druttle.ru - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned druttle.ru and returned a unknown verdict (score 0). The page resolved to 103.224.182.253 on Trellian Pty. Limited in US. 1 domain and 1 IP were contacted, over 1 HTTP request. 113 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 0%
- Scanned URL:
https://druttle.ru/123?utm_term=are+the+rich+brothers+really+brothers - Domain: druttle.ru · IP: 103.224.182.253 · AS133618 · US
- Server: Apache
- Page title: druttle.ru
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-19 14:28:11 UTC
Malware communicating with this URL (113)
These samples were observed contacting or being served from druttle.ru. Each links to its full analysis.
- Phishing - referenced ·
bc29d2ae88e667cd7628542e9e640493· first seen 2026-08-19 - Phishing - referenced ·
ba5703482f7c05f58bc563300c1ed39c· first seen 2026-08-19 - Phishing - referenced ·
6da7f03f8dd7501cdc752312b684e1e2· first seen 2026-08-19 - Phishing - referenced ·
e63a84632db8d7ed351952ca751d9486· first seen 2026-08-19 - Phishing - referenced ·
b5ece4f3642543ea3fe2351ded2f23a4· first seen 2026-08-19 - Phishing - referenced ·
093b350ec64414cef9a894e141223a17· first seen 2026-08-17 - Phishing - referenced ·
c80d8cf7d090aa12714fb60da6f9361e· first seen 2026-08-17 - Phishing - referenced ·
3eff2839471d83e89930342e49a0bcbb· first seen 2026-08-17 - Phishing - referenced ·
da9db4b818fc3ad65381585d5f9647ea· first seen 2026-08-17 - Phishing - referenced ·
bf36b5bfd8ffddbd331c145eae5eaba1· first seen 2026-08-17 - Phishing - referenced ·
d7f69e0f4768e2fa4f16a7aa58a543f8· first seen 2026-08-16 - Phishing - referenced ·
05a924e5d3aee6ffccba4ad99f3380a7· first seen 2026-08-16 - Phishing - referenced ·
2d5e9f99c391b24332f21f86f9ea27fb· first seen 2026-08-16 - Phishing - referenced ·
f6268ae0ce6ff82b048babe4869f18f0· first seen 2026-08-16 - Phishing - referenced ·
1ae9375d80e7038496081b77c49802d4· first seen 2026-08-16
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Detected technologies
- Apache
Contacted infrastructure
- 103.224.182.253 - AS133618 Trellian Pty. Limited (United States)
Observed indicators
- druttle.ru
- 103.224.182.253
- https://druttle.ru/123?utm_term=are+the+rich+brothers+really+brothers
- https://druttle.ru/js/fingerprint/iife.min.js
- http://druttle.ru/123?utm_term=are+the+rich+brothers+really+brothers&tr_uuid=20260820-0028-11d2-b22a-c8e8a5e14cee&fp=-3
Other scans of druttle.ru (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=affidavit+of+loss+title+sample+philippines - 23 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=brother+hl-5450dn+printer+offline - 22 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=iq+test+questions+with+answers+pdf+in+tamil - 21 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=would+you+rather+questions+funny - 21 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=how+to+use+convection+oven+to+bake+bread - 20 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=dell+v313+printer+setup - 20 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=dell+v313+printer+setup - 20 Aug 2026 - unknown ·
https://druttle.ru/strik?utm_term=how+do+i+connect+my+bluetooth+mouse+to+my+mac - 19 Aug 2026 - unknown ·
https://druttle.ru/123?utm_term=craftsman+garage+door+opener+programming - 19 Aug 2026 - unknown ·
https://druttle.ru/123?utm_term=gorilla+nantucket+playset+instructions
Questions about druttle.ru
- Is druttle.ru safe?
- The scan of druttle.ru on 19 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with druttle.ru?
- 113 analysed samples communicate with this URL, including Phishing.
- How was druttle.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of druttle.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan