asirius.su - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned asirius.su and returned a unknown verdict (score 16), categorised as credential-harvest. The page resolved to 5.23.50.26 on TimeWeb-AS - JSC _TIMEWEB_, RU in RU. 12 domains and 1 IP were contacted, over 29 HTTP requests. 13 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 16) · Confidence 22%
- Scanned URL:
http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/55a35348f37674b9ec08c44f9d8caa38/78326284716.pdf - Domain: asirius.su · IP: 5.23.50.26 · AS9123 · RU
- Server: nginx/1.30.4
- Page title: Страница не найдена — Асириус
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 29
- Scan tier: fast · observed 2026-08-23 10:07:13 UTC
Malware communicating with this URL (13)
These samples were observed contacting or being served from asirius.su. Each links to its full analysis.
- Phishing - referenced ·
28b10b933cb868f079d020263cf7227f· first seen 2026-08-23 - Phishing - referenced ·
92981ae95ced31f44c2ee3f897285bf2· first seen 2026-08-22 - Phishing - referenced ·
1fecee02c1f4a0f830115b0cfc4848b1· first seen 2026-08-20 - Phishing - referenced ·
65e7375dce566ec03037f184d522ce06· first seen 2026-08-20 - Phishing - referenced ·
09c2bb0fd97c50e21b817c91b5dab281· first seen 2026-08-19 - Phishing - referenced ·
007ccc374f13bb6f5994f2c0f70e6910· first seen 2026-08-16 - Phishing - referenced ·
bbeb3e923f9a081a51479064829e2377· first seen 2026-08-16 - Phishing - referenced ·
cc84c6e2e7ddc46c3f3e3eb9ded07a9f· first seen 2026-08-16 - Phishing - referenced ·
d82d47a354b986d67e23cf858a2fd150· first seen 2026-08-15 - Phishing - referenced ·
9abfe834005b7e55af439e19404e36cd· first seen 2026-08-15 - Phishing - referenced ·
47f6fbc5faece94feeefda0ed0d14925· first seen 2026-08-14 - Phishing - referenced ·
452560f6a0a1fa0047ce065911e5785d· first seen 2026-08-13 - Phishing - referenced ·
7acb12a5369d2d571ca244a97cfbe01a· first seen 2026-08-12
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Nginx
- WordPress
- jQuery
- Bootstrap
Contacted infrastructure
- 5.23.50.26 - AS9123 TimeWeb-AS - JSC _TIMEWEB_, RU (RU)
Observed indicators
- asirius.su
- gmpg.org
- moderate.cleantalk.org
- fonts.googleapis.com
- fonts.gstatic.com
- ajax.googleapis.com
- wa.me
- t.me
- woodmart.xtemos.com
- cdn.jsdelivr.net
- moderate4-v4.cleantalk.org
- mc.yandex.ru
- 5.23.50.26
- http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/55a35348f37674b9ec08c44f9d8caa38/78326284716.pdf
- http://gmpg.org/xfn/11
- http://asirius.su/xmlrpc.php
- http://asirius.su/wp-content/themes/woodmart/js/libs/ie11CustomProperties.min.js
- http://moderate.cleantalk.org/
- http://fonts.googleapis.com/
- https://asirius.su/feed/
Other scans of asirius.su (5)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown ·
http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/978703a4d7b0f117ecfbea5ff2d66e01/ - 20 Aug 2026 - unknown ·
http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/7adda1eed08691c88507ac4b80a4a34a/ - 16 Aug 2026 - unknown ·
http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/91df9f3611f82495779b9161f3e286fa/ - 15 Aug 2026 - unknown ·
http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/17f9e81224b7a3337e1d5e1790d94784/ - 15 Aug 2026 - unknown ·
http://asirius.su/wp-content/plugins/super-forms/uploads/php/files/17f9e81224b7a3337e1d5e1790d94784/
Questions about asirius.su
- Is asirius.su safe?
- The scan of asirius.su on 23 Aug 2026 reached no verdict either way (score 16). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with asirius.su?
- 13 analysed samples communicate with this URL, including Phishing.
- How was asirius.su checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of asirius.su
Scanned on MalwareAnalyzer by Cyble · Open interactive scan