0bdf0629bbfae3e61608216406ed3b657d17a - referenced ·
3f76b6dcb28c2d15abc29de9cff0bdf0· first seen 2026-08-21 - ea208e3fcc39e350c2f42b64164eba51c9228b37703b208dff90adf77c5e3e77 - referenced ·
ea208e3fcc39e350c2f42b64164eba51· first seen 2026-08-21
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (classic.js) is known suspicious in the corpus
- File download routed to the malware sandbox (classic.js)
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.66.172.247 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- classic.js ·
f9ccdaa68ad30b653358a8e0f980095c
Observed indicators
- widgets.amung.us
- whos.amung.us
- t.dtscout.com
- 172.66.172.247
- http://widgets.amung.us/classic.js
- http://whos.amung.us/pingjs/?k=
- https://t.dtscout.com/i/?l=
Other scans of widgets.amung.us (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://jotamaria-cearense.blogspot.com/search - 24 Aug 2026 - unknown ·
http://fullpornolariizle.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-alecrim.blogspot.com/2012/10/blog-post.html - 23 Aug 2026 - suspicious ·
http://widgets.amung.us/colored.js - 23 Aug 2026 - unknown ·
http://jotamaria-ccdeassu.blogspot.com/search - 23 Aug 2026 - unknown ·
http://jotamaria-bmmossoro.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/2014/06/ex-governadores-do-ceara.html - 23 Aug 2026 - suspicious ·
http://widgets.amung.us/colored.js - 23 Aug 2026 - unknown ·
http://health-healng.blogspot.com/2014/11/blog-post_16.html
Questions about widgets.amung.us
- Is widgets.amung.us safe?
- No. MalwareAnalyzer scanned widgets.amung.us on 22 Aug 2026 and returned a suspicious verdict with a score of 45 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with widgets.amung.us?
- 58 analysed samples communicate with this URL.
- How was widgets.amung.us checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of widgets.amung.us
Scanned on MalwareAnalyzer by Cyble · Open interactive scan