demo3.milkmaid.it - suspicious URL scan, 20 Aug 2026

MalwareAnalyzer by Cyble scanned demo3.milkmaid.it and returned a suspicious verdict (score 24), categorised as credential-harvest. The page resolved to 51.89.21.114 on OVH GmbH in DE. 3 domains and 1 IP were contacted, over 8 HTTP requests. 1 malware sample communicates with this URL. The request followed 2 redirects before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.

Scan result

Redirect chain

  1. https://demo3.milkmaid.it/
  2. http://demo3.milkmaid.it/
  3. http://demo3.milkmaid.it/login

Malware communicating with this URL (1)

These samples were observed contacting or being served from demo3.milkmaid.it. Each links to its full analysis.

Antivirus & YARA (0 of 47 engines)

No engine flagged this page's content.

Categories

Why this verdict

Detected technologies

Contacted infrastructure

Observed indicators

Questions about demo3.milkmaid.it

Is demo3.milkmaid.it safe?
No. MalwareAnalyzer scanned demo3.milkmaid.it on 20 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
What malware is associated with demo3.milkmaid.it?
1 analysed samples communicate with this URL.
How was demo3.milkmaid.it checked?
A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.

Scanned at the fast tier - see how URL scanning works.

Scan another URL · Latest analyzed threats · All scans of demo3.milkmaid.it

Scanned on MalwareAnalyzer by Cyble · Open interactive scan