b2c.bookingo.net - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned b2c.bookingo.net and returned a malicious verdict (score 85). The page resolved to 185.158.133.1 on Internet Utilities Europe and Asia Limited in PL. 4 domains and 4 IPs were contacted, over 37 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 85) · Confidence 94%
- Scanned URL:
https://b2c.bookingo.net/ - Domain: b2c.bookingo.net · IP: 185.158.133.1 · AS13335 · PL
- Server: cloudflare
- Page title: SAHAB SCANNER - Comparateur de Vols Algérie
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 17 22: · subject CN=b2c.bookingo.net
- HTTP requests captured: 37 · cookies set: 3 · outgoing links: 4
- Scan tier: standard · observed 2026-08-20 04:06:19 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Runtime data beacon to rahjlclamzxktmgafsah.supabase.co
- Certificate issued < 48h ago
Detected technologies
- Cloudflare
Contacted infrastructure
- 185.158.133.1 - AS13335 Internet Utilities Europe and Asia Limited (Poland)
- 172.217.25.195 - AS15169 Google LLC (Malaysia)
Observed indicators
- b2c.bookingo.net
- rahjlclamzxktmgafsah.supabase.co
- www.gstatic.com
- images.unsplash.com
- 185.158.133.1
- 104.18.38.10
- 151.101.30.208
- 172.217.25.195
- https://b2c.bookingo.net/
- https://b2c.bookingo.net/assets/index-NVzB0a0X.js
- https://b2c.bookingo.net/assets/index-CIPBy7Cr.css
- https://b2c.bookingo.net/~flock.js
Questions about b2c.bookingo.net
- Is b2c.bookingo.net safe?
- No. MalwareAnalyzer scanned b2c.bookingo.net on 20 Aug 2026 and returned a malicious verdict with a score of 85 out of 100. Treat it as hostile until it is re-checked.
- How was b2c.bookingo.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of b2c.bookingo.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan