dmddsgn.com - suspicious URL scan, 16 Aug 2026
MalwareAnalyzer by Cyble scanned dmddsgn.com and returned a suspicious verdict (score 21), categorised as suspicious-infrastructure. The page resolved to 87.236.16.93 on Beget Ltd in RU. The domain was registered 2574 days ago through Registrar of Domain Names REG.RU LLC. 1 domain and 1 IP were contacted. 9 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 16 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 21) · Confidence 24%
- Scanned URL:
https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/34452c91f45d0dff164d583b5977317e/15431871456.pdf - Domain: dmddsgn.com · IP: 87.236.16.93 · AS198610 · RU
- Server: nginx-reuseport/1.21.1
- Page title: 403 Forbidden
- HTTP status: 403 · text/html; charset=iso-8859-1
- Registrar: Registrar of Domain Names REG.RU LLC · domain age 2574 days · created 2019-07-29
- Scan tier: fast · observed 2026-08-16 00:17:32 UTC
Malware communicating with this URL (9)
These samples were observed contacting or being served from dmddsgn.com. Each links to its full analysis.
- Phishing - referenced ·
c3b8ca6d56618b26d6932e3b954a6d97· first seen 2026-08-16 - Phishing - referenced ·
1c57457c2d7d7d35a65edb85191ff030· first seen 2026-08-15 - Phishing - referenced ·
bda2df7fd383e84fa1d24a8858875654· first seen 2026-08-15 - Phishing - referenced ·
4b8bd4e7e432b51a555e9b138a3beb0d· first seen 2026-08-15 - Phishing - referenced ·
f231147f3588b93f7890f75afc272b19· first seen 2026-08-14 - Phishing - referenced ·
2cb56007d99da9fb6d1ad27098747db6· first seen 2026-08-14 - Phishing - referenced ·
ca75c03c76d8197773eacc87c1b29adf· first seen 2026-08-14 - daxuta.pdf - referenced ·
fb91c6cd4d78ba7114c9da5aa68b6c0d· first seen 2026-08-13 - Phishing - referenced ·
6b69b49982bbeed4605a371c629fe71e· first seen 2026-08-12
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- suspicious-infrastructure
Why this verdict
- Algorithmically-generated (DGA-like) hostname
Detected technologies
- Nginx
Contacted infrastructure
- 87.236.16.93 - AS198610 Beget Ltd (Russian Federation)
Observed indicators
- dmddsgn.com
- 87.236.16.93
- https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/34452c91f45d0dff164d583b5977317e/15431871456.pdf
Other scans of dmddsgn.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://dmddsgn.com/wp-content/plugins/super-forms/uploads/php/files/76df2a9d7326c7ca5119b23de52fe49
Questions about dmddsgn.com
- Is dmddsgn.com safe?
- No. MalwareAnalyzer scanned dmddsgn.com on 16 Aug 2026 and returned a suspicious verdict with a score of 21 out of 100, categorised as suspicious-infrastructure. Treat it as hostile until it is re-checked.
- What malware is associated with dmddsgn.com?
- 9 analysed samples communicate with this URL, including Phishing.
- How was dmddsgn.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of dmddsgn.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan