booking.revenuediscovery.com - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned booking.revenuediscovery.com and returned a suspicious verdict (score 36). The page resolved to 178.128.57.27 on DigitalOcean, LLC in SG. The domain was registered 2090 days ago through Web Commerce Communications Limited dba WebNic.cc. 3 domains and 3 IPs were contacted, over 13 HTTP requests. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 36) · Confidence 45%
- Scanned URL:
https://booking.revenuediscovery.com/ - Domain: booking.revenuediscovery.com · IP: 178.128.57.27 · AS14061 · SG
- Server: nginx-rc
- Page title: RD Booking Hub - Resource Booking System
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: Web Commerce Communications Limited dba WebNic.cc · domain age 2090 days · created 2020-12-01
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 21 02: · subject CN=booking.revenuediscovery.com
- HTTP requests captured: 13 · cookies set: 2 · outgoing links: 76
- Scan tier: standard · observed 2026-08-23 04:31:40 UTC
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Detected technologies
- Nginx
- Bootstrap
Contacted infrastructure
- 178.128.57.27 - AS14061 DigitalOcean, LLC (Singapore)
- 103.180.114.1 - AS200325 BUNNYWAY, informacijske storitve d.o.o (Australia)
- 104.17.207.5 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- booking.revenuediscovery.com
- fonts.bunny.net
- cdn.jsdelivr.net
- 178.128.57.27
- 103.180.114.1
- 104.17.207.5
- https://booking.revenuediscovery.com/
- https://booking.revenuediscovery.com/images/logo/rd-logo.png
- https://fonts.bunny.net/
- https://fonts.bunny.net/css?family=inter:400,500,600,700,800&display=swap
- https://cdn.jsdelivr.net/npm/bootstrap@5.3.2/dist/css/bootstrap.min.css
- https://booking.revenuediscovery.com/build/assets/app-COuBJtvq.js
- https://booking.revenuediscovery.com/public-cart
- https://booking.revenuediscovery.com/login
- https://booking.revenuediscovery.com/storage/resources/uFt9UYCytVH7js7AqJoA6SSrKz6cMNFjaHQzsDPh.jpg
- https://booking.revenuediscovery.com/storage/resources/ER2VfVcC1zrjaQkJtaPW04USckIgmUMAJNzw9Gi6.jpg
- https://booking.revenuediscovery.com/images/asset%20photo/Aset%20Marketing/BOX%20BACKGROUND/BOX%20BACKGROUND.jpg
- https://booking.revenuediscovery.com/images/asset%20photo/Aset%20Marketing/CAMERA%202%20(CANON%20G7X%20MARK%20iii)/BODY%20CAMERA.png
- https://booking.revenuediscovery.com/images/asset%20photo/Aset%20Marketing/CAMERA%203%20(CANON%20EOS%20M50%20MARK%20ii)/BODY%20CAMERA.jpg
- https://booking.revenuediscovery.com/images/asset%20photo/Aset%20Marketing/CLAPPER/CLAPPER.jpg
Questions about booking.revenuediscovery.com
- Is booking.revenuediscovery.com safe?
- No. MalwareAnalyzer scanned booking.revenuediscovery.com on 23 Aug 2026 and returned a suspicious verdict with a score of 36 out of 100. Treat it as hostile until it is re-checked.
- How was booking.revenuediscovery.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of booking.revenuediscovery.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan