biznesfishki.ru - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned biznesfishki.ru and returned a unknown verdict (score -2), categorised as credential-harvest. The page resolved to 5.188.159.148 on Selectel Network in RU. 15 domains and 1 IP were contacted, over 53 HTTP requests. 3 malware samples communicate with this URL (Phishing). The request followed 2 redirects before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -2) · Confidence 8%
- Scanned URL:
http://biznesfishki.ru/files/userfiles/files/91386590928.pdf - Domain: biznesfishki.ru · IP: 5.188.159.148 · AS49505 · RU
- Server: nginx/1.30.3
- Page title: Бизнесфишки - мягкое мороженое, фризеры и смеси для мягкого мороженого
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 12 22: · subject CN=biznesfishki.ru
- HTTP requests captured: 53
- Scan tier: standard · observed 2026-08-24 08:55:06 UTC
Redirect chain
http://biznesfishki.ru/files/userfiles/files/91386590928.pdfhttps://biznesfishki.ru/files/userfiles/files/91386590928.pdfhttps://biznesfishki.ru/
Malware communicating with this URL (3)
These samples were observed contacting or being served from biznesfishki.ru. Each links to its full analysis.
- Phishing - referenced ·
a5177ad6810fab0aa92ccb079d36b0e2· first seen 2026-08-22 - Phishing - referenced ·
d24e79b0473134681381754034423e66· first seen 2026-08-20 - Phishing - referenced ·
4f63b882ff60071a7e2cdf7b4d8b3358· first seen 2026-08-13
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
Detected technologies
- Nginx
- PHP
- WordPress
- jQuery
Contacted infrastructure
- 5.188.159.148 - AS49505 Selectel Network (Russian Federation)
Observed indicators
- biznesfishki.ru
- ai-up.ru
- script.marquiz.ru
- www.google.com
- mc.yandex.ru
- fonts.googleapis.com
- fonts.gstatic.com
- cdn.jsdelivr.net
- t.me
- max.ru
- dzen.ru
- rutube.ru
- www.youtube.com
- sladky-ostrov.ru
- cdn.envybox.io
- 5.188.159.148
- https://biznesfishki.ru/
- https://ai-up.ru/fn/pixel?p=1779779954
- https://script.marquiz.ru/v2.js
- https://www.google.com/
Other scans of biznesfishki.ru (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown
Questions about biznesfishki.ru
- Is biznesfishki.ru safe?
- The scan of biznesfishki.ru on 24 Aug 2026 reached no verdict either way (score -2). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with biznesfishki.ru?
- 3 analysed samples communicate with this URL, including Phishing.
- How was biznesfishki.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of biznesfishki.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan