apt-booking.progfeel.co.in - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned apt-booking.progfeel.co.in and returned a suspicious verdict (score 22), categorised as credential-harvest. The page resolved to 103.158.54.95 on Infodex Solutions Pvt. Ltd. in IN. The domain was registered 3965 days ago through #1 Indian Domains dba Mitsu.in. 5 domains and 5 IPs were contacted, over 21 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 22) · Confidence 31%
- Scanned URL:
https://apt-booking.progfeel.co.in/account/login/?next=/ - Domain: apt-booking.progfeel.co.in · IP: 103.158.54.95 · AS141338 · IN
- Server: Apache/2.4.52 (Ubuntu)
- Page title: Appointment Booking Login
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: #1 Indian Domains dba Mitsu.in · domain age 3965 days · created 2015-10-13
- Registrant country: IN
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 20 02: · subject CN=apt-booking.progfeel.co.in
- Evidenced operator: SplendorNet Technologies
- HTTP requests captured: 21 · cookies set: 1 · outgoing links: 1
- Scan tier: standard · observed 2026-08-22 05:20:53 UTC
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Detected technologies
- Apache
- Bootstrap
Contacted infrastructure
- 103.158.54.95 - AS141338 Infodex Solutions Pvt. Ltd. (India)
- 104.17.24.14 - AS13335 Cloudflare, Inc. (United States)
- 142.250.207.3 - AS15169 Google LLC (Japan)
Observed indicators
- apt-booking.progfeel.co.in
- cdn.jsdelivr.net
- cdnjs.cloudflare.com
- fonts.googleapis.com
- fonts.gstatic.com
- 103.158.54.95
- 151.101.193.229
- 104.17.24.14
- 142.250.183.42
- 142.250.207.3
- https://apt-booking.progfeel.co.in/account/login/?next=/
- https://apt-booking.progfeel.co.in/static/assets/images/dreamwork-logo.png
- https://cdn.jsdelivr.net/npm/bootstrap@5.0.2/dist/css/bootstrap.min.css
- https://apt-booking.progfeel.co.in/static/assets/js/hyper-config.js
- https://apt-booking.progfeel.co.in/static/assets/css/app-saas.min.css
- https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.6.0/css/all.min.css
- https://cdnjs.cloudflare.com/ajax/libs/aos/2.3.4/aos.css
- https://fonts.googleapis.com/css2?family=Poppins:wght@400;500;600;700;800&display=swap
- https://apt-booking.progfeel.co.in/media/favicon.png
- https://apt-booking.progfeel.co.in/static/css/custom.css
Questions about apt-booking.progfeel.co.in
- Is apt-booking.progfeel.co.in safe?
- No. MalwareAnalyzer scanned apt-booking.progfeel.co.in on 22 Aug 2026 and returned a suspicious verdict with a score of 22 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- How was apt-booking.progfeel.co.in checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of apt-booking.progfeel.co.in
Scanned on MalwareAnalyzer by Cyble · Open interactive scan