bagandpack.ru - URL scan, 14 Aug 2026
MalwareAnalyzer by Cyble scanned bagandpack.ru and returned a unknown verdict (score 12). The page resolved to 45.130.41.32 on Beget LLC in RU. 6 domains and 1 IP were contacted, over 65 HTTP requests. 4 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 14 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 12) · Confidence 15%
- Scanned URL:
http://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/482da384575f4c3cbf97d8b2891d0188/mawixawifidinizajavezim.pdf - Domain: bagandpack.ru · IP: 45.130.41.32 · AS198610 · RU
- Server: nginx-reuseport/1.21.1
- Page title: Страница не найдена – Bag&Pack
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 65
- Scan tier: fast · observed 2026-08-14 10:01:13 UTC
Redirect chain
http://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/482da384575f4c3cbf97d8b2891d0188/mawixawifidinizajavezim.pdfhttps://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/482da384575f4c3cbf97d8b2891d0188/mawixawifidinizajavezim.pdf
Malware communicating with this URL (4)
These samples were observed contacting or being served from bagandpack.ru. Each links to its full analysis.
- Phishing - referenced ·
037cc201781bd332ece59ae1f3dd8c06· first seen 2026-08-14 - Phishing - referenced ·
b21f20a1b4caa00d321d935de3a0726a· first seen 2026-08-13 - Phishing - referenced ·
36cf97f990821d968dfb9394061758cf· first seen 2026-08-13 - Phishing - referenced ·
b5568f1ac65aade52fc0ac0c20e93c9f· first seen 2026-08-13
Antivirus & YARA (1 of 44 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Nginx
- PHP
- WordPress
- jQuery
- Bootstrap
Contacted infrastructure
- 45.130.41.32 - AS198610 Beget LLC (Russian Federation)
Observed indicators
- bagandpack.ru
- developers.google.com
- fonts.googleapis.com
- gmpg.org
- mc.yandex.ru
- www.instagram.com
- 45.130.41.32
- https://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/482da384575f4c3cbf97d8b2891d0188/mawixawifidinizajavezim.pdf
- https://developers.google.com/
- https://fonts.googleapis.com/
- https://bagandpack.ru/feed/
- https://bagandpack.ru/comments/feed/
- https://bagandpack.ru/wp-content/themes/enfold/config-woocommerce/woocommerce-mod.css?ver=6.9.7
- https://bagandpack.ru/wp-content/themes/enfold/css/grid.css?ver=4.5.6
- https://bagandpack.ru/wp-content/themes/enfold/css/base.css?ver=4.5.6
- https://bagandpack.ru/wp-content/themes/enfold/css/layout.css?ver=4.5.6
- https://bagandpack.ru/wp-content/themes/enfold/config-templatebuilder/avia-shortcodes/audio-player/audio-player.css?ver=6.9.7
- https://bagandpack.ru/wp-content/themes/enfold/config-templatebuilder/avia-shortcodes/blog/blog.css?ver=6.9.7
- https://bagandpack.ru/wp-content/themes/enfold/config-templatebuilder/avia-shortcodes/postslider/postslider.css?ver=6.9.7
- https://bagandpack.ru/wp-content/themes/enfold/config-templatebuilder/avia-shortcodes/buttons/buttons.css?ver=6.9.7
Other scans of bagandpack.ru (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown ·
https://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/b15e9eebc8bd7781f511c8a79e4ca - 20 Aug 2026 - unknown ·
https://bagandpack.ru/wp-content/plugins/super-forms/uploads/php/files/1f234453865733c5d32dd4eb89e52
Questions about bagandpack.ru
- Is bagandpack.ru safe?
- The scan of bagandpack.ru on 14 Aug 2026 reached no verdict either way (score 12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with bagandpack.ru?
- 4 analysed samples communicate with this URL, including Phishing.
- How was bagandpack.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of bagandpack.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan