www.facebook.com - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned www.facebook.com and returned a benign verdict (score 0), categorised as credential-harvest. The page resolved to 157.240.8.35 on Facebook, Inc. in AU. The domain was registered 10740 days ago through RegistrarSafe, LLC. 7 domains and 2 IPs were contacted. 220 malware samples communicate with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 12%
- Scanned URL:
https://connect.facebook.net/ - Domain: www.facebook.com · IP: 157.240.8.35 · AS32934 · AU
- Page title: Facebook
- HTTP status: 200 · text/html; charset="utf-8"
- Registrar: RegistrarSafe, LLC · domain age 10740 days · created 1997-03-29
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Aug 31 23: · subject C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com
- Evidenced operator: Meta Platforms, Inc.
- Scan tier: fast · observed 2026-08-24 06:42:24 UTC
Redirect chain
https://connect.facebook.net/https://www.facebook.com/
Malware communicating with this URL (220)
These samples were observed contacting or being served from www.facebook.com. Each links to its full analysis.
- fc20da1e08c170c2a45629ae13338fc4ffe87ca2d9b98b94cd9f37e419d63534 - referenced ·
fc20da1e08c170c2a45629ae13338fc4· first seen 2026-08-24 - b207d74bec93f19f6341ce96503cba4d651cab9b4d346f131491244d7b21fea8 - referenced ·
b207d74bec93f19f6341ce96503cba4d· first seen 2026-08-24 - 36da5b3051a3afd0d38227789dc9682542283debc0bb25a6a184623ac06d947a - referenced ·
36da5b3051a3afd0d38227789dc96825· first seen 2026-08-24 - 5edb6cb0d8b9be0b2697ab7cf7b10a99fccde29d4c53ef8b92452563168e41dd - referenced ·
5edb6cb0d8b9be0b2697ab7cf7b10a99· first seen 2026-08-24 - 5ede5492e375b1281ea32bbe260136293457bfe5d1dccf2f9872f0a3d5ea804b - referenced ·
5ede5492e375b1281ea32bbe26013629· first seen 2026-08-24 - 2f935614fdfbd291b5643fdb596bd8f0e08df17735043fb67783abd11cde19e0 - referenced ·
2f935614fdfbd291b5643fdb596bd8f0· first seen 2026-08-24 - ec709c78e90f449cc51c3d390370b720ac2492bbd586de1baf46156bc098e9b7 - referenced ·
ec709c78e90f449cc51c3d390370b720· first seen 2026-08-24 - 99d578926044274a3915e6632de5421a771af8eb5a88dad3998f625dce2ed8e6 - referenced ·
99d578926044274a3915e6632de5421a· first seen 2026-08-24 - b6e35666a1663be4d084420d20fcde7064ab2ea5b71efb2c1b71824e5d8ec880 - referenced ·
b6e35666a1663be4d084420d20fcde70· first seen 2026-08-24 - c84440adcc52d6e8d2f0146522004104dce6d3cda3dd69cfa9b25c69b2059efd - referenced ·
c84440adcc52d6e8d2f0146522004104· first seen 2026-08-24 - be7aec187f32f6fd9c4b85c536161b0875084ce0eb046bec6537d2602bc57b81 - referenced ·
be7aec187f32f6fd9c4b85c536161b08· first seen 2026-08-24 - a4e069ba73932d677be5614e7823899cdd8fd733623bace7889404593d187601 - referenced ·
a4e069ba73932d677be5614e7823899c· first seen 2026-08-24 - f767892302c185fcd0cbc833dc246b214211f37de954513b3dcdd277ebb403de - referenced ·
f767892302c185fcd0cbc833dc246b21· first seen 2026-08-24 - 2904992f60c19434db0d82e233024c57d94d51a4d9ae0b42997ab3ad8017a2b7 - referenced ·
2904992f60c19434db0d82e233024c57· first seen 2026-08-23 - 2e08d12a894532a8541d3daf16657da40c4715c5a8fc15d754056edca6663dbc - referenced ·
2e08d12a894532a8541d3daf16657da4· first seen 2026-08-23
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 157.240.8.35 - AS32934 Facebook, Inc. (Australia)
- 157.240.8.23 - AS32934 Facebook, Inc. (Australia)
Observed indicators
- www.facebook.com
- static.xx.fbcdn.net
- en-gb.facebook.com
- scontent.xx.fbcdn.net
- video.xx.fbcdn.net
- l.facebook.com
- developers.facebook.com
- 157.240.8.35
- 157.240.8.23
- https://www.facebook.com/
- https://static.xx.fbcdn.net/rsrc.php/y1/r/ay1hV6OlegS.ico
- https://en-gb.facebook.com/
- https://scontent.xx.fbcdn.net/
- https://video.xx.fbcdn.net/
- https://static.xx.fbcdn.net/rsrc.php/v5/yQ/l/0,cross/aBIDyB4xhJy8wmKvUcQXclxgo-3469oiGT9DWDYPz6DhfgQe914iiBfD-GevAmvU9KONMKn3YhINqU49pVNahkCkeiF2w9Hlit1.css
- https://www.facebook.com/recover/initiate/?privacy_mutation_token=eyJ0eXBlIjo1LCJjcmVhdGlvbl90aW1lIjoxNzg3NTUzNzQ0fQ%3D%3D&ars=facebook_login
- https://www.facebook.com/reg/?entry_point=login
- https://www.facebook.com/reg/
- https://www.facebook.com/login/
- https://l.facebook.com/l.php?u=https%3A%2F%2Fmessenger.com%2F&h=AUCKcvjuXIv3E4-eUuxW0PYK0GcxJ_-p5-iDK1m_TrltH28J_O7Vc6IFHk_XeAqEtoFMRbOqa3TmX1RamDHxByy2AOVIE_PaXNuoKftegOclrdr8_7oICskX7-c4kuiwVCu1enmzo9XON6uy
Other scans of www.facebook.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://landofcoder.com/ - 24 Aug 2026 - benign ·
https://community.dropbox.com/en/ - 24 Aug 2026 - benign ·
https://help.dropbox.com/ - 24 Aug 2026 - unknown ·
https://manhremhoangvan.com/wp-content/uploads/files/zezumemesodetoros.pdf - 24 Aug 2026 - unknown ·
http://eng.sut.ac.th/tce/2016/administrator/ckfinder/userfiles/files/49307295506.pdf - 24 Aug 2026 - suspicious ·
https://manhremhoangvan.com/wp-content/uploads/files/zezumemesodetoros.pdf - 24 Aug 2026 - unknown ·
http://eng.sut.ac.th/tce/2016/administrator/ckfinder/userfiles/files/49307295506.pdf - 24 Aug 2026 - suspicious ·
https://flyags.com/editorResources/file/47360693342.pdf - 24 Aug 2026 - suspicious ·
https://flyags.com/editorResources/file/47360693342.pdf - 24 Aug 2026 - unknown ·
https://creativecommons.org/licenses/by/3.0/
Questions about www.facebook.com
- Is www.facebook.com safe?
- The scan of www.facebook.com on 24 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with www.facebook.com?
- 220 analysed samples communicate with this URL.
- How was www.facebook.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.facebook.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan