autodiscover.ruangapple.id - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned autodiscover.ruangapple.id and returned a malicious verdict (score 100), categorised as phishing. The page resolved to 162.244.93.81 on Webhosting Holdings LLC in US. The domain was registered 1316 days ago through PT Perdana Citra Komputer Indonesia (DACENI). 1 domain and 1 IP were contacted, over 21 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 100) · Confidence 100%
- Scanned URL:
https://autodiscover.ruangapple.id/interface/root - Domain: autodiscover.ruangapple.id · IP: 162.244.93.81 · AS46824 · US
- Server: nginx/1.22.1
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: PT Perdana Citra Komputer Indonesia (DACENI) · domain age 1316 days · created 2023-01-13
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 18 05: · subject CN=autodiscover.ruangapple.id
- HTTP requests captured: 21 · outgoing links: 1
- Scan tier: standard · observed 2026-08-21 16:22:24 UTC
Antivirus & YARA (3 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
Categories
- phishing
Why this verdict
- 3 antivirus/YARA engines flagged the page content: JPCERT_LODEINFO, SOPHOS_Gootloader_JS, DLV_HTML_Smuggling
- Domain impersonates apple (combosquat)
- Certificate issued < 48h ago
Detected technologies
- Nginx
Contacted infrastructure
- 162.244.93.81 - AS46824 Webhosting Holdings LLC (United States)
Observed indicators
- autodiscover.ruangapple.id
- 162.244.93.81
- https://autodiscover.ruangapple.id/interface/root
- https://autodiscover.ruangapple.id/favicon.ico
- https://autodiscover.ruangapple.id/interface/output/fonts/roboto/roboto.css
- https://autodiscover.ruangapple.id/interface/output/login-v-639096288240000000.min.css
- https://autodiscover.ruangapple.id/interface/output/fonts/font-awesome/css/font-awesome.css
- https://autodiscover.ruangapple.id/interface/output/angular-v-639096288240000000.js
- https://autodiscover.ruangapple.id/interface/output/vendor-v-639096288240000000.js
- https://autodiscover.ruangapple.id/interface/output/site-v-639096288240000000.js
- https://autodiscover.ruangapple.id/interface/output/site-v-639096288240000000.templates.js
Questions about autodiscover.ruangapple.id
- Is autodiscover.ruangapple.id safe?
- No. MalwareAnalyzer scanned autodiscover.ruangapple.id on 21 Aug 2026 and returned a malicious verdict with a score of 100 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was autodiscover.ruangapple.id checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of autodiscover.ruangapple.id
Scanned on MalwareAnalyzer by Cyble · Open interactive scan