widgets.amung.us - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned widgets.amung.us and returned a suspicious verdict (score 45). The page resolved to 172.66.172.247 on Cloudflare, Inc. in US. 3 domains and 1 IP were contacted. 71 malware samples communicate with this URL. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 45) · Confidence 54%
- Scanned URL:
http://widgets.amung.us/colored.js - Domain: widgets.amung.us · IP: 172.66.172.247 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/x-javascript
- Scan tier: fast · observed 2026-08-23 23:48:37 UTC
Malware communicating with this URL (71)
These samples were observed contacting or being served from widgets.amung.us. Each links to its full analysis.
- 7778fa2721c05f2e4d668d27f0dc8b65a3df0f88f9fb8dfebf03664c808b438e - referenced ·
7778fa2721c05f2e4d668d27f0dc8b65· first seen 2026-08-23 - 2e08d12a894532a8541d3daf16657da40c4715c5a8fc15d754056edca6663dbc - referenced ·
2e08d12a894532a8541d3daf16657da4· first seen 2026-08-23 - 4e2bbf3f2471596a1ff50a136a9a936350d87c0cae02e1ffbc5b36ed542e2b28 - referenced ·
4e2bbf3f2471596a1ff50a136a9a9363· first seen 2026-08-23 - fe9797cb40538c075b0059c1f5a690b9c678cd6466d5beb8e4f6a665c4271f3d - referenced ·
fe9797cb40538c075b0059c1f5a690b9· first seen 2026-08-23 - 4bf8253dcefbb1684389ea961a0f9c7ef280f9c916f16137b1002489a7e40ddf - referenced ·
4bf8253dcefbb1684389ea961a0f9c7e· first seen 2026-08-23 - fe9d8f0f3c5797d6af84b5fc48c422505f71ba1531e5023a2e0a41070d6e7103 - referenced ·
fe9d8f0f3c5797d6af84b5fc48c42250· first seen 2026-08-23 - fe92860ba9256d8e148560631bb5f7c9d6af53f2dcf619af5ff99186baa9d504 - referenced ·
fe92860ba9256d8e148560631bb5f7c9· first seen 2026-08-23 - 4b1e8d031aa6f64441b6adb117c7f0d41f250f639f408629e7ff0b2ee4977647 - referenced ·
4b1e8d031aa6f64441b6adb117c7f0d4· first seen 2026-08-23 - 1ed8bb7b5d0f377f478a6da25724876729c7e29b369f84ebbe902bf897f47679 - referenced ·
1ed8bb7b5d0f377f478a6da257248767· first seen 2026-08-23 - 5bc72043084f7baf95528ae4fa891e25ca673d8cd5203042d7ac8202bd6c26c6 - referenced ·
5bc72043084f7baf95528ae4fa891e25· first seen 2026-08-23 - f0e0bc4c27081af20d24dfb61ebf4090ed08cef2e69cccd02db704dfa6ffbc2e - referenced ·
f0e0bc4c27081af20d24dfb61ebf4090· first seen 2026-08-23 - ae2a1944e9901a82404efb660c06cfd43f4ab6c64a44814ad5054a148c9b5ba0 - referenced ·
ae2a1944e9901a82404efb660c06cfd4· first seen 2026-08-23 - f822ca6bcee72933778bb4582a2e3f5ff2c3bc60dae5a1eb0febd8238490ad05 - referenced ·
f822ca6bcee72933778bb4582a2e3f5f· first seen 2026-08-22 - 983ba845db0c03fb41504863ea6f0f54757decbebbca4d6609ec3c000b1e94d4 - referenced ·
983ba845db0c03fb41504863ea6f0f54· first seen 2026-08-22 - f820775db706e77c809941c3b724679358783bbdd618654648baaaa1a0c6b1e4 - referenced ·
f820775db706e77c809941c3b7246793· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (colored.js) is known suspicious in the corpus
- File download routed to the malware sandbox (colored.js)
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.66.172.247 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- colored.js ·
9410fb33ac9af2d2c9105c55870f64fa
Observed indicators
- widgets.amung.us
- whos.amung.us
- t.dtscout.com
- 172.66.172.247
- http://widgets.amung.us/colored.js
- http://whos.amung.us/pingjs/?k=
- http://widgets.amung.us/colwid/?c=
- https://t.dtscout.com/i/?l=
Other scans of widgets.amung.us (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://fullpornolariizle.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-alecrim.blogspot.com/2012/10/blog-post.html - 23 Aug 2026 - unknown ·
http://jotamaria-ccdeassu.blogspot.com/search - 23 Aug 2026 - unknown ·
http://jotamaria-bmmossoro.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/2014/06/ex-governadores-do-ceara.html - 23 Aug 2026 - suspicious
- 23 Aug 2026 - unknown ·
http://health-healng.blogspot.com/2014/11/blog-post_16.html - 23 Aug 2026 - unknown ·
http://health-healng.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-academiadeodontologia.blogspot.com/2011/11/36-jose-nunes-cabral-de-carvalho.html
Questions about widgets.amung.us
- Is widgets.amung.us safe?
- No. MalwareAnalyzer scanned widgets.amung.us on 23 Aug 2026 and returned a suspicious verdict with a score of 45 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with widgets.amung.us?
- 71 analysed samples communicate with this URL.
- How was widgets.amung.us checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of widgets.amung.us
Scanned on MalwareAnalyzer by Cyble · Open interactive scan