viralizate.net
96.47.167.18AS26042 · USpage delivers an executable (https://viralizate.net/…ildersinc/download.php)
- Delivered filemalicious
- Browser Analysissuspicious
- Content Inspectionclean
- Threat Intelligenceclean
- Network & Hostingclean
- Related Infrastructureclean
- TLS Fingerprintunknown
- Domain Intelligenceunknown
What happened
Step by step, from what the scanner recorded.Be careful — warning signs found
AutomatedIts page title claims to be Adobe, which this address is not associated with. The file it serves was analysed and found malicious. This site shows signs commonly seen in scams or impersonation, but we could not confirm it for certain. It may be a real threat, or it may be a legitimate site that simply looks unusual to our automated checks.
What to do
Avoid entering passwords or payment details until you are sure it is genuine. Open the company directly from its known website or app instead of this link. Check the evidence below and escalate to your analyst if unsure.
"Suspicious" is a caution, not a confirmation — it can be a false alarm. The evidence below explains why it was flagged.
Findings
Strongest firstWe analysed the file this page delivered — it is Malicious.
Success
SHA-256 09293a6c589d933da8584b8293edcea434f0fb7096d22e75aa9fb80f1671ae65
The page presents itself as a document but its button downloads a program to run, not a document to read.
Analyst noteConfirm what the download actually serves. A document workflow that delivers an installer is the tell; the file itself may be signed and clean.
The page DISPLAYS a known brand's logo while carrying almost no content of its own — no article, no navigation, nothing the brand's own site would have.
Analyst noteThe brand is in the page's images, not just its words, and the page has nothing else on it. Check what the page is asking the visitor to do.
Files · 2
Stored by the engineWhat you download may be live malware. Open it only in an isolated environment, and do not double-click it.
The ZIP is encrypted. Password:infected
Inside the ZIP the file carries a name the engine generated, not the one the page used.
Downloaded fileCleanThe engine stored it under a generated name
SHA-2569cc0dfa491f5eebdca6a351e699886946b0b96fdbcb7d454ea15af2fffdf6b93
Fromhxxps://viralizate[.]net/fencebuildersinc/
Delivered fileMaliciousThe engine stored it under a generated name
SHA-25609293a6c589d933da8584b8293edcea434f0fb7096d22e75aa9fb80f1671ae65
Fromhxxps://viralizate[.]net/fencebuildersinc/download[.]php
Infrastructure
- IP
- 96.47.167.18FIBERSTATE - FiberState, LLC, US · AS26042US
- TLS
- CN=YR1, O=Let's Encrypt, C=US · expires Oct 11, 2026
- Redirects
- 1 hop · /fencebuildersinc/ → /fencebuildersinc/download.html
WHOIS
- Registrar
- Arsys Internet, S.L. dba NICLINE.COM
- Created
- Nov 12, 2021
- Expires
- Nov 12, 2026
- Nameservers
- ns49.dnsiaas.comns50.dnsiaas.com
Hashes & fingerprints
Page capture
LiveTitle “Background Image Page” · brand shown: Adobe (medium)
Engines
8 · time to verdictPage
- HTTP
- 200 · Completed
- Title
- Background Image Page
- Load
- 38.32 s · 8 requests