www.avira.com - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.avira.com and returned a unknown verdict (score 16), categorised as credential-harvest. The page resolved to 23.33.238.193 on Akamai Technologies, Inc. in AU. 23 domains and 2 IPs were contacted, over 12 HTTP requests. 27 malware samples communicate with this URL (Fileinfector, HUILoader, Cryptinject, REvil). The request followed 2 redirects before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 16) · Confidence 22%
- Scanned URL:
http://www.freeav.com/ - Domain: www.avira.com · IP: 23.33.238.193 · AS20940 · AU
- Server: akamai
- Page title: Download Security Software for Windows, Mac, Android & iOS | Avira Antivirus
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 12
- Scan tier: fast · observed 2026-08-20 00:17:24 UTC
Redirect chain
http://www.freeav.com/https://www.freeav.com/https://www.avira.com/
Malware communicating with this URL (27)
These samples were observed contacting or being served from www.avira.com. Each links to its full analysis.
- Fileinfector - contacted ·
2df3ebb8e7d913a246ed63b231ce1857· first seen 2026-08-20 - Fileinfector - referenced ·
a37449ba597f6047de087c4c1067fb98· first seen 2026-08-18 - 7fb0a5e3b348d6f1eb7733c1a3eb24e339b5946aa192db4af7f12b76153fbecf - referenced ·
7fb0a5e3b348d6f1eb7733c1a3eb24e3· first seen 2026-08-17 - Fileinfector - referenced ·
33dacf68bf4f4479d7c1694670a879e4· first seen 2026-08-17 - HUILoader - referenced ·
b59355d6bf9b5bff38e8d3b5027e2a9e· first seen 2026-08-17 - 4cadf7261bae027d53184cb6e6e292c8b342b1097659ed14b95d803c0c4b9140 - referenced ·
4cadf7261bae027d53184cb6e6e292c8· first seen 2026-08-16 - Fileinfector - referenced ·
c676430497b78ec6c58e6e1bc19e5fb0· first seen 2026-08-16 - Cryptinject - referenced ·
2712e3dc51599d4da4e2815e2b8d75a9· first seen 2026-08-15 - Fileinfector - referenced ·
96b1b0b2b58388545a873089511a1416· first seen 2026-08-15 - REvil - referenced ·
09f57082a2d904244c9e03847ec0ab57· first seen 2026-08-15 - 1acbdcaafbc09c71c6984bd6691c32db892415d643fb119b1db6019d088e97ea - referenced ·
1acbdcaafbc09c71c6984bd6691c32db· first seen 2026-08-15 - Fileinfector - referenced ·
04afe5194c380b4a4f958bc5e1775b4c· first seen 2026-08-15 - 49b61da7cf239f73d6a96976a4b0dc3d05f022c8006f9ace3a31c691280e1c46 - referenced ·
49b61da7cf239f73d6a96976a4b0dc3d· first seen 2026-08-15 - f4f71fdf8025f496310afcbb043535808884d1050f5b17fe373ae4b2580a0ec1 - referenced ·
f4f71fdf8025f496310afcbb04353580· first seen 2026-08-15 - Fileinfector - referenced ·
ba39ef382d52ef46602a53f66cdc9132· first seen 2026-08-14
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Cross-host redirect chain
Detected technologies
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 23.33.238.193 - AS20940 Akamai Technologies, Inc. (Australia)
- 52.58.28.12 - AS16509 A100 ROW GmbH (Germany)
Observed indicators
- www.avira.com
- nexus.ensighten.com
- assets.adobedtm.com
- www.webassetscdn.com
- script.crazyegg.com
- www.googletagmanager.com
- www.google-analytics.com
- www.microsoft.com
- support.avira.com
- my.avira.com
- www.trustpilot.com
- e-shop.avira.com
- play.google.com
- itunes.apple.com
- assets.prod.cms.avira.com
- www.youtube-nocookie.com
- google.com
- sitedirector.avira.com
- newsroom.gendigital.com
- oem.avira.com
Other scans of www.avira.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://www.avira.com/en/avira-antivirus-security-upsell - 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
Questions about www.avira.com
- Is www.avira.com safe?
- The scan of www.avira.com on 20 Aug 2026 reached no verdict either way (score 16). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.avira.com?
- 27 analysed samples communicate with this URL, including Fileinfector, HUILoader, Cryptinject, REvil.
- How was www.avira.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.avira.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan