38e5bbdfe8be.gdziezjesc.info - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned 38e5bbdfe8be.gdziezjesc.info and returned a suspicious verdict (score 34), categorised as credential-harvest. The page resolved to 94.152.13.94 on Hosting Servers in PL. 10 domains and 1 IP were contacted, over 15 HTTP requests. 1 malware sample communicates with this URL (Phishing). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 34) · Confidence 43%
- Scanned URL:
https://38e5bbdfe8be.gdziezjesc.info/userfiles/file/sijop.pdf - Domain: 38e5bbdfe8be.gdziezjesc.info · IP: 94.152.13.94 · AS29522 · PL
- Server: nginx
- Page title: Gdzie Zjeść w Warszawie - Najlepsze restauracje w Warszawie - GdzieZjesc.info - Restauracje Warszawa - Catering kawiarnie oraz puby w Warszawie - Gdzie Zjeść
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=CloudFlare, Inc., OU=CloudFlare Origin SSL Certificate Authority, L=San Francisco, ST=California · valid to Nov 15 09: · subject O=CloudFlare, Inc., OU=CloudFlare Origin CA, CN=CloudFlare Origin Certificate
- Evidenced operator: CloudFlare, Inc.
- HTTP requests captured: 15
- Scan tier: standard · observed 2026-08-22 23:45:20 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from 38e5bbdfe8be.gdziezjesc.info. Each links to its full analysis.
- Phishing - referenced ·
f7eaa43d607f36cb4d30c3e6ebb36ca8· first seen 2026-08-15
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Untrusted certificate (SELF_SIGNED_CERT_IN_CHAIN)
- Matches phishing-kit family "Meta / Facebook Login Kit"
Detected technologies
- Nginx
- Google Analytics
- jQuery
- Cloudflare Insights
Contacted infrastructure
- 94.152.13.94 - AS29522 Hosting Servers (Poland)
Observed indicators
- 38e5bbdfe8be.gdziezjesc.info
- www.googletagmanager.com
- www.clarity.ms
- www.gdziezjesc.info
- cdnjs.cloudflare.com
- pagead2.googlesyndication.com
- www.facebook.com
- www.instagram.com
- www.afmedia.pl
- static.cloudflareinsights.com
- 94.152.13.94
- https://38e5bbdfe8be.gdziezjesc.info/userfiles/file/sijop.pdf
- https://www.googletagmanager.com/gtag/js?id=G-78VB22CYMH
- https://www.clarity.ms/tag/
- https://www.gdziezjesc.info/
- https://www.gdziezjesc.info/rss.php
- https://38e5bbdfe8be.gdziezjesc.info/favicon.png
- https://38e5bbdfe8be.gdziezjesc.info/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js
- https://38e5bbdfe8be.gdziezjesc.info/min/?f=/css/bootstrap.modal.min.css,css/font-awesome.min.css,css/style.css,css/responsive.css,css/hovers.css,js/photoswipe/photoswipe.css,js/photoswipe/default-skin/default-skin.css,css/subscribe-better.css,css/jquery.smartsuggest.css,css/jquery.fancybox.min.css,js/rateit/rateit.css&123456
- https://cdnjs.cloudflare.com/ajax/libs/jquery/3.6.1/jquery.min.js
Other scans of 38e5bbdfe8be.gdziezjesc.info (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://38e5bbdfe8be.gdziezjesc.info/
Questions about 38e5bbdfe8be.gdziezjesc.info
- Is 38e5bbdfe8be.gdziezjesc.info safe?
- No. MalwareAnalyzer scanned 38e5bbdfe8be.gdziezjesc.info on 22 Aug 2026 and returned a suspicious verdict with a score of 34 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with 38e5bbdfe8be.gdziezjesc.info?
- 1 analysed samples communicate with this URL, including Phishing.
- How was 38e5bbdfe8be.gdziezjesc.info checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of 38e5bbdfe8be.gdziezjesc.info
Scanned on MalwareAnalyzer by Cyble · Open interactive scan