alenakovalchuk.ru - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned alenakovalchuk.ru and returned a suspicious verdict (score 54). The page resolved to 87.236.16.248 on Beget Ltd in RU. 1 domain and 1 IP were contacted. 17 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 54) · Confidence 60%
- Scanned URL:
https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/9cf6f6ecd27aa8e7b01229d78f2d5b0a/97971247550.pdf - Domain: alenakovalchuk.ru · IP: 87.236.16.248 · AS198610 · RU
- Server: nginx-reuseport/1.21.1
- HTTP status: 200 · application/pdf
- Scan tier: fast · observed 2026-08-21 01:46:32 UTC
Malware communicating with this URL (17)
These samples were observed contacting or being served from alenakovalchuk.ru. Each links to its full analysis.
- Phishing - referenced ·
e237ca62c349508c1e6873c0bcd1b710· first seen 2026-08-21 - Phishing - referenced ·
910847a10b8af5079b0549fb9722d82f· first seen 2026-08-20 - Phishing - referenced ·
9acb04775a1e9f5469a60c2483fdf6bf· first seen 2026-08-19 - Phishing - referenced ·
e47fa93f5535ebe19c476d22f44ad023· first seen 2026-08-17 - Phishing - referenced ·
45a32255686494ba1cac9803a734b7ab· first seen 2026-08-17 - Phishing - referenced ·
b5f8e9e8e7dce56b412a5b61599982ee· first seen 2026-08-17 - Phishing - referenced ·
90ec2e2099d50c43b22e572db6329723· first seen 2026-08-16 - Phishing - referenced ·
93dc882d9bf757547ce6575306ecde54· first seen 2026-08-16 - Phishing - referenced ·
1c6a0d6aea0d1cb4f55483fde14e045e· first seen 2026-08-16 - Phishing - referenced ·
140adc74f17c10cc54e05aca5184c710· first seen 2026-08-15 - Phishing - referenced ·
e60f33d04c8de6d18d9b321799d968da· first seen 2026-08-15 - Phishing - referenced ·
2dbcda817e2d79d14346fb439087eee5· first seen 2026-08-15 - Phishing - referenced ·
1f114c13ed029c5344a265550caf7f75· first seen 2026-08-13 - Phishing - referenced ·
829d25a507d7b748db4acf51605cdf50· first seen 2026-08-13 - Phishing - referenced ·
1611cfd072afbbb3bd214e33d9305b3d· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- File download routed to the malware sandbox (97971247550.pdf)
Detected technologies
- Nginx
Contacted infrastructure
- 87.236.16.248 - AS198610 Beget Ltd (Russian Federation)
Files served by this page
- 97971247550.pdf ·
62cac3ecd9e2e4c4ad82fe7082cab0e5
Observed indicators
- alenakovalchuk.ru
- 87.236.16.248
- https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/9cf6f6ecd27aa8e7b01229d78f2d5b0a/97971247550.pdf
Other scans of alenakovalchuk.ru (6)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 17 Aug 2026 - suspicious ·
https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/743a7c4a738fb84244c48d780 - 16 Aug 2026 - suspicious ·
https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/61167ccdb52c94ac5dffdaf43 - 15 Aug 2026 - suspicious ·
https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/06d58007f5a1968a2ab0e2667 - 15 Aug 2026 - suspicious ·
https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/aa4ee52eafb9d68b375fb5c29 - 13 Aug 2026 - suspicious ·
https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/81d5a232a7f3f2ed138bc7010 - 12 Aug 2026 - suspicious ·
https://alenakovalchuk.ru/wp-content/plugins/super-forms/uploads/php/files/7d4be31eed581f6fc14c6bdbb
Questions about alenakovalchuk.ru
- Is alenakovalchuk.ru safe?
- No. MalwareAnalyzer scanned alenakovalchuk.ru on 21 Aug 2026 and returned a suspicious verdict with a score of 54 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with alenakovalchuk.ru?
- 17 analysed samples communicate with this URL, including Phishing.
- How was alenakovalchuk.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of alenakovalchuk.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan