widgets.amung.us - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned widgets.amung.us and returned a suspicious verdict (score 45). The page resolved to 172.66.172.247 on Cloudflare, Inc. in US. 3 domains and 1 IP were contacted. 63 malware samples communicate with this URL. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 45) · Confidence 54%
- Scanned URL:
http://widgets.amung.us/colored.js - Domain: widgets.amung.us · IP: 172.66.172.247 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/x-javascript
- Scan tier: fast · observed 2026-08-23 15:33:41 UTC
Malware communicating with this URL (63)
These samples were observed contacting or being served from widgets.amung.us. Each links to its full analysis.
- 1ed8bb7b5d0f377f478a6da25724876729c7e29b369f84ebbe902bf897f47679 - referenced ·
1ed8bb7b5d0f377f478a6da257248767· first seen 2026-08-23 - 5bc72043084f7baf95528ae4fa891e25ca673d8cd5203042d7ac8202bd6c26c6 - referenced ·
5bc72043084f7baf95528ae4fa891e25· first seen 2026-08-23 - f0e0bc4c27081af20d24dfb61ebf4090ed08cef2e69cccd02db704dfa6ffbc2e - referenced ·
f0e0bc4c27081af20d24dfb61ebf4090· first seen 2026-08-23 - ae2a1944e9901a82404efb660c06cfd43f4ab6c64a44814ad5054a148c9b5ba0 - referenced ·
ae2a1944e9901a82404efb660c06cfd4· first seen 2026-08-23 - f822ca6bcee72933778bb4582a2e3f5ff2c3bc60dae5a1eb0febd8238490ad05 - referenced ·
f822ca6bcee72933778bb4582a2e3f5f· first seen 2026-08-22 - 983ba845db0c03fb41504863ea6f0f54757decbebbca4d6609ec3c000b1e94d4 - referenced ·
983ba845db0c03fb41504863ea6f0f54· first seen 2026-08-22 - f820775db706e77c809941c3b724679358783bbdd618654648baaaa1a0c6b1e4 - referenced ·
f820775db706e77c809941c3b7246793· first seen 2026-08-22 - 225d99f9142a18f15dd0fe54fb2f3855e14b2450a3e08b8d462002ee8c502810 - referenced ·
225d99f9142a18f15dd0fe54fb2f3855· first seen 2026-08-22 - 22598a5e1c1d90013a94117c2e0cdb8ae5692579834fffbdf0b521887d7b0a0f - referenced ·
22598a5e1c1d90013a94117c2e0cdb8a· first seen 2026-08-22 - f9953adad9df1f7ff6b1b603ca05bde7f0e6708bb8494521f8479980423c1c33 - referenced ·
f9953adad9df1f7ff6b1b603ca05bde7· first seen 2026-08-22 - a6d622955c2bab36867a9fd7ba0928d62a26e436b1c5155f186b64cc7e9459da - referenced ·
a6d622955c2bab36867a9fd7ba0928d6· first seen 2026-08-22 - 5a32552292040fdc6472ddd169f9f63c1059c2ec6f4df37fe523ae596a11ef03 - referenced ·
5a32552292040fdc6472ddd169f9f63c· first seen 2026-08-22 - d3285421298a58d3884d35927618706720926578f9d481d6834ed57208ecd1fd - referenced ·
d3285421298a58d3884d359276187067· first seen 2026-08-22 - 3f7508ed6be9e89f851b84a55dc2e62f034d79f72e5a846a84628fc37028d792 - referenced ·
3f7508ed6be9e89f851b84a55dc2e62f· first seen 2026-08-22 - 94344a7ea5b0839462e19af1d2f28ec4b96472cf76d4a202a0c9aab54f0d2299 - referenced ·
94344a7ea5b0839462e19af1d2f28ec4· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (colored.js) is known suspicious in the corpus
- File download routed to the malware sandbox (colored.js)
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.66.172.247 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- colored.js ·
9410fb33ac9af2d2c9105c55870f64fa
Observed indicators
- widgets.amung.us
- whos.amung.us
- t.dtscout.com
- 172.66.172.247
- http://widgets.amung.us/colored.js
- http://whos.amung.us/pingjs/?k=
- http://widgets.amung.us/colwid/?c=
- https://t.dtscout.com/i/?l=
Other scans of widgets.amung.us (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://phimhddd.blogspot.com/search/label/M%C3%83%C2%83%C3%82%C2%83%C3%83%C2%82%C3%82%C2%83%C3%83%C2 - 24 Aug 2026 - unknown ·
http://jotamaria-cearense.blogspot.com/search - 24 Aug 2026 - unknown ·
http://fullpornolariizle.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-alecrim.blogspot.com/2012/10/blog-post.html - 23 Aug 2026 - suspicious
- 23 Aug 2026 - unknown ·
http://jotamaria-ccdeassu.blogspot.com/search - 23 Aug 2026 - unknown ·
http://jotamaria-bmmossoro.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/2014/06/ex-governadores-do-ceara.html - 23 Aug 2026 - unknown ·
http://health-healng.blogspot.com/2014/11/blog-post_16.html
Questions about widgets.amung.us
- Is widgets.amung.us safe?
- No. MalwareAnalyzer scanned widgets.amung.us on 23 Aug 2026 and returned a suspicious verdict with a score of 45 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with widgets.amung.us?
- 63 analysed samples communicate with this URL.
- How was widgets.amung.us checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of widgets.amung.us
Scanned on MalwareAnalyzer by Cyble · Open interactive scan