6it-vibor.rufacebook.events.thesixfigurementors.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned 6it-vibor.rufacebook.events.thesixfigurementors.com and returned a suspicious verdict (score 51). The page resolved to 54.174.39.19 on Amazon Technologies Inc. in US. The domain was registered 5932 days ago through GoDaddy.com, LLC. 10 domains and 10 IPs were contacted, over 23 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 51) · Confidence 60%
- Scanned URL:
https://6it-vibor.rufacebook.events.thesixfigurementors.com/ - Domain: 6it-vibor.rufacebook.events.thesixfigurementors.com · IP: 54.174.39.19 · AS14618 · US
- Page title: Bizzabo | 404 | Social Networking in conferences, meetups and events made easy with Bizzabo’s mobile networking solution
- HTTP status: 404 · text/html; charset=utf-8
- Registrar: GoDaddy.com, LLC · domain age 5932 days · created 2010-05-24
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 17 21: · subject CN=6it-vibor.rufacebook.events.thesixfigurementors.com
- HTTP requests captured: 23 · cookies set: 2 · outgoing links: 1
- Scan tier: standard · observed 2026-08-20 12:14:06 UTC
Antivirus & YARA (2 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- 2 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, JPCERT_LODEINFO
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Detected technologies
- jQuery
Contacted infrastructure
- 54.174.39.19 - AS14618 Amazon Technologies Inc. (United States)
- 104.17.24.14 - AS13335 Cloudflare, Inc. (United States)
- 172.64.154.50 - AS13335 Cloudflare, Inc. (United States)
- 142.250.207.3 - AS15169 Google LLC (Japan)
- 142.250.195.142 - AS15169 Google LLC (India)
- 157.240.15.13 - AS32934 Facebook, Inc. (Singapore)
- 172.66.0.227 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- 6it-vibor.rufacebook.events.thesixfigurementors.com
- cdn-static.bizzabo.com
- cdnjs.cloudflare.com
- apis.google.com
- connect.facebook.net
- platform.twitter.com
- platform.linkedin.com
- fonts.googleapis.com
- fonts.gstatic.com
- syndication.twitter.com
- 54.174.39.19
- 108.158.32.104
- 104.17.24.14
- 172.64.154.50
- 142.250.195.170
- 151.101.28.157
- 142.250.207.3
- 142.250.195.142
- 157.240.15.13
- 172.66.0.227
Questions about 6it-vibor.rufacebook.events.thesixfigurementors.com
- Is 6it-vibor.rufacebook.events.thesixfigurementors.com safe?
- No. MalwareAnalyzer scanned 6it-vibor.rufacebook.events.thesixfigurementors.com on 20 Aug 2026 and returned a suspicious verdict with a score of 51 out of 100. Treat it as hostile until it is re-checked.
- How was 6it-vibor.rufacebook.events.thesixfigurementors.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of 6it-vibor.rufacebook.events.thesixfigurementors.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan