aefd.nelreports.net - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned aefd.nelreports.net and returned a unknown verdict (score -12). The page resolved to 23.46.10.55 on Akamai Technologies, Inc. in AU. 1 domain and 1 IP were contacted. 117 malware samples communicate with this URL (Juko, Zusy, Gootloader, Generickdz). This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://aefd.nelreports.net/ - Domain: aefd.nelreports.net · IP: 23.46.10.55 · AS20940 · AU
- Server: Kestrel
- HTTP status: 404
- TLS issuer: C=US, O=Microsoft Corporation, CN=Microsoft TLS G2 ECC CA OCSP 02 · valid to Mar 3 05: · subject C=US, ST=WA, L=Redmond, O=Microsoft Corporation, CN=*.nelreports.net
- Evidenced operator: Microsoft Corporation
- Scan tier: fast · observed 2026-08-24 06:47:23 UTC
Malware communicating with this URL (117)
These samples were observed contacting or being served from aefd.nelreports.net. Each links to its full analysis.
- 216974cc4040859dfc9aacbf07d3a71adc4484fa83e6a7228e8854a2d6992e7f - contacted ·
216974cc4040859dfc9aacbf07d3a71a· first seen 2026-08-24 - Juko - contacted ·
43f2b3b2dd5e94c93f0feea61136c97d· first seen 2026-08-24 - Zusy - contacted ·
d53a997ca3b6c5ce009a03e3351d7e92· first seen 2026-08-24 - b6e89411c62313bf48cd4634d7c6dd4654b2d4a357f39debb2c69d8a05f9b242 - contacted ·
b6e89411c62313bf48cd4634d7c6dd46· first seen 2026-08-24 - Gootloader - contacted ·
b6e105c49523177a04f65400536984e3· first seen 2026-08-24 - Generickdz - contacted ·
8730202dc2298ff83430bd251ab88696· first seen 2026-08-23 - Lmir - contacted ·
c19c3b38b36bf27abda111fbd1885eb2· first seen 2026-08-23 - Bskd - contacted ·
2067904512510724369e1beb777e280e· first seen 2026-08-23 - fe948d0a123eaafdc137fc795f3f0ef114d90826b96450e7f213d82f0c13985d - contacted ·
fe948d0a123eaafdc137fc795f3f0ef1· first seen 2026-08-23 - bf34b7b41c49ce9b9fd601fbeaddd82566b35d06a42ee1cea09d004dea48bfcb - contacted ·
bf34b7b41c49ce9b9fd601fbeaddd825· first seen 2026-08-23 - Ursu - contacted ·
4d0e7703a1e13982b31e760231e1b38d· first seen 2026-08-23 - 16f779bf0e84f83c74a64a366c4ba844ff0b2730893e0ad034b3af733cf85ac6 - contacted ·
16f779bf0e84f83c74a64a366c4ba844· first seen 2026-08-23 - Zusy - contacted ·
48bfcf090b3ce5968a22f9fb52e9c67a· first seen 2026-08-23 - Zusy - contacted ·
84522221dc296ac781c071589b27a7fa· first seen 2026-08-23 - Beebone - contacted ·
f633d1fd5b92c2ae34627587b3cf14ea· first seen 2026-08-23
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 23.46.10.55 - AS20940 Akamai Technologies, Inc. (Australia)
Observed indicators
- aefd.nelreports.net
- 23.46.10.55
- https://aefd.nelreports.net/
Other scans of aefd.nelreports.net (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 23 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
Questions about aefd.nelreports.net
- Is aefd.nelreports.net safe?
- The scan of aefd.nelreports.net on 24 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with aefd.nelreports.net?
- 117 analysed samples communicate with this URL, including Juko, Zusy, Gootloader, Generickdz.
- How was aefd.nelreports.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of aefd.nelreports.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan