conrays.ru - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned conrays.ru and returned a suspicious verdict (score 42). The page resolved to 89.111.150.31 on RU-CENTER in RU. 1 domain and 1 IP were contacted. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 42) · Confidence 51%
- Scanned URL:
https://conrays.ru/f/data/91097562908.pdf - Domain: conrays.ru · IP: 89.111.150.31 · AS48287 · RU
- Server: nginx/1.30.4
- HTTP status: 200 · application/pdf
- TLS issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign GCC R3 DV TLS CA 2020 · valid to Nov 7 07: · subject CN=www.conrays.ru
- Scan tier: standard · observed 2026-08-21 01:50:39 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from conrays.ru. Each links to its full analysis.
- Phishing - referenced ·
477d9311663df988fd5678840f4df9f2· first seen 2026-08-16 - Phishing - referenced ·
8192643c2194ed0caefd6e13c44ff9ae· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- File download routed to the malware sandbox (91097562908.pdf)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
Contacted infrastructure
- 89.111.150.31 - AS48287 RU-CENTER (Russian Federation)
Files served by this page
- 91097562908.pdf ·
6c9ac4ed438dee34c1c7e95c7d824e47
Observed indicators
- conrays.ru
- 89.111.150.31
- https://conrays.ru/f/data/91097562908.pdf
Other scans of conrays.ru (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://conrays.ru/f/data/dejububopekukor.pdf
Questions about conrays.ru
- Is conrays.ru safe?
- No. MalwareAnalyzer scanned conrays.ru on 21 Aug 2026 and returned a suspicious verdict with a score of 42 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with conrays.ru?
- 2 analysed samples communicate with this URL, including Phishing.
- How was conrays.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of conrays.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan