dbi-cloud.bwnet.it - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned dbi-cloud.bwnet.it and returned a suspicious verdict (score 36). The page resolved to 23.88.44.251 on Hetzner Online GmbH in DE. 3 domains and 1 IP were contacted, over 26 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 36) · Confidence 45%
- Scanned URL:
https://dbi-cloud.bwnet.it/login - Domain: dbi-cloud.bwnet.it · IP: 23.88.44.251 · AS24940 · DE
- Server: nginx
- Page title: Login – Nextcloud
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 17 21: · subject CN=dbi-cloud.bwnet.it
- HTTP requests captured: 26 · cookies set: 4 · outgoing links: 3
- Scan tier: standard · observed 2026-08-20 08:46:24 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Detected technologies
- Nginx
Contacted infrastructure
- 23.88.44.251 - AS24940 Hetzner Online GmbH (Germany)
Observed indicators
- dbi-cloud.bwnet.it
- www.enable-javascript.com
- nextcloud.com
- 23.88.44.251
- https://dbi-cloud.bwnet.it/login
- https://dbi-cloud.bwnet.it/core/img/favicon.ico
- https://dbi-cloud.bwnet.it/core/img/favicon-touch.png
- https://dbi-cloud.bwnet.it/core/img/favicon-mask.svg
- https://dbi-cloud.bwnet.it/core/img/manifest.json
- https://dbi-cloud.bwnet.it/core/css/server.css?v=2288dd05-27
- https://dbi-cloud.bwnet.it/apps/theming/css/default.css?v=cbb7a98a-27
- https://dbi-cloud.bwnet.it/core/css/guest.css?v=2288dd05-27
- https://dbi-cloud.bwnet.it/dist/core-common.js?v=2288dd05-27
- https://dbi-cloud.bwnet.it/dist/core-main.js?v=2288dd05-27
- https://dbi-cloud.bwnet.it/dist/core-login.js?v=2288dd05-27
- https://dbi-cloud.bwnet.it/apps/theming/js/theming.js?v=2288dd05-27
- https://dbi-cloud.bwnet.it/apps/theming/theme/default.css?plain=1&v=08b6a771
- https://dbi-cloud.bwnet.it/apps/theming/theme/light.css?plain=1&v=08b6a771
- https://dbi-cloud.bwnet.it/apps/theming/theme/dark.css?plain=1&v=08b6a771
- https://dbi-cloud.bwnet.it/apps/theming/theme/light-highcontrast.css?plain=1&v=08b6a771
Questions about dbi-cloud.bwnet.it
- Is dbi-cloud.bwnet.it safe?
- No. MalwareAnalyzer scanned dbi-cloud.bwnet.it on 20 Aug 2026 and returned a suspicious verdict with a score of 36 out of 100. Treat it as hostile until it is re-checked.
- How was dbi-cloud.bwnet.it checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of dbi-cloud.bwnet.it
Scanned on MalwareAnalyzer by Cyble · Open interactive scan