www.avira.com - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned www.avira.com and returned a unknown verdict (score 4), categorised as credential-harvest. The page resolved to 23.33.238.168 on Akamai Technologies, Inc. in AU. The domain was registered 9301 days ago through MarkMonitor Inc.. 23 domains and 2 IPs were contacted, over 12 HTTP requests. 65 malware samples communicate with this URL (Fileinfector, HUILoader, Lamer, Cryptinject). The request followed 2 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 4) · Confidence 13%
- Scanned URL:
http://www.freeav.com/ - Domain: www.avira.com · IP: 23.33.238.168 · AS20940 · AU
- Server: akamai
- Page title: Download Security Software for Windows, Mac, Android & iOS | Avira Antivirus
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: MarkMonitor Inc. · domain age 9301 days · created 2001-03-05
- TLS issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36 · valid to Sep 22 23: · subject C=US, ST=Arizona, O=Gen Digital Inc., CN=avira.com
- Evidenced operator: Gen Digital Inc.
- HTTP requests captured: 12
- Scan tier: fast · observed 2026-08-23 00:52:09 UTC
Redirect chain
http://www.freeav.com/https://www.freeav.com/https://www.avira.com/
Malware communicating with this URL (65)
These samples were observed contacting or being served from www.avira.com. Each links to its full analysis.
- Fileinfector - referenced ·
ebb28d377963bb8813bc941a43c68c0b· first seen 2026-08-23 - HUILoader - referenced ·
361dbbb82bf32294eb8f30387ba8d788· first seen 2026-08-22 - Fileinfector - referenced ·
0659e8e24db5df1adeca458d0afff03d· first seen 2026-08-22 - Fileinfector - referenced ·
e60de18bdb7a35a183621511dba4c538· first seen 2026-08-22 - Fileinfector - referenced ·
83b9417e1b1f297c14a21018882be78d· first seen 2026-08-22 - Fileinfector - referenced ·
ec9e34da9a7a3d70338cf39ef2c470d1· first seen 2026-08-22 - Fileinfector - referenced ·
4b01b3407c94779490c56b4302404bc0· first seen 2026-08-22 - Lamer - referenced ·
35827a21fc9d606c525d079f149250b7· first seen 2026-08-22 - Cryptinject - referenced ·
a3b7b669d660eb669a02e4832716f1e5· first seen 2026-08-22 - fae69573c0df52e5c4e9701919bf906c5891e6a174b40fb21a31f8d44af7f1e8 - referenced ·
fae69573c0df52e5c4e9701919bf906c· first seen 2026-08-22 - Fileinfector - referenced ·
c2c53d2de6ac0056464a5a080048eb6b· first seen 2026-08-21 - HUILoader - referenced ·
2ac0370d9afece495545c0678d447e05· first seen 2026-08-21 - Fileinfector - referenced ·
f07b16d175c346eed2ad9483633439b4· first seen 2026-08-21 - ee3119cd5ec2d0492c181dad02d0b64d915433590286a63a9c98de0802fea35a - referenced ·
ee3119cd5ec2d0492c181dad02d0b64d· first seen 2026-08-21 - Fileinfector - referenced ·
94c2da749615decf799b24ee577b3e06· first seen 2026-08-21
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
- Cross-host redirect chain
Detected technologies
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 23.33.238.168 - AS20940 Akamai Technologies, Inc. (Australia)
- 52.58.28.12 - AS16509 A100 ROW GmbH (Germany)
Observed indicators
- www.avira.com
- nexus.ensighten.com
- assets.adobedtm.com
- www.webassetscdn.com
- script.crazyegg.com
- www.googletagmanager.com
- www.google-analytics.com
- www.microsoft.com
- support.avira.com
- my.avira.com
- www.trustpilot.com
- e-shop.avira.com
- play.google.com
- itunes.apple.com
- assets.prod.cms.avira.com
- www.youtube-nocookie.com
- google.com
- sitedirector.avira.com
- newsroom.gendigital.com
- oem.avira.com
Other scans of www.avira.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://www.avira.com/en/avira-antivirus-security-upsell - 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
Questions about www.avira.com
- Is www.avira.com safe?
- The scan of www.avira.com on 23 Aug 2026 reached no verdict either way (score 4). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.avira.com?
- 65 analysed samples communicate with this URL, including Fileinfector, HUILoader, Lamer, Cryptinject.
- How was www.avira.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.avira.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan