balcimimarlik.com - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned balcimimarlik.com and returned a suspicious verdict (score 42). The page resolved to 104.21.60.249 on Cloudflare, Inc. in US. The domain was registered 3303 days ago through ODTU Gelistirme Vakfi Bilgi Teknolojileri Sanayi Ve Ticaret Anonim Sirketi. 1 domain and 2 IPs were contacted. 2 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 42) · Confidence 51%
- Scanned URL:
http://balcimimarlik.com/resimler/files/68912659687.pdf - Domain: balcimimarlik.com · IP: 104.21.60.249 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · application/pdf
- Registrar: ODTU Gelistirme Vakfi Bilgi Teknolojileri Sanayi Ve Ticaret Anonim Sirketi · domain age 3303 days · created 2017-08-03
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Oct 2 05: · subject CN=balcimimarlik.com
- Scan tier: standard · observed 2026-08-19 18:06:19 UTC
Redirect chain
http://balcimimarlik.com/resimler/files/68912659687.pdfhttps://balcimimarlik.com/resimler/files/68912659687.pdf
Malware communicating with this URL (2)
These samples were observed contacting or being served from balcimimarlik.com. Each links to its full analysis.
- Phishing - referenced ·
31f18e54adef213a861fc7b74c1ddd08· first seen 2026-08-14 - Phishing - referenced ·
170d9b28f1974855ffb1fc01e76cf77e· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- File download routed to the malware sandbox (68912659687.pdf)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.21.60.249 - AS13335 Cloudflare, Inc. (United States)
- 172.67.203.25 - AS13335 Cloudflare, Inc. (United States)
Files served by this page
- 68912659687.pdf ·
eea467d0865161db6e42f9d12b0e4330
Observed indicators
- balcimimarlik.com
- 104.21.60.249
- 172.67.203.25
- https://balcimimarlik.com/resimler/files/68912659687.pdf
Other scans of balcimimarlik.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - suspicious
- 19 Aug 2026 - suspicious
- 13 Aug 2026 - suspicious ·
https://balcimimarlik.com/resimler/files/93531662247.pdf - 13 Aug 2026 - suspicious ·
https://balcimimarlik.com/resimler/files/93531662247.pdf
Questions about balcimimarlik.com
- Is balcimimarlik.com safe?
- No. MalwareAnalyzer scanned balcimimarlik.com on 19 Aug 2026 and returned a suspicious verdict with a score of 42 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with balcimimarlik.com?
- 2 analysed samples communicate with this URL, including Phishing.
- How was balcimimarlik.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of balcimimarlik.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan