5thaveseniors.org - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned 5thaveseniors.org and returned a suspicious verdict (score 28). The page resolved to 172.67.205.8 on Cloudflare, Inc. in US. 5 domains and 2 IPs were contacted, over 4 HTTP requests. 3 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
http://5thaveseniors.org/userfiles/file/refanos.pdf - Domain: 5thaveseniors.org · IP: 172.67.205.8 · AS13335 · US
- Server: cloudflare
- Page title: Page not found – 5th Avenue 50Plus Activity Centre
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Oct 9 14: · subject CN=5thaveseniors.org
- HTTP requests captured: 4
- Scan tier: standard · observed 2026-08-20 19:46:17 UTC
Redirect chain
http://5thaveseniors.org/userfiles/file/refanos.pdfhttps://5thaveseniors.org/userfiles/file/refanos.pdf
Malware communicating with this URL (3)
These samples were observed contacting or being served from 5thaveseniors.org. Each links to its full analysis.
- Phishing - referenced ·
361c46c86cc77c79b3db5d67f31e102b· first seen 2026-08-15 - Phishing - referenced ·
b894bddce22a754aa3d1301a28faf619· first seen 2026-08-14 - Phishing - referenced ·
f001234ec8fc620987ea7b2f97944008· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_Maldoc_VBA_AutoExec
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
- PHP
- WordPress
- jQuery
- Cloudflare Insights
Contacted infrastructure
- 172.67.205.8 - AS13335 Cloudflare, Inc. (United States)
- 104.21.22.126 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- 5thaveseniors.org
- www.facebook.com
- bit.ly
- www.google.com
- static.cloudflareinsights.com
- 172.67.205.8
- 104.21.22.126
- https://5thaveseniors.org/userfiles/file/refanos.pdf
- https://5thaveseniors.org/feed/
- https://5thaveseniors.org/wp-content/uploads/2024/07/5th_ave_favicon_64x64.png
- https://5thaveseniors.org/wp-content/uploads/2024/07/5th_ave_favicon_180x180.png
- https://5thaveseniors.org/wp-content/uploads/2024/07/5th_ave_favicon_192x192.png
- https://5thaveseniors.org/wp-content/plugins/email-encoder-bundle/assets/css/style.css?ver=54d4eedc552c499c4a8d6b89c23d3df1
- https://5thaveseniors.org/wp-includes/css/dashicons.min.css?ver=2b5b1bdd2245da65747e7b92a4293b04
- https://5thaveseniors.org/wp-content/uploads/fusion-styles/e67e950b47c1e567e9775fd7000dff37.min.css?ver=3.16
- https://5thaveseniors.org/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://5thaveseniors.org/wp-content/plugins/email-encoder-bundle/assets/js/custom.js?ver=2d37aa1530beb8634b12ca51eeda0b4b
- https://5thaveseniors.org/wp-json/
- https://5thaveseniors.org/xmlrpc.php?rsd
- https://5thaveseniors.org/wp-content/uploads/fusion-gfonts/JTUSjIg1_i6t8kCHKm459Wlhyw.woff2
Other scans of 5thaveseniors.org (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 15 Aug 2026 - suspicious ·
https://5thaveseniors.org/userfiles/file/dixinemosuxil.pdf - 14 Aug 2026 - suspicious ·
https://5thaveseniors.org/userfiles/file/xuvasizojowapopuzes.pdf - 14 Aug 2026 - suspicious ·
https://5thaveseniors.org/userfiles/file/xuvasizojowapopuzes.pdf
Questions about 5thaveseniors.org
- Is 5thaveseniors.org safe?
- No. MalwareAnalyzer scanned 5thaveseniors.org on 20 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with 5thaveseniors.org?
- 3 analysed samples communicate with this URL, including Phishing.
- How was 5thaveseniors.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of 5thaveseniors.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan