apiok.ru - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned apiok.ru and returned a suspicious verdict (score 28). The page resolved to 5.61.23.12 on Odnoklassniki Services in RU. 3 domains and 2 IPs were contacted, over 1 HTTP request. 2 malware samples communicate with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://connect.ok.ru/ - Domain: apiok.ru · IP: 5.61.23.12 · AS47764 · RU
- Server: Apache
- Page title: ОК для сайтов
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=GR, O=Hellenic Academic and Research Institutions CA, CN=HARICA DV TLS RSA · valid to Feb 7 14: · subject CN=*.apiok.ru
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-22 02:57:51 UTC
Redirect chain
https://connect.ok.ru/https://apiok.ru/ext/
Malware communicating with this URL (2)
These samples were observed contacting or being served from apiok.ru. Each links to its full analysis.
- 01ce80d25811e30901d314f8bb27596feed6d2f487533c4d7061158e0bb7f6fe - referenced ·
01ce80d25811e30901d314f8bb27596f· first seen 2026-08-22 - 3d8b407f6823d3b9dfb08ec1de5362790fc714ce995fafe755483c7e46b12348 - referenced ·
3d8b407f6823d3b9dfb08ec1de536279· first seen 2026-08-20
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Apache
- Google Analytics
Contacted infrastructure
- 5.61.23.12 - AS47764 Odnoklassniki Services (Russian Federation)
- 217.20.147.3 - AS47764 Odnoklassniki Services (Russian Federation)
Observed indicators
- apiok.ru
- top-fwz1.mail.ru
- mc.yandex.ru
- 5.61.23.12
- 217.20.147.3
- https://apiok.ru/ext/
- https://apiok.ru/res/img/favicon.png
- https://apiok.ru/assets/main.css
- https://apiok.ru/assets/app.js
- https://apiok.ru/
- https://apiok.ru/apps/
- https://apiok.ru/dev/
- https://apiok.ru/res/img/ru_flag.png
- https://apiok.ru/en/ext/
- https://apiok.ru/res/img/en_flag.png
- https://apiok.ru/search
- https://apiok.ru/ext/like
- https://apiok.ru/ext/group
- https://apiok.ru/ext/profile
- https://apiok.ru/ext/publish
Questions about apiok.ru
- Is apiok.ru safe?
- No. MalwareAnalyzer scanned apiok.ru on 22 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with apiok.ru?
- 2 analysed samples communicate with this URL.
- How was apiok.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of apiok.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan