www.facebook.com - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.facebook.com and returned a benign verdict (score 0), categorised as credential-harvest. The page resolved to 157.240.13.35 on Facebook, Inc. in SG. 7 domains and 2 IPs were contacted. 115 malware samples communicate with this URL (HUILoader, DCOM, Fileinfector). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 12%
- Scanned URL:
https://connect.facebook.net/ - Domain: www.facebook.com · IP: 157.240.13.35 · AS32934 · SG
- Page title: Facebook
- HTTP status: 200 · text/html; charset="utf-8"
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Aug 27 23: · subject C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com
- Evidenced operator: Meta Platforms, Inc.
- Scan tier: fast · observed 2026-08-21 05:42:20 UTC
Redirect chain
https://connect.facebook.net/https://www.facebook.com/
Malware communicating with this URL (115)
These samples were observed contacting or being served from www.facebook.com. Each links to its full analysis.
- c3fc4d5eb2f53469d3ba4c898ba668bc11bb12789419869b05367ed2ca621861 - referenced ·
c3fc4d5eb2f53469d3ba4c898ba668bc· first seen 2026-08-21 - f8d39a52146691c5be469b7db560043754541cd0e37e971bf6b3c8f47bd3df59 - referenced ·
f8d39a52146691c5be469b7db5600437· first seen 2026-08-21 - df05cd3736dd18eb19d506b05d8290e05aa4ee725c0457830f55c6cac87919f9 - referenced ·
df05cd3736dd18eb19d506b05d8290e0· first seen 2026-08-21 - df09af1faee3a5b5d585ce268dab72265e0ea36df6f95343e3e0153f5ec755e3 - referenced ·
df09af1faee3a5b5d585ce268dab7226· first seen 2026-08-21 - HUILoader - contacted ·
1dad207c4d8680b8b165e299757ebf58· first seen 2026-08-21 - 1e24682882eebdf2ff70792a875675869145c82fa6490296f3954e72009b9808 - referenced ·
1e24682882eebdf2ff70792a87567586· first seen 2026-08-21 - 2de99b563224ba7482bae750f72534199a666cdbf3d5967cc7dbe3ec5a886cca - referenced ·
2de99b563224ba7482bae750f7253419· first seen 2026-08-21 - DCOM - contacted ·
7d18fff7b88f96be68f4862a87ab6991· first seen 2026-08-20 - dccdb8fff9af16095967d9df83c2bb27e784f44f9863e94d5e40fc6d1030ab49 - referenced ·
dccdb8fff9af16095967d9df83c2bb27· first seen 2026-08-20 - Fileinfector - contacted ·
a120bb56775bd34337709b59a91c7a28· first seen 2026-08-20 - fa1a7bae8f976d92c78e190c98b5bc1b0375cc79bcd25c3ccabcea4baa1d7232 - referenced ·
fa1a7bae8f976d92c78e190c98b5bc1b· first seen 2026-08-20 - 8553371fa39c8529660192fe165d8fb73e58c3701ab09fe5e051a293b05c7cb3 - referenced ·
8553371fa39c8529660192fe165d8fb7· first seen 2026-08-20 - dcc655189ea41cb28c4b34b607d7cb3da6021eef6303edafbe7e6d78773cee74 - referenced ·
dcc655189ea41cb28c4b34b607d7cb3d· first seen 2026-08-20 - dcc1053dd00b1bb7f1ee495afa28a6f588a527b93c0500f12c7e5e1df39a285b - referenced ·
dcc1053dd00b1bb7f1ee495afa28a6f5· first seen 2026-08-20 - 82022d85bdd245a5c1b9c0c9600f4332d51ef13ede049baf4641ace36f5cdea5 - referenced ·
82022d85bdd245a5c1b9c0c9600f4332· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 157.240.13.35 - AS32934 Facebook, Inc. (Singapore)
- 157.240.8.23 - AS32934 Facebook, Inc. (Australia)
Observed indicators
- www.facebook.com
- static.xx.fbcdn.net
- en-gb.facebook.com
- scontent.xx.fbcdn.net
- video.xx.fbcdn.net
- l.facebook.com
- developers.facebook.com
- 157.240.13.35
- 157.240.8.23
- https://www.facebook.com/
- https://static.xx.fbcdn.net/rsrc.php/y1/r/ay1hV6OlegS.ico
- https://en-gb.facebook.com/
- https://scontent.xx.fbcdn.net/
- https://video.xx.fbcdn.net/
- https://static.xx.fbcdn.net/rsrc.php/v5/yj/l/0,cross/WybJ5a5bJddEU4T_aHxuwqxgo-3469oiGT9DWDYPz6DhfgQe914iiBfD-GevAmvU9KONMKn3YhINqU49pVNahkCkeiF2w9Hlit1.css
- https://www.facebook.com/recover/initiate/?privacy_mutation_token=eyJ0eXBlIjo1LCJjcmVhdGlvbl90aW1lIjoxNzg3MjkwOTQwfQ%3D%3D&ars=facebook_login
- https://www.facebook.com/reg/?entry_point=login
- https://www.facebook.com/reg/
- https://www.facebook.com/login/
- https://l.facebook.com/l.php?u=https%3A%2F%2Fmessenger.com%2F&h=AUA0O2kse3VdImC_oyjFXYAuSHwFXkFcZHhXqsEW0WaE9rT-4ppDjiTG4uN-CclNwrSNvHGYJ9-D0Rj3fMemNOSNupoSybjXv-6uo8iDeiqChVVkKFuuyV1eYJiuaG4xWEVgcweAjRhkNDaF
Other scans of www.facebook.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://store.edenroc.biz/ - 24 Aug 2026 - unknown ·
https://www.aamailsoft.com/ - 24 Aug 2026 - unknown ·
http://selintasdunia.blogspot.com/2011/02/10-isi-kepala-perempuan-yang-perlu.html - 24 Aug 2026 - unknown ·
https://tallerescarrion.com/uploads/file/43332621506.pdf - 24 Aug 2026 - unknown ·
https://tallerescarrion.com/uploads/file/43332621506.pdf - 24 Aug 2026 - suspicious ·
https://www.clickteam.com/ - 24 Aug 2026 - unknown ·
https://fabrykakonwersji.pl/wp-content/plugins/super-forms/uploads/php/files/8095f0e7f9fb7d896523db3 - 24 Aug 2026 - unknown ·
https://www.fabriziocar.it/userfiles/files/fabifi.pdf - 24 Aug 2026 - unknown ·
https://deshdunya.com/blogimage/file/96657463789.pdf - 24 Aug 2026 - unknown ·
https://www.fabriziocar.it/userfiles/files/fabifi.pdf
Questions about www.facebook.com
- Is www.facebook.com safe?
- The scan of www.facebook.com on 21 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with www.facebook.com?
- 115 analysed samples communicate with this URL, including HUILoader, DCOM, Fileinfector.
- How was www.facebook.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.facebook.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan