ayurvedaemart.com - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned ayurvedaemart.com and returned a malicious verdict (score 69), categorised as credential-harvest, impersonating binance. The page resolved to 119.18.49.9 on Hostgator Asian Operations Division. in IN. The domain was registered 6392 days ago through GoDaddy.com, LLC. 4 domains and 1 IP were contacted, over 3 HTTP requests. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 69) · Confidence 81%
- Scanned URL:
https://ayurvedaemart.com/uploads/file/64598020074.pdf - Domain: ayurvedaemart.com · IP: 119.18.49.9 · AS394695 · IN
- Server: Apache
- Page title: Ayurvedaemart.com | A complete Online Store for Ayurveda, ayurvedic medicines, Herbal Products, Kerala
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: GoDaddy.com, LLC · domain age 6392 days · created 2009-02-18
- TLS issuer: C=US, O=cPanel, LLC, CN=cPanel ECC Domain Validation Secure Server CA 3 · valid to Oct 27 23: · subject CN=ayurvedaemart.com
- HTTP requests captured: 3
- Scan tier: standard · observed 2026-08-21 04:00:25 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from ayurvedaemart.com. Each links to its full analysis.
- Phishing - referenced ·
12c57499385babfbf8fa252912dd7281· first seen 2026-08-17 - Phishing - referenced ·
5b918e4589ff7477db42f34a07487874· first seen 2026-08-12
Antivirus & YARA (2 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
Categories
- credential-harvest
Why this verdict
- 2 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, JPCERT_LODEINFO
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Matches phishing-kit family "Binance / Crypto Exchange Kit"
Detected technologies
- Apache
- Google Analytics
Contacted infrastructure
- 119.18.49.9 - AS394695 Hostgator Asian Operations Division. (India)
Observed indicators
- ayurvedaemart.com
- fonts.googleapis.com
- fonts.gstatic.com
- www.googletagmanager.com
- 119.18.49.9
- https://ayurvedaemart.com/uploads/file/64598020074.pdf
- https://ayurvedaemart.com/public/uploads/all/izAQX3aB5AhRzEIFa7f6D7gFIHCwZYAO32ns1htu.png
- https://fonts.googleapis.com/
- https://fonts.gstatic.com/
- https://fonts.googleapis.com/css2?family=Public+Sans:ital,wght@0,100;0,200;0,300;0,400;0,500;0,600;0,700;0,800;0,900;1,100;1,200;1,300;1,400;1,500;1,600;1,700;1,800;1,900&display=swap
- https://ayurvedaemart.com/public/assets/css/vendors.css?v=11.1.0
- https://ayurvedaemart.com/public/assets/css/aiz-core.css?v=4989
- https://ayurvedaemart.com/public/assets/css/custom-style.css?v=11.1.0
- https://www.googletagmanager.com/gtag/js?id=
- https://ayurvedaemart.com/public/assets/img/placeholder.jpg
- https://ayurvedaemart.com/public/assets/img/flags/en.png
- https://ayurvedaemart.com/public/assets/img/flags/bd.png
- https://ayurvedaemart.com/public/assets/img/flags/sa.png
- https://ayurvedaemart.com/shops/create
- https://ayurvedaemart.com/seller/login
Other scans of ayurvedaemart.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - malicious
Questions about ayurvedaemart.com
- Is ayurvedaemart.com safe?
- No. MalwareAnalyzer scanned ayurvedaemart.com on 21 Aug 2026 and returned a malicious verdict with a score of 69 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- Does ayurvedaemart.com belong to binance?
- No. This page claims the identity of binance but nothing establishes that binance operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- What malware is associated with ayurvedaemart.com?
- 2 analysed samples communicate with this URL, including Phishing.
- How was ayurvedaemart.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of ayurvedaemart.com · Other binance phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan