ambrose.edu - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned ambrose.edu and returned a suspicious verdict (score 36). The page resolved to 159.198.75.135 on Namecheap, Inc. in US. 8 domains and 1 IP were contacted, over 8 HTTP requests. 69 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 36) · Confidence 45%
- Scanned URL:
https://ambrose.edu/sites/default/files/webform/ginigiwosumomigari.pdf - Domain: ambrose.edu · IP: 159.198.75.135 · AS22612 · US
- Server: Apache
- Page title: Page not found - Ambrose University
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 16 21: · subject CN=www.ambrose.edu
- HTTP requests captured: 8
- Scan tier: standard · observed 2026-08-19 17:57:12 UTC
Malware communicating with this URL (69)
These samples were observed contacting or being served from ambrose.edu. Each links to its full analysis.
- Phishing - referenced ·
b02aa81f3e6375f0396c42478bd6d7f9· first seen 2026-08-17 - Phishing - referenced ·
97b3de999153537586962b7b0c02c757· first seen 2026-08-17 - Phishing - referenced ·
b3b61e320ae1587278f78ec18fbdbc82· first seen 2026-08-16 - Phishing - referenced ·
dba15238de053848682682616a279824· first seen 2026-08-16 - Phishing - referenced ·
bf8752c6399d58e90decae36fea50cdc· first seen 2026-08-16 - Phishing - referenced ·
be2d520e95b4c39834c2d8dc2154b721· first seen 2026-08-16 - Phishing - referenced ·
77ff28d7436806887f847df418bfdf2c· first seen 2026-08-16 - Phishing - referenced ·
a292c76501c163b993af966364ca747d· first seen 2026-08-16 - Phishing - referenced ·
18c25db6ced31ccd053c87e4e6d5b07d· first seen 2026-08-16 - Phishing - referenced ·
2cfe3efaa330108bb8feb87f11c04f3d· first seen 2026-08-16 - Phishing - referenced ·
159d66ac41ea7fed6e51243378297013· first seen 2026-08-16 - Phishing - referenced ·
2c12a5f0d8145a3031a38dab42f38575· first seen 2026-08-16 - Phishing - referenced ·
cee6827f91eca36a8c0e7a03ecceb886· first seen 2026-08-16 - Phishing - referenced ·
5b32730ec32c848fd9cb2f2c6fa55d98· first seen 2026-08-16 - Phishing - referenced ·
f77f510ec27437c9ee09bd7a04f3faa1· first seen 2026-08-16
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Detected technologies
- Apache
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 159.198.75.135 - AS22612 Namecheap, Inc. (United States)
Observed indicators
- ambrose.edu
- gmpg.org
- www.googletagmanager.com
- fonts.googleapis.com
- cdn.jsdelivr.net
- fonts.gstatic.com
- ambrose-cdn.com
- cookiedatabase.org
- 159.198.75.135
- https://ambrose.edu/sites/default/files/webform/ginigiwosumomigari.pdf
- http://gmpg.org/xfn/11
- https://www.googletagmanager.com/gtm.js?id=
- https://fonts.googleapis.com/
- https://cdn.jsdelivr.net/
- https://www.googletagmanager.com/
- https://ambrose.edu/wp-content/cache/wpo-minify/1787075278/assets/wpo-minify-header-sr7css1756711874.min.css
- https://ambrose.edu/wp-content/plugins/complianz-gdpr/assets/css/cookieblocker.min.css?ver=1782751218
- https://ambrose.edu/wp-content/cache/wpo-minify/1787075278/assets/wpo-minify-header-tailpress-app1781731021.min.css
- https://ambrose.edu/wp-content/cache/wpo-minify/1787075278/assets/wpo-minify-header-ambrose-google-fonts.min.css
- https://cdn.jsdelivr.net/npm/remixicon@4.7.0/fonts/remixicon.css?ver=4.7.0
Other scans of ambrose.edu (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/nakevatekiviva.pdf - 19 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/zateguzafafidefezibexe.pdf - 19 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/nakevatekiviva.pdf - 17 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/nakevatekiviva.pdf - 17 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/nakevatekiviva.pdf - 17 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/tinijozude.pdf - 16 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/kepasibadugemefobovabo.pdf - 16 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/tinijozude.pdf - 16 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/tinijozude.pdf - 16 Aug 2026 - suspicious ·
https://ambrose.edu/sites/default/files/webform/21691652676.pdf
Questions about ambrose.edu
- Is ambrose.edu safe?
- No. MalwareAnalyzer scanned ambrose.edu on 19 Aug 2026 and returned a suspicious verdict with a score of 36 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with ambrose.edu?
- 69 analysed samples communicate with this URL, including Phishing.
- How was ambrose.edu checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of ambrose.edu
Scanned on MalwareAnalyzer by Cyble · Open interactive scan