apkmody.ir - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned apkmody.ir and returned a unknown verdict (score -12). The page resolved to 49.12.129.169 on Hetzner Online GmbH in DE. 1 domain and 1 IP were contacted. 1 malware sample communicates with this URL. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://apkmody.ir/wp-content/themes/NovindownloadV2/css/bootstrap-grid.min.css - Domain: apkmody.ir · IP: 49.12.129.169 · AS24940 · DE
- Page title: 404 Not Found
- HTTP status: 404 · text/html
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Oct 30 13: · subject CN=apkmody.ir
- Scan tier: fast · observed 2026-08-22 10:12:08 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from apkmody.ir. Each links to its full analysis.
- 13593af0fee8da071c7a6fad188b526d1f8e2e3c0f0adc081f886a31a6ea23dc - referenced ·
13593af0fee8da071c7a6fad188b526d· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 49.12.129.169 - AS24940 Hetzner Online GmbH (Germany)
Observed indicators
- apkmody.ir
- 49.12.129.169
- https://apkmody.ir/wp-content/themes/NovindownloadV2/css/bootstrap-grid.min.css
Other scans of apkmody.ir (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown ·
https://apkmody.ir/wp-content/themes/NovindownloadV2/css/style-rtl.alpha6.min.css - 22 Aug 2026 - unknown ·
https://apkmody.ir/wp-content/themes/NovindownloadV2/css/bootstrap-reboot.min.css
Questions about apkmody.ir
- Is apkmody.ir safe?
- The scan of apkmody.ir on 22 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with apkmody.ir?
- 1 analysed samples communicate with this URL.
- How was apkmody.ir checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of apkmody.ir
Scanned on MalwareAnalyzer by Cyble · Open interactive scan