be-now.pl - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned be-now.pl and returned a malicious verdict (score 56), categorised as credential-harvest. The page resolved to 85.128.168.233 on webhosting servers in PL. The domain was registered 4852 days ago through nazwa.pl sp. z o.o.. 1 domain and 1 IP were contacted, over 6 HTTP requests. 1 malware sample communicates with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 56) · Confidence 65%
- Scanned URL:
http://be-now.pl/userfiles/file/38967678422.pdf - Domain: be-now.pl · IP: 85.128.168.233 · AS15967 · PL
- Server: Apache/2
- Page title: Skup Kamienic
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: nazwa.pl sp. z o.o. · domain age 4852 days · created 2013-05-09
- Registrant country: pl
- Evidenced operator: Be-Now Sp. z o.o.
- HTTP requests captured: 6
- Scan tier: standard · observed 2026-08-21 13:25:51 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from be-now.pl. Each links to its full analysis.
- Phishing - referenced ·
05c98efdcc0abc978e29c5fea14caf0f· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Apache
- jQuery
Contacted infrastructure
- 85.128.168.233 - AS15967 webhosting servers (Poland)
Observed indicators
- be-now.pl
- 85.128.168.233
- http://be-now.pl/userfiles/file/38967678422.pdf
- http://be-now.pl/
- http://be-now.pl/templates-repository/scripts/923/images/fav.ico
- http://be-now.pl/templates-repository/scripts/923/style/foundation.css
- http://be-now.pl/common/css/font-Lato-Light.css
- http://be-now.pl/templates-repository/scripts/923/style/style8.css
- http://be-now.pl/templates-repository/scripts/923/style/style.css
- http://be-now.pl/common/js/jquery-2.1.3.js
- http://be-now.pl/templates-repository/scripts/923/js/modernizr.custom.js
- http://be-now.pl/templates-repository/scripts/923/js/wiz.js
- http://be-now.pl/templates-repository/scripts/923/js/library/classie.js
- http://be-now.pl/templates-repository/scripts/923/images/linia1.png
- http://be-now.pl/templates-repository/scripts/923/images/linia2.png
- http://be-now.pl/templates-repository/scripts/923/js/waypoints.min.js
- http://be-now.pl/templates-repository/scripts/923/js/demo1.js
Other scans of be-now.pl (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - malicious
Questions about be-now.pl
- Is be-now.pl safe?
- No. MalwareAnalyzer scanned be-now.pl on 21 Aug 2026 and returned a malicious verdict with a score of 56 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with be-now.pl?
- 1 analysed samples communicate with this URL, including Phishing.
- How was be-now.pl checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of be-now.pl
Scanned on MalwareAnalyzer by Cyble · Open interactive scan