widgets.amung.us - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned widgets.amung.us and returned a suspicious verdict (score 45). The page resolved to 104.20.41.165 on Cloudflare, Inc. in US. 3 domains and 1 IP were contacted. 27 malware samples communicate with this URL. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 45) · Confidence 54%
- Scanned URL:
http://widgets.amung.us/colored.js - Domain: widgets.amung.us · IP: 104.20.41.165 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/x-javascript
- Scan tier: fast · observed 2026-08-19 22:23:19 UTC
Malware communicating with this URL (27)
These samples were observed contacting or being served from widgets.amung.us. Each links to its full analysis.
- 4235e231232c0707fc91c26792765a7e74749af5ddc0bb7e1ee18ef552bcf525 - referenced ·
4235e231232c0707fc91c26792765a7e· first seen 2026-08-19 - 1b1763d494eaee6600fb1f5d3e0648886c97cfc6fd1db02acee45fea0b8317aa - referenced ·
1b1763d494eaee6600fb1f5d3e064888· first seen 2026-08-19 - 4671b296be3a5fb8970fb42bfaf903f5436d54a528eebd11b995c977be0d3875 - referenced ·
4671b296be3a5fb8970fb42bfaf903f5· first seen 2026-08-19 - colored.js - referenced ·
9410fb33ac9af2d2c9105c55870f64fa· first seen 2026-08-19 - 6e986864e3816effc5ab16204054bee217da86c89fafcf77bca4deeeb4642c48 - referenced ·
6e986864e3816effc5ab16204054bee2· first seen 2026-08-19 - 24aed64698adc85db6d4838030811eaa20f6ad20721cde88add1b462ce35734b - referenced ·
24aed64698adc85db6d4838030811eaa· first seen 2026-08-17 - 6ad65bcc3eedec33cfb96bcb67114fcb25c2d982e8f0f7872a390f4c2c7616cd - referenced ·
6ad65bcc3eedec33cfb96bcb67114fcb· first seen 2026-08-17 - 6ad6adbc2e1a6e47bf8aaab1f2e0be8a07266e28c3a901ce5bb99fa330ee0f6a - referenced ·
6ad6adbc2e1a6e47bf8aaab1f2e0be8a· first seen 2026-08-17 - 11b720edf0766eab7626ca6804b3b2ab325f409128258adea68813d596e98992 - referenced ·
11b720edf0766eab7626ca6804b3b2ab· first seen 2026-08-16 - 3b41b6effad27604d275485f119b011af0c7f286164a90dba65210e9ef6d62ab - referenced ·
3b41b6effad27604d275485f119b011a· first seen 2026-08-16 - c3e6d3f192d7491b04ed60c428b5efaea684f1ede8d31bdd54714783cad96fcd - referenced ·
c3e6d3f192d7491b04ed60c428b5efae· first seen 2026-08-16 - 11ba7aef120b9edc2b40484073f99e9baf34511221bb704d580059a5abf94c7b - referenced ·
11ba7aef120b9edc2b40484073f99e9b· first seen 2026-08-16 - 11b3fa21c17510300571f67a9285fb6a9b48fe3f628b8affbb932d55db98400e - referenced ·
11b3fa21c17510300571f67a9285fb6a· first seen 2026-08-16 - 11b84f2268a79401d1587336aefd89dda050f4bbb8d951752febfb8ca5566319 - referenced ·
11b84f2268a79401d1587336aefd89dd· first seen 2026-08-16 - 67f749c94b8d056ce94e5bf43b60e856fb18d5a3eeae9095c7aa66c0b0c2d0d1 - referenced ·
67f749c94b8d056ce94e5bf43b60e856· first seen 2026-08-16
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (colored.js) is known suspicious in the corpus
- File download routed to the malware sandbox (colored.js)
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.20.41.165 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- colored.js ·
9410fb33ac9af2d2c9105c55870f64fa
Observed indicators
- widgets.amung.us
- whos.amung.us
- t.dtscout.com
- 104.20.41.165
- http://widgets.amung.us/colored.js
- http://whos.amung.us/pingjs/?k=
- http://widgets.amung.us/colwid/?c=
- https://t.dtscout.com/i/?l=
Other scans of widgets.amung.us (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://jotamaria-cearense.blogspot.com/search - 24 Aug 2026 - unknown ·
http://fullpornolariizle.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-alecrim.blogspot.com/2012/10/blog-post.html - 23 Aug 2026 - suspicious
- 23 Aug 2026 - unknown ·
http://jotamaria-ccdeassu.blogspot.com/search - 23 Aug 2026 - unknown ·
http://jotamaria-bmmossoro.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/2014/06/ex-governadores-do-ceara.html - 23 Aug 2026 - suspicious
- 23 Aug 2026 - unknown ·
http://health-healng.blogspot.com/2014/11/blog-post_16.html
Questions about widgets.amung.us
- Is widgets.amung.us safe?
- No. MalwareAnalyzer scanned widgets.amung.us on 19 Aug 2026 and returned a suspicious verdict with a score of 45 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with widgets.amung.us?
- 27 analysed samples communicate with this URL.
- How was widgets.amung.us checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of widgets.amung.us
Scanned on MalwareAnalyzer by Cyble · Open interactive scan