bestofbucerias.com - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned bestofbucerias.com and returned a unknown verdict (score 0). The page resolved to 70.38.97.25 on Leaseweb Canada Inc. in CA. 5 domains and 1 IP were contacted, over 6 HTTP requests. 3 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 6%
- Scanned URL:
https://bestofbucerias.com/upload/file/70071382171.pdf - Domain: bestofbucerias.com · IP: 70.38.97.25 · AS32613 · CA
- Page title: Page not found – Best of Bucerias
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Oct 25 13: · subject CN=*.bestofbucerias.com
- HTTP requests captured: 6
- Scan tier: standard · observed 2026-08-20 05:24:57 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from bestofbucerias.com. Each links to its full analysis.
- Phishing - referenced ·
c0b0208f30ee8a2d628b439583a7a066· first seen 2026-08-15 - Phishing - referenced ·
99ebf1c90bab554701c5d19542264a8e· first seen 2026-08-14 - Phishing - referenced ·
68eb4d1e9d63996528e6a5cbb9688325· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- PHP
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 70.38.97.25 - AS32613 Leaseweb Canada Inc. (Canada)
Observed indicators
- bestofbucerias.com
- www.googletagmanager.com
- fonts.googleapis.com
- www.facebook.com
- www.instagram.com
- 70.38.97.25
- https://bestofbucerias.com/upload/file/70071382171.pdf
- https://www.googletagmanager.com/
- https://fonts.googleapis.com/
- https://bestofbucerias.com/feed/
- https://bestofbucerias.com/comments/feed/
- https://bestofbucerias.com/events/?ical=1
- https://www.googletagmanager.com/gtag/js?id=G-86TY2486MB
- https://bestofbucerias.com/upload/file/page_view
- https://bestofbucerias.com/upload/file/timing
- https://bestofbucerias.com/wp-content/litespeed/ucss/ab08ab716f881d92287d1904dbdbedb1.css?ver=dc60c
- https://bestofbucerias.com/wp-content/plugins/litespeed-cache/assets/js/css_async.min.js
- https://bestofbucerias.com/wp-content/plugins/google-analytics-for-wordpress/assets/js/frontend-gtag.min.js?ver=10.2.2
- https://bestofbucerias.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.googletagmanager.com/gtag/js?id=GT-PHWNDVM3
Other scans of bestofbucerias.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 14 Aug 2026 - unknown ·
https://bestofbucerias.com/upload/file/jivitojuj.pdf - 14 Aug 2026 - unknown ·
https://bestofbucerias.com/upload/file/jivitojuj.pdf
Questions about bestofbucerias.com
- Is bestofbucerias.com safe?
- The scan of bestofbucerias.com on 20 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with bestofbucerias.com?
- 3 analysed samples communicate with this URL, including Phishing.
- How was bestofbucerias.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of bestofbucerias.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan