almavilag.hu - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned almavilag.hu and returned a unknown verdict (score 15), categorised as credential-harvest. The page resolved to 185.33.54.9 on DotRoll in HU. 3 domains and 1 IP were contacted, over 43 HTTP requests. 1 malware sample communicates with this URL (Phishing). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 15) · Confidence 24%
- Scanned URL:
https://almavilag.hu/files/files/3831272224.pdf - Domain: almavilag.hu · IP: 185.33.54.9 · AS47381 · HU
- Server: Apache
- Page title: Oldal nem található – AlmaVilág
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 31 18: · subject CN=almavilag.hu
- HTTP requests captured: 43
- Scan tier: standard · observed 2026-08-20 19:30:51 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from almavilag.hu. Each links to its full analysis.
- Phishing - referenced ·
fc745e0580247998d104fa0b5f0f16fe· first seen 2026-08-17
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Matches phishing-kit family "BlackEye"
Detected technologies
- Apache
- WordPress
- React
- jQuery
Contacted infrastructure
- 185.33.54.9 - AS47381 DotRoll (Hungary)
Observed indicators
- almavilag.hu
- gmpg.org
- www.google.com
- 185.33.54.9
- https://almavilag.hu/files/files/3831272224.pdf
- http://gmpg.org/xfn/11
- https://almavilag.hu/xmlrpc.php
- https://almavilag.hu/wp-content/themes/flatsome/assets/js/flatsome.js?ver=e2eddd6c228105dac048
- https://almavilag.hu/wp-content/themes/flatsome/assets/js/chunk.slider.js?ver=3.20.7
- https://almavilag.hu/wp-content/themes/flatsome/assets/js/chunk.popups.js?ver=3.20.7
- https://almavilag.hu/wp-content/themes/flatsome/assets/js/chunk.tooltips.js?ver=3.20.7
- https://almavilag.hu/wp-content/themes/flatsome/assets/js/woocommerce.js?ver=1c9be63d628ff7c3ff4c
- https://almavilag.hu/feed/
- https://almavilag.hu/comments/feed/
- https://almavilag.hu/wp-content/plugins/advanced-coupons-for-woocommerce-free/dist/assets/index-467dde24.css?ver=1782542648
- https://almavilag.hu/wp-content/plugins/advanced-coupons-for-woocommerce-free/dist/assets/index-2a7d8588.css?ver=1782542648
- https://almavilag.hu/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-10.9.1
- https://almavilag.hu/wp-content/plugins/price-list//css/ndpl_style.css?ver=6.9.7
- https://almavilag.hu/wp-content/plugins/free-shipping-label/assets/build/fsl-public.css?ver=3.5.2
- https://almavilag.hu/wp-content/plugins/saferpay_woocommerce_gateway/assets/css/notify.css?ver=1
Other scans of almavilag.hu (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 17 Aug 2026 - unknown ·
https://almavilag.hu/files/files/48080872019.pdf
Questions about almavilag.hu
- Is almavilag.hu safe?
- The scan of almavilag.hu on 20 Aug 2026 reached no verdict either way (score 15). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with almavilag.hu?
- 1 analysed samples communicate with this URL, including Phishing.
- How was almavilag.hu checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of almavilag.hu
Scanned on MalwareAnalyzer by Cyble · Open interactive scan