Scan report · 26 days agoPublic

docs.virustotal.com

34.117.229.111AS396982 · US
Verdict

What happened

Step by step, from what the scanner recorded.
Load 34.7 s · 62 requests
01 · Visitor opensdocs.virustotal.com/docs/how-it-works
02 · Page shown
How it works
03 · File delivered · malicious1eee20a8-1344-47bb-8917-5973405bbca4.html

Dangerous — confirmed threat

Automated

The file it serves was analysed and found malicious. We found strong evidence that this site is malicious — for example a phishing page, a scam, or hostile code. Treat anything it asked for (passwords, card details, codes) as exposed.

What to do

Do not enter any information or download anything. If you already did, change those passwords now and contact your bank if payment details were involved. Block or report the link to your team.

This reflects the evidence found at the time of the scan. If you believe it is a mistake, you can escalate it for analyst review.

Findings

Strongest first
MalwareMalware found in the downloaded file
1eee20a8-1344-47bb-8917-5973405bbca4.html

Our Content Inspection engine downloaded the file this URL serves and analyzed it as a real payload — it matched known malware. Do not open or run this file.

Success

SHA-256 610e4dd3d475db7c320d6442f5c1cc77ffca157e37829a48a0e76c8c38ff2745

InfoCross-domain scripts injected at runtime
1 script(s)

The page dynamically injected scripts from other domains. This is extremely common on legitimate sites (CDNs, analytics, asset domains) and is shown for context only.

Analyst noteNoisy by itself — a CDN/asset domain (e.g. a brand's own *.githubassets.com) is normal. Only meaningful if the source domain is unrelated/suspicious.

Infrastructure

IP
34.117.229.111GOOGLE-CLOUD-PLATFORM - Google LLC, US · AS396982US
TLS
CN=WR3, O=Google Trust Services, C=US · expires Oct 28, 2026

WHOIS

Registrar
MarkMonitor Inc.
Created
Sep 18, 2002
Expires
Sep 18, 2027
Nameservers
ns-cloud-c1.googledomains.comns-cloud-c2.googledomains.comns-cloud-c3.googledomains.comns-cloud-c4.googledomains.com
10 malicious15 suspicious

Hashes & fingerprints

Page capture

Live

Title “How it works”

Engines

7 · time to verdict

Page

HTTP
200 · Completed
Title
How it works
Load
34.66 s · 62 requests
Stack · 13CloudflareCloudflare Bot ManagementGooberGoogle AnalyticsGoogle Cloud CDNGoogle Tag Manager