www.avira.com - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned www.avira.com and returned a unknown verdict (score 4), categorised as credential-harvest. The page resolved to 23.33.238.168 on Akamai Technologies, Inc. in AU. The domain was registered 9302 days ago through MarkMonitor Inc.. 23 domains and 2 IPs were contacted, over 12 HTTP requests. 76 malware samples communicate with this URL (Fileinfector, Cryptinject, Bgmo, AntiDebug). The request followed 2 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 4) · Confidence 13%
- Scanned URL:
http://www.freeav.com/ - Domain: www.avira.com · IP: 23.33.238.168 · AS20940 · AU
- Server: akamai
- Page title: Download Security Software for Windows, Mac, Android & iOS | Avira Antivirus
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: MarkMonitor Inc. · domain age 9302 days · created 2001-03-05
- TLS issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36 · valid to Sep 22 23: · subject C=US, ST=Arizona, O=Gen Digital Inc., CN=avira.com
- Evidenced operator: Gen Digital Inc.
- HTTP requests captured: 12
- Scan tier: fast · observed 2026-08-23 16:32:39 UTC
Redirect chain
http://www.freeav.com/https://www.freeav.com/https://www.avira.com/
Malware communicating with this URL (76)
These samples were observed contacting or being served from www.avira.com. Each links to its full analysis.
- Fileinfector - referenced ·
418fed7baf5728fea3033130cca2f445· first seen 2026-08-23 - Fileinfector - referenced ·
4f85aac69f12c2faca087a5a90398fc8· first seen 2026-08-23 - Fileinfector - referenced ·
f261824b9db0afb78bb0caee5175196d· first seen 2026-08-23 - Fileinfector - referenced ·
a49bd95da3994955a1a991e73c0b78c0· first seen 2026-08-23 - Cryptinject - referenced ·
ab873b5a29f6a0cc34a06adee720c630· first seen 2026-08-23 - Fileinfector - referenced ·
0f806f6e5315caff928408ef43bc3ab0· first seen 2026-08-23 - 961b7d702550deeb1597801a718b441897e7d21dbb5322dd34d7381603b008ab - referenced ·
961b7d702550deeb1597801a718b4418· first seen 2026-08-23 - Bgmo - referenced ·
08ccb63db294fe21b1b9c90c5fd4b5e0· first seen 2026-08-23 - d5be9a3ec2d7d9caa54a2b147b0b44a650d3038afa1b99f2d8ed9c835930e038 - referenced ·
d5be9a3ec2d7d9caa54a2b147b0b44a6· first seen 2026-08-23 - Fileinfector - referenced ·
b0bccb2efc60122be1c5db2825af1a98· first seen 2026-08-23 - AntiDebug - referenced ·
a9af701a7a57022dcc0b2148a39c08fe· first seen 2026-08-23 - Fileinfector - referenced ·
ebb28d377963bb8813bc941a43c68c0b· first seen 2026-08-23 - HUILoader - referenced ·
361dbbb82bf32294eb8f30387ba8d788· first seen 2026-08-22 - Fileinfector - referenced ·
0659e8e24db5df1adeca458d0afff03d· first seen 2026-08-22 - Fileinfector - referenced ·
e60de18bdb7a35a183621511dba4c538· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
- Cross-host redirect chain
Detected technologies
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 23.33.238.168 - AS20940 Akamai Technologies, Inc. (Australia)
- 52.58.28.12 - AS16509 A100 ROW GmbH (Germany)
Observed indicators
- www.avira.com
- nexus.ensighten.com
- assets.adobedtm.com
- www.webassetscdn.com
- script.crazyegg.com
- www.googletagmanager.com
- www.google-analytics.com
- www.microsoft.com
- support.avira.com
- my.avira.com
- www.trustpilot.com
- e-shop.avira.com
- play.google.com
- itunes.apple.com
- assets.prod.cms.avira.com
- www.youtube-nocookie.com
- google.com
- sitedirector.avira.com
- newsroom.gendigital.com
- oem.avira.com
Other scans of www.avira.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown ·
https://www.avira.com/en/avira-antivirus-security-upsell - 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
Questions about www.avira.com
- Is www.avira.com safe?
- The scan of www.avira.com on 23 Aug 2026 reached no verdict either way (score 4). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.avira.com?
- 76 analysed samples communicate with this URL, including Fileinfector, Cryptinject, Bgmo, AntiDebug.
- How was www.avira.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.avira.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan