www.facebook.com - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.facebook.com and returned a benign verdict (score 0), categorised as credential-harvest. The page resolved to 157.240.8.35 on Facebook, Inc. in AU. The domain was registered 10738 days ago through RegistrarSafe, LLC. 7 domains and 2 IPs were contacted. 176 malware samples communicate with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 12%
- Scanned URL:
https://connect.facebook.net/ - Domain: www.facebook.com · IP: 157.240.8.35 · AS32934 · AU
- Page title: Facebook
- HTTP status: 200 · text/html; charset="utf-8"
- Registrar: RegistrarSafe, LLC · domain age 10738 days · created 1997-03-29
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Aug 30 23: · subject C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com
- Evidenced operator: Meta Platforms, Inc.
- Scan tier: fast · observed 2026-08-22 20:57:01 UTC
Redirect chain
https://connect.facebook.net/https://www.facebook.com/
Malware communicating with this URL (176)
These samples were observed contacting or being served from www.facebook.com. Each links to its full analysis.
- 501c5aae0439ca2e6f39ba60b2edd12a178cbd801daa69a586030ffed8b10a0c - referenced ·
501c5aae0439ca2e6f39ba60b2edd12a· first seen 2026-08-22 - 85c5b92f8d957a93fa1988619f3325f628c2f80d46e9bb43e0b314fad5b14457 - referenced ·
85c5b92f8d957a93fa1988619f3325f6· first seen 2026-08-22 - 2257c3e4d9bae2592c4b2c284aedaf992495138be9de422b2850689b36ccde77 - referenced ·
2257c3e4d9bae2592c4b2c284aedaf99· first seen 2026-08-22 - c640a89a0bf8b6a261b6f8733f512687dff6ead91bc71febc1cd261d17b4fc9a - referenced ·
c640a89a0bf8b6a261b6f8733f512687· first seen 2026-08-22 - 225379861f291b792f2c31b00b3998a8dacca2edf56501f9853eb00a5011b118 - referenced ·
225379861f291b792f2c31b00b3998a8· first seen 2026-08-22 - 225d99f9142a18f15dd0fe54fb2f3855e14b2450a3e08b8d462002ee8c502810 - referenced ·
225d99f9142a18f15dd0fe54fb2f3855· first seen 2026-08-22 - 2251e4b83d20deac67cdc8505e5f5f4855536f65acb543e9f6c9cb58d858ed07 - referenced ·
2251e4b83d20deac67cdc8505e5f5f48· first seen 2026-08-22 - 225ca7375117c92811e1ecd78b55a07e56b8f49f6ee79a047c54f299c93b5776 - referenced ·
225ca7375117c92811e1ecd78b55a07e· first seen 2026-08-22 - 2258e21e7b543c73d03d2770aeeef6188e11767859cb6a6ed09f2d9d894dcfbf - referenced ·
2258e21e7b543c73d03d2770aeeef618· first seen 2026-08-22 - 225aa81fcd6cc71c3e4c6523fe57ad963fabc0d7c9660a97abebcecf622d17e1 - referenced ·
225aa81fcd6cc71c3e4c6523fe57ad96· first seen 2026-08-22 - 22598a5e1c1d90013a94117c2e0cdb8ae5692579834fffbdf0b521887d7b0a0f - referenced ·
22598a5e1c1d90013a94117c2e0cdb8a· first seen 2026-08-22 - 0ca8372c2cd9636b943d2f156de874f8fc449568b7c6421ba8f3e7206749afe4 - referenced ·
0ca8372c2cd9636b943d2f156de874f8· first seen 2026-08-22 - f9953adad9df1f7ff6b1b603ca05bde7f0e6708bb8494521f8479980423c1c33 - referenced ·
f9953adad9df1f7ff6b1b603ca05bde7· first seen 2026-08-22 - af088a66e5f53eda956ebdd8c023a313fb48a792c314f33133e8b7d1727ea25e - referenced ·
af088a66e5f53eda956ebdd8c023a313· first seen 2026-08-22 - f9967f752c58162309bcef6479767c076ef73fc5e9c907610d4cff1fe1b12dfb - referenced ·
f9967f752c58162309bcef6479767c07· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 157.240.8.35 - AS32934 Facebook, Inc. (Australia)
- 157.240.8.23 - AS32934 Facebook, Inc. (Australia)
Observed indicators
- www.facebook.com
- static.xx.fbcdn.net
- en-gb.facebook.com
- scontent.xx.fbcdn.net
- video.xx.fbcdn.net
- l.facebook.com
- developers.facebook.com
- 157.240.8.35
- 157.240.8.23
- https://www.facebook.com/
- https://static.xx.fbcdn.net/rsrc.php/y1/r/ay1hV6OlegS.ico
- https://en-gb.facebook.com/
- https://scontent.xx.fbcdn.net/
- https://video.xx.fbcdn.net/
- https://static.xx.fbcdn.net/rsrc.php/v5/yP/l/0,cross/_maTRyRZ22Z8wmKvUcQXclxgo-3469oiGT9DWDYPz6DhfgQe914iiBfD-GevAmvU9KONMKn3YhINqU49pVNahkCkeiF2w9Hlit1.css
- https://www.facebook.com/recover/initiate/?privacy_mutation_token=eyJ0eXBlIjo1LCJjcmVhdGlvbl90aW1lIjoxNzg3NDMyMjIyfQ%3D%3D&ars=facebook_login
- https://www.facebook.com/reg/?entry_point=login
- https://www.facebook.com/reg/
- https://www.facebook.com/login/
- https://l.facebook.com/l.php?u=https%3A%2F%2Fmessenger.com%2F&h=AUDVpcALZB4Es5haDIBdd1TOHs-BTij_cFqL6eRZnPDJLUKaCRwAXqIjn2_jO1w_b-Ba_BZ_yIyQBEUj7KwO1101ikdNV8OnAiuy6Dw_4x8LYQfTHOXKs0Ik4uzgzRs20WlFRS8P8a3XrhW_
Other scans of www.facebook.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://store.edenroc.biz/ - 24 Aug 2026 - unknown ·
https://www.aamailsoft.com/ - 24 Aug 2026 - unknown ·
http://selintasdunia.blogspot.com/2011/02/10-isi-kepala-perempuan-yang-perlu.html - 24 Aug 2026 - unknown ·
https://tallerescarrion.com/uploads/file/43332621506.pdf - 24 Aug 2026 - unknown ·
https://tallerescarrion.com/uploads/file/43332621506.pdf - 24 Aug 2026 - suspicious ·
https://www.clickteam.com/ - 24 Aug 2026 - unknown ·
https://fabrykakonwersji.pl/wp-content/plugins/super-forms/uploads/php/files/8095f0e7f9fb7d896523db3 - 24 Aug 2026 - unknown ·
https://www.fabriziocar.it/userfiles/files/fabifi.pdf - 24 Aug 2026 - unknown ·
https://deshdunya.com/blogimage/file/96657463789.pdf - 24 Aug 2026 - unknown ·
https://www.fabriziocar.it/userfiles/files/fabifi.pdf
Questions about www.facebook.com
- Is www.facebook.com safe?
- The scan of www.facebook.com on 22 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with www.facebook.com?
- 176 analysed samples communicate with this URL.
- How was www.facebook.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.facebook.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan