053dev.update.mon-app-138.201.154.177.sslip.io - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned 053dev.update.mon-app-138.201.154.177.sslip.io and returned a suspicious verdict (score 53), categorised as credential-harvest. The page resolved to 138.201.154.177 on Hetzner Online GmbH in DE. 3 domains and 1 IP were contacted, over 33 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 53) · Confidence 68%
- Scanned URL:
https://053dev.update.mon-app-138.201.154.177.sslip.io/users/sign_in - Domain: 053dev.update.mon-app-138.201.154.177.sslip.io · IP: 138.201.154.177 · AS24940 · DE
- Server: Elestio
- Page title: Sign in · GitLab
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 17 22: · subject CN=053dev.update.mon-app-138.201.154.177.sslip.io
- HTTP requests captured: 33 · cookies set: 4 · outgoing links: 5
- Scan tier: standard · observed 2026-08-21 04:46:14 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_Maldoc_VBA_AutoExec
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
- Certificate issued < 48h ago
- Matches phishing-kit family "u-admin (uAdmin)"
Contacted infrastructure
- 138.201.154.177 - AS24940 Hetzner Online GmbH (Germany)
Observed indicators
- 053dev.update.mon-app-138.201.154.177.sslip.io
- about.gitlab.com
- forum.gitlab.com
- 138.201.154.177
- https://053dev.update.mon-app-138.201.154.177.sslip.io/users/sign_in
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/gitlab-sans/GitLabSans-9892dc17af892e03de41625c0ee325117a3b8ee4ba6005f3a3eac68510030aed.woff2
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/gitlab-sans/GitLabSans-Italic-f96f17332d67b21ada2dfba5f0c0e1d5801eab99330472057bf18edd93d4ccf7.woff2
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/gitlab-mono/GitLabMono-29c2152dac8739499dd0fe5cd37a486ebcc7d4798c9b6d3aeab65b3172375b05.woff2
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/gitlab-mono/GitLabMono-Italic-af36701a2188df32a9dcea12e0424c380019698d4f76da9ad8ea2fd59432cf83.woff2
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/application-c3d1141f40d7efe66c65a7b03cd6a1ed927c6792f90c35b7a6615d22bf20ab46.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/application_dark-89f19079874affe419a1d9a2a75794437c6cd02a0133db6deeda1f25f4d74671.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/page_bundles/login-7240ec00cf3969b710fe5e8959f8ef8eeff66d635ded28839b1b4256ae8d96a3.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/page_bundles/commit_description-9e7efe20f0cef17d0606edabfad0418e9eb224aaeaa2dae32c817060fa60abcc.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/page_bundles/work_items-d1aad2d3c26f03afa76a3d4bbb860c7563f7faea5741b9cccdc950cd1d6b42bf.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/page_bundles/notes_shared-1a99012f97ba760b6bc57563b5b2863243958d14d14a25fee12843f0268c2731.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/tailwind_cqs-47738a1cfefcc2bdfccf88967aea4864c8b0c249b5e10c969a5694e9b2e78341.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/fonts-deb7ad1d55ca77c0172d8538d53442af63604ff490c74acc2859db295c125bdb.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/highlight/themes/white-3e4f99f7678bc281e0acfacb2313bca0361fec21d357958f670d3b992ab562fd.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/highlight/themes/dark-b2fa723200af7b5f3b9e4478161d984ce37ab1c4f4fac8407e8e12fec2d8e5f0.css
- https://053dev.update.mon-app-138.201.154.177.sslip.io/assets/webpack/runtime.148dd071.bundle.js
Questions about 053dev.update.mon-app-138.201.154.177.sslip.io
- Is 053dev.update.mon-app-138.201.154.177.sslip.io safe?
- No. MalwareAnalyzer scanned 053dev.update.mon-app-138.201.154.177.sslip.io on 21 Aug 2026 and returned a suspicious verdict with a score of 53 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- How was 053dev.update.mon-app-138.201.154.177.sslip.io checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of 053dev.update.mon-app-138.201.154.177.sslip.io
Scanned on MalwareAnalyzer by Cyble · Open interactive scan