comlark.ru - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned comlark.ru and returned a suspicious verdict (score 48). The page resolved to 89.253.238.10. 4 domains and 1 IP were contacted, over 34 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 48) · Confidence 54%
- Scanned URL:
http://comlark.ru/userfiles/files/55632013430.pdf - Domain: comlark.ru · IP: 89.253.238.10
- Server: nginx
- Page title: Страница не найдена
- HTTP status: 404 · text/html; charset=windows-1251
- TLS issuer: C=US, O=Let's Encrypt, CN=R10 · valid to Apr 3 17: · subject CN=comlark.ru
- HTTP requests captured: 34
- Scan tier: standard · observed 2026-08-20 01:21:08 UTC
Redirect chain
http://comlark.ru/userfiles/files/55632013430.pdfhttps://comlark.ru/userfiles/files/55632013430.pdf
Malware communicating with this URL (1)
These samples were observed contacting or being served from comlark.ru. Each links to its full analysis.
- Phishing - referenced ·
cd883aa14779db87c1faf9a4d98974fd· first seen 2026-08-17
Antivirus & YARA (1 of 47 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Untrusted certificate (CERT_HAS_EXPIRED)
Detected technologies
- Nginx
- PHP
- Google Analytics
- jQuery
Contacted infrastructure
- 89.253.238.10 - AS41535 MNT-RUSONYX (RU)
Observed indicators
- comlark.ru
- mc.yandex.ru
- komlark.ru
- www.googletagmanager.com
- 89.253.238.10
- https://comlark.ru/userfiles/files/55632013430.pdf
- https://comlark.ru/favicon.ico?v=1661852150?v=1661852150
- https://comlark.ru/bitrix/js/ui/design-tokens/dist/ui.design-tokens.css?168796199924720
- https://comlark.ru/bitrix/js/ui/fonts/opensans/ui.font.opensans.css?16879618942555
- https://comlark.ru/bitrix/js/main/popup/dist/main.popup.bundle.css?168796203829861
- https://comlark.ru/bitrix/js/main/core/css/core_date.css?168796196010481
- https://comlark.ru/local/templates/dresscode/fonts/roboto/roboto.css?16618521502457
- https://comlark.ru/local/templates/dresscode/themes/white/mint/style.css?166185215042760
- https://comlark.ru/bitrix/templates/dresscode/headers/header5/css/style.css?165701193314835
- https://comlark.ru/bitrix/panel/main/popup.css?168796196722696
- https://comlark.ru/local/templates/dresscode/headers/header5/css/style.css?166185215014835
- https://comlark.ru/local/templates/dresscode/headers/header5/css/types/type1.css?166185215072
- https://comlark.ru/bitrix/components/dresscode/sale.geo.positiion/templates/.default/style.css?165701179214130
- https://comlark.ru/local/templates/dresscode/components/bitrix/menu/topMenu4/style.css?1661852150690
- https://comlark.ru/local/templates/dresscode/components/bitrix/form.result.new/modal/style.css?166185215010985
Questions about comlark.ru
- Is comlark.ru safe?
- No. MalwareAnalyzer scanned comlark.ru on 20 Aug 2026 and returned a suspicious verdict with a score of 48 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with comlark.ru?
- 1 analysed samples communicate with this URL, including Phishing.
- How was comlark.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of comlark.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan