widgets.amung.us - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned widgets.amung.us and returned a suspicious verdict (score 45). The page resolved to 104.20.41.165 on Cloudflare, Inc. in US. 3 domains and 1 IP were contacted. 46 malware samples communicate with this URL. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 45) · Confidence 54%
- Scanned URL:
http://widgets.amung.us/classic.js - Domain: widgets.amung.us · IP: 104.20.41.165 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/x-javascript
- Scan tier: fast · observed 2026-08-21 20:13:33 UTC
Malware communicating with this URL (46)
These samples were observed contacting or being served from widgets.amung.us. Each links to its full analysis.
- e7f588037861e52d4c1fc30ea4891a58b08d8a45a2ba8d302cbd3ca45266c68c - referenced ·
e7f588037861e52d4c1fc30ea4891a58· first seen 2026-08-21 - 3f76b6dcb28c2d15abc29de9cff0bdf0629bbfae3e61608216406ed3b657d17a - referenced ·
3f76b6dcb28c2d15abc29de9cff0bdf0· first seen 2026-08-21 - ea208e3fcc39e350c2f42b64164eba51c9228b37703b208dff90adf77c5e3e77 - referenced ·
ea208e3fcc39e350c2f42b64164eba51· first seen 2026-08-21 - fe7a3e94053ec35d01f79a0ec9abea0056b95a84f3730fc7912cde5ad90a4427 - referenced ·
fe7a3e94053ec35d01f79a0ec9abea00· first seen 2026-08-21 - 3234fe9827e963b9e48f97f2d78aeecf1103e8b45ddb2298e0f81e08c0ff39db - referenced ·
3234fe9827e963b9e48f97f2d78aeecf· first seen 2026-08-21 - 6b291a07958ccaefb0cb22910ca70f2120491a777386511858d24691dca72107 - referenced ·
6b291a07958ccaefb0cb22910ca70f21· first seen 2026-08-21 - df0eeb407fe5fbb2047fd9b936cde6df31600be25056dff3dcf07d3ba3ad7d7e - referenced ·
df0eeb407fe5fbb2047fd9b936cde6df· first seen 2026-08-21 - df05cdb875c8c739f4790ded50c1a5a9c6f775bdd704471f725e21582e38c4d3 - referenced ·
df05cdb875c8c739f4790ded50c1a5a9· first seen 2026-08-21 - df05cd3736dd18eb19d506b05d8290e05aa4ee725c0457830f55c6cac87919f9 - referenced ·
df05cd3736dd18eb19d506b05d8290e0· first seen 2026-08-21 - df053d4348143ccf30f9befff240c15a17be8fef855c5146726550917bd5fb44 - referenced ·
df053d4348143ccf30f9befff240c15a· first seen 2026-08-21 - e0da1271a9e432b1e26f41a5df95ac1a0dc3a4b6bbbe0fbbddf43f974976487f - referenced ·
e0da1271a9e432b1e26f41a5df95ac1a· first seen 2026-08-21 - 7f4c9279e62a5de10979a4f660f1dc7148cd47139a15b104bd911e8227d1d2bf - referenced ·
7f4c9279e62a5de10979a4f660f1dc71· first seen 2026-08-20 - 27c3c4e40b0472c7633c3c261bc01176a57fc3a5ca28cc417d1e955e6b5e39c6 - referenced ·
27c3c4e40b0472c7633c3c261bc01176· first seen 2026-08-20 - 7127907ce31aa75d8cfc81181ec46fb3d78036addde8025b959158979182f1f7 - referenced ·
7127907ce31aa75d8cfc81181ec46fb3· first seen 2026-08-20 - bd56432d8c49039f839455a8545e50c253bdccdde73ee8ecc10307716de32eca - referenced ·
bd56432d8c49039f839455a8545e50c2· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (classic.js) is known suspicious in the corpus
- File download routed to the malware sandbox (classic.js)
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.20.41.165 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- classic.js ·
f9ccdaa68ad30b653358a8e0f980095c
Observed indicators
- widgets.amung.us
- whos.amung.us
- t.dtscout.com
- 104.20.41.165
- http://widgets.amung.us/classic.js
- http://whos.amung.us/pingjs/?k=
- https://t.dtscout.com/i/?l=
Other scans of widgets.amung.us (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
http://jotamaria-cearense.blogspot.com/search - 24 Aug 2026 - unknown ·
http://fullpornolariizle.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-alecrim.blogspot.com/2012/10/blog-post.html - 23 Aug 2026 - suspicious ·
http://widgets.amung.us/colored.js - 23 Aug 2026 - unknown ·
http://jotamaria-ccdeassu.blogspot.com/search - 23 Aug 2026 - unknown ·
http://jotamaria-bmmossoro.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/ - 23 Aug 2026 - unknown ·
http://jotamaria-ceara.blogspot.com/2014/06/ex-governadores-do-ceara.html - 23 Aug 2026 - suspicious ·
http://widgets.amung.us/colored.js - 23 Aug 2026 - unknown ·
http://health-healng.blogspot.com/2014/11/blog-post_16.html
Questions about widgets.amung.us
- Is widgets.amung.us safe?
- No. MalwareAnalyzer scanned widgets.amung.us on 21 Aug 2026 and returned a suspicious verdict with a score of 45 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with widgets.amung.us?
- 46 analysed samples communicate with this URL.
- How was widgets.amung.us checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of widgets.amung.us
Scanned on MalwareAnalyzer by Cyble · Open interactive scan