www.blogger.com - suspicious URL scan, 14 Aug 2026
MalwareAnalyzer by Cyble scanned www.blogger.com and returned a suspicious verdict (score 28). The page resolved to 142.250.183.41 on Google LLC in IN. The domain was registered 9914 days ago through MarkMonitor Inc.. 4 domains and 1 IP were contacted. 95 malware samples communicate with this URL (Formbook, Autolike). This is a point-in-time observation from 14 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://www.blogger.com/feeds/6861249084893505952/posts/default - Domain: www.blogger.com · IP: 142.250.183.41 · AS15169 · IN
- Server: blogger-renderd
- Page title: Pinguinalité
- HTTP status: 200 · application/atom+xml; charset=UTF-8
- Registrar: MarkMonitor Inc. · domain age 9914 days · created 1999-06-22
- TLS issuer: C=US, O=Google Trust Services, CN=WR2 · valid to Oct 12 18: · subject CN=*.blogger.com
- Scan tier: fast · observed 2026-08-14 16:41:18 UTC
Malware communicating with this URL (95)
These samples were observed contacting or being served from www.blogger.com. Each links to its full analysis.
- Formbook - referenced ·
5029f6b798db0f286b466533bb100535· first seen 2026-08-14 - 502dbd9dd39156c61ed89a554b78ed57c42a9e97aac3fa7d013d4abdac960029 - referenced ·
502dbd9dd39156c61ed89a554b78ed57· first seen 2026-08-14 - 502fed293876707fee98db2e8a4c1c9cc5663aec731bc96c05c4f2306896861d - referenced ·
502fed293876707fee98db2e8a4c1c9c· first seen 2026-08-14 - 50203ecaf2ea9d34caf5bc07679ffe61578c6db373d4842aa0e970352a3fb09c - referenced ·
50203ecaf2ea9d34caf5bc07679ffe61· first seen 2026-08-14 - Autolike - referenced ·
50280127b129a9118c7f1b1f06db1bfa· first seen 2026-08-14 - d94029fa276eed6771df315ece2992b148728406442afce9b9a0d8b472842fd1 - referenced ·
d94029fa276eed6771df315ece2992b1· first seen 2026-08-14 - a23ddec978c2659a47bb84a62358dd550789a3194349a059c7e40e8b79ba67f8 - referenced ·
a23ddec978c2659a47bb84a62358dd55· first seen 2026-08-14 - e44ddf67bd3303bfc92f7eb5c7970cd96ce9ec8c3f9294ff6822bed060441eae - referenced ·
e44ddf67bd3303bfc92f7eb5c7970cd9· first seen 2026-08-14 - 50260b26b7c6eb0c14fc8ef16b2c85c33831674e2009c01687519af5d36b6398 - referenced ·
50260b26b7c6eb0c14fc8ef16b2c85c3· first seen 2026-08-14 - 50264756b385609ebb4516d20023528a7b0cc59f71845df7e2f47f7c072f765c - referenced ·
50264756b385609ebb4516d20023528a· first seen 2026-08-14 - 2600cebc020ae61486a4149a9fb2217d7ec11efb8175951d2aa80622c77af742 - referenced ·
2600cebc020ae61486a4149a9fb2217d· first seen 2026-08-14 - 80e115ee59fd112ff5f381786d9a5e69cf7b2cb89db675c1f8ba9da8cee889cd - referenced ·
80e115ee59fd112ff5f381786d9a5e69· first seen 2026-08-14 - 80e6105d0ef3448f34308e591a4a4dfe770212c04174d90ffcfe590b03189b70 - referenced ·
80e6105d0ef3448f34308e591a4a4dfe· first seen 2026-08-14 - 0b0c61804cc4a1789f87c3ba9ee56092b6d501ad7f2e9e0228f7d4d8f3789bda - referenced ·
0b0c61804cc4a1789f87c3ba9ee56092· first seen 2026-08-14 - 80e75e309c56dcdf76d7400fa40680b88c30ae86a32b6d0372bbb2a580999b19 - referenced ·
80e75e309c56dcdf76d7400fa40680b8· first seen 2026-08-14
Antivirus & YARA (1 of 44 engines)
- YARA: ReversingLabs [yara]: RL_Formbook_XLoader (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: RL_Formbook_XLoader
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 142.250.183.41 - AS15169 Google LLC (India)
Observed indicators
- www.blogger.com
- pinguin-alite.blogspot.com
- pubsubhubbub.appspot.com
- img1.blogblog.com
- 142.250.183.41
- https://www.blogger.com/feeds/6861249084893505952/posts/default
- http://www.blogger.com/styles/atom.css
- https://pinguin-alite.blogspot.com/feeds/posts/default
- https://pinguin-alite.blogspot.com/
- http://pubsubhubbub.appspot.com/
- https://www.blogger.com/feeds/6861249084893505952/posts/default?start-index=26&max-results=25
- https://img1.blogblog.com/img/b16-rounded.gif
- https://pinguin-alite.blogspot.com/feeds/1067803103922436337/comments/default
- https://pinguin-alite.blogspot.com/2026/07/julien-jimenez-comment-faire-evoluer.html#comment-form
- https://www.blogger.com/feeds/6861249084893505952/posts/default/1067803103922436337
- https://pinguin-alite.blogspot.com/2026/07/julien-jimenez-comment-faire-evoluer.html
- https://pinguin-alite.blogspot.com/feeds/3693036288206611388/comments/default
- https://pinguin-alite.blogspot.com/2026/02/rencontre-troubles-anxieux-comment.html#comment-form
- https://www.blogger.com/feeds/6861249084893505952/posts/default/3693036288206611388
- https://pinguin-alite.blogspot.com/2026/02/rencontre-troubles-anxieux-comment.html
Other scans of www.blogger.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://www.blogger.com/static/v1/jsbin/1957234192-lbx__pt_br.js - 24 Aug 2026 - unknown ·
http://istana-sepeda.blogspot.com/feeds/posts/default - 24 Aug 2026 - unknown ·
http://istana-sepeda.blogspot.com/2012/04/fork-rst-first-platinum-travel-100.html - 24 Aug 2026 - unknown ·
http://agamakejawen.blogspot.com/feeds/posts/default?alt=rss - 24 Aug 2026 - unknown ·
http://agamakejawen.blogspot.com/feeds/posts/default - 24 Aug 2026 - unknown ·
http://agamakejawen.blogspot.com/2010/07/wejangan-dewa-ruci-cerita-dalam_9537.html - 24 Aug 2026 - unknown ·
http://agamakejawen.blogspot.com/favicon.ico - 24 Aug 2026 - unknown ·
http://jotamaria-centraloeste.blogspot.com/search - 24 Aug 2026 - unknown ·
http://jotamaria-centraloeste.blogspot.com/ - 24 Aug 2026 - unknown ·
http://jotamaria-centraloeste.blogspot.com/2010/08/capitao-aderlan-bezeraa-de-araujo.html
Questions about www.blogger.com
- Is www.blogger.com safe?
- No. MalwareAnalyzer scanned www.blogger.com on 14 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.blogger.com?
- 95 analysed samples communicate with this URL, including Formbook, Autolike.
- How was www.blogger.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.blogger.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan