www.facebook.com - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.facebook.com and returned a benign verdict (score 0), categorised as credential-harvest. The page resolved to 157.240.15.35 on Facebook, Inc. in SG. The domain was registered 10735 days ago through RegistrarSafe, LLC. 7 domains and 2 IPs were contacted. 86 malware samples communicate with this URL (Fileinfector). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: benign (score 0) · Confidence 12%
- Scanned URL:
https://connect.facebook.net/ - Domain: www.facebook.com · IP: 157.240.15.35 · AS32934 · SG
- Page title: Facebook
- HTTP status: 200 · text/html; charset="utf-8"
- Registrar: RegistrarSafe, LLC · domain age 10735 days · created 1997-03-29
- TLS issuer: C=US, O=DigiCert Inc, CN=DigiCert Global G2 TLS RSA SHA256 2020 CA1 · valid to Aug 27 23: · subject C=US, ST=California, L=Menlo Park, O=Meta Platforms, Inc., CN=*.facebook.com
- Evidenced operator: Meta Platforms, Inc.
- Scan tier: fast · observed 2026-08-20 04:12:21 UTC
Redirect chain
https://connect.facebook.net/https://www.facebook.com/
Malware communicating with this URL (86)
These samples were observed contacting or being served from www.facebook.com. Each links to its full analysis.
- Fileinfector - contacted ·
4314df0a740340c721a7e9049e2c9173· first seen 2026-08-20 - 0f3b76075929a987ffbeae163f89a9f2fe98b6295b36071abdb52b9b84dfff00 - referenced ·
0f3b76075929a987ffbeae163f89a9f2· first seen 2026-08-20 - 99005e76e76dfa6d1307d39afb8b3a77949c42b6ca5048742b4f4fcdc6e42267 - referenced ·
99005e76e76dfa6d1307d39afb8b3a77· first seen 2026-08-20 - 695391375ed46309ecff4c96abb6945955f97fc2bed2b211d7878acbcd461cc0 - referenced ·
695391375ed46309ecff4c96abb69459· first seen 2026-08-20 - Fileinfector - contacted ·
2df3ebb8e7d913a246ed63b231ce1857· first seen 2026-08-20 - 9a838d282b78b253100681953b544da6c36ee2761840024782f84134cdf7cddc - referenced ·
9a838d282b78b253100681953b544da6· first seen 2026-08-19 - e07affe0ff90e2a656e93dff625711547ce078dda432fc678dc4537e848b0ee6 - referenced ·
e07affe0ff90e2a656e93dff62571154· first seen 2026-08-19 - 990ff0daab21470e66ad0c7227c3c507ee70692995aba5a26ca440d52e79a7bf - referenced ·
990ff0daab21470e66ad0c7227c3c507· first seen 2026-08-19 - fbevents.js - referenced ·
5d8d4bb1186f740b55e9d632b68acc0b· first seen 2026-08-19 - 3c82da6cc4cc2feb20242656e6e0eda087b38ff6d2532ac7e0afe671969817c1 - referenced ·
3c82da6cc4cc2feb20242656e6e0eda0· first seen 2026-08-19 - 984772ded921b432769d1690bf3e0d80909da241f902ed5d9e2ee91038ce6d5a - referenced ·
984772ded921b432769d1690bf3e0d80· first seen 2026-08-19 - e342d1a5ca701c959295444750b46a8420bc0f617cf941e41485545d512dc052 - referenced ·
e342d1a5ca701c959295444750b46a84· first seen 2026-08-19 - ffe73f4359a037ecf75f93ba8b73971e116ac939d3cc64e484b44b8b8d53be1f - referenced ·
ffe73f4359a037ecf75f93ba8b73971e· first seen 2026-08-19 - 7c288b1214c057ec81f1b4d2f592add488049bcf23dfeb407e70aedc359b75fb - referenced ·
7c288b1214c057ec81f1b4d2f592add4· first seen 2026-08-19 - 60a8a5d0242d70cfd70be8248d655934ba3a1ee9b2e2c4c492e64d5b6d83aa7b - referenced ·
60a8a5d0242d70cfd70be8248d655934· first seen 2026-08-19
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 157.240.15.35 - AS32934 Facebook, Inc. (Singapore)
- 157.240.15.13 - AS32934 Facebook, Inc. (Singapore)
Observed indicators
- www.facebook.com
- static.xx.fbcdn.net
- en-gb.facebook.com
- scontent.xx.fbcdn.net
- video.xx.fbcdn.net
- l.facebook.com
- developers.facebook.com
- 157.240.15.35
- 157.240.15.13
- https://www.facebook.com/
- https://static.xx.fbcdn.net/rsrc.php/y1/r/ay1hV6OlegS.ico
- https://en-gb.facebook.com/
- https://scontent.xx.fbcdn.net/
- https://video.xx.fbcdn.net/
- https://static.xx.fbcdn.net/rsrc.php/v5/yh/l/0,cross/lfOH5gSFMGyEU4T_aHxuwqxgo-3469oiGT9DWDYPz6DhfgQe914iiBfD-GevAmvU9KONMKn3YhINqU49pVNahkCkeiF2w9Hlit1.css
- https://www.facebook.com/recover/initiate/?privacy_mutation_token=eyJ0eXBlIjo1LCJjcmVhdGlvbl90aW1lIjoxNzg3MTk5MTQyfQ%3D%3D&ars=facebook_login
- https://www.facebook.com/reg/?entry_point=login
- https://www.facebook.com/reg/
- https://www.facebook.com/login/
- https://l.facebook.com/l.php?u=https%3A%2F%2Fmessenger.com%2F&h=AUAYBa4y5ErOF23y9LCrS6ruK8gBLokMfN4l9SntsF5ul6wjah5xM7E9AHkk8Y_eEsZuxxosWDRtDIGYzI12LEmgspPSQpRhqfXYopK3A-xBslU5NkYcSE6NZWobyg9L32GKGpxMp1kCXZf6
Other scans of www.facebook.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://naatsihwp.org.au/ - 24 Aug 2026 - unknown ·
http://abapaposentados.com.br/wp-content/plugins/formcraft/file-upload/server/content/files/160b88ee - 24 Aug 2026 - unknown ·
https://www.a1touchsolution.nl/en/sites/default/files/95216779236.pdf - 24 Aug 2026 - unknown ·
https://www.immiflex.com/wp-content/plugins/formcraft/file-upload/server/content/files/1615cc21d1633 - 24 Aug 2026 - unknown ·
https://www.ebenisterie-burette.com/ckfinder/userfiles/files/68149192623.pdf - 24 Aug 2026 - unknown ·
https://www.webinaris.com/ - 24 Aug 2026 - unknown ·
https://www.webinaris.com/ - 24 Aug 2026 - unknown ·
http://legendsnewsbr.blogspot.com/ - 24 Aug 2026 - unknown ·
https://moda.net.pl/ - 24 Aug 2026 - unknown ·
https://moda.net.pl/moda/polecamy/keep-calm-and-wait-for-friday
Questions about www.facebook.com
- Is www.facebook.com safe?
- The scan of www.facebook.com on 20 Aug 2026 found no evidence of harm. That is the absence of a finding at one point in time, not a guarantee: a page can change, and a scan only sees what it was served.
- What malware is associated with www.facebook.com?
- 86 analysed samples communicate with this URL, including Fileinfector.
- How was www.facebook.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.facebook.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan