emissor.atxsales.com.br - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned emissor.atxsales.com.br and returned a unknown verdict (score 18), categorised as credential-harvest. The page resolved to 107.161.183.157 on Ditcom Internet Ltda. in US. 1 domain and 1 IP were contacted, over 10 HTTP requests. 1 malware sample communicates with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 18) · Confidence 21%
- Scanned URL:
https://emissor.atxsales.com.br/ - Domain: emissor.atxsales.com.br · IP: 107.161.183.157 · AS33182 · US
- Server: Apache
- Page title: ATX Emissor
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 10
- Scan tier: fast · observed 2026-08-22 16:23:13 UTC
Redirect chain
https://emissor.atxsales.com.br/https://emissor.atxsales.com.br/login.php?domain=atxemissor
Malware communicating with this URL (1)
These samples were observed contacting or being served from emissor.atxsales.com.br. Each links to its full analysis.
- 03cf3b788540276f332862439abd78cc7f8cd273d6340d2393e7a471b70de324 - referenced ·
03cf3b788540276f332862439abd78cc· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- Apache
- jQuery
- Bootstrap
Contacted infrastructure
- 107.161.183.157 - AS33182 Ditcom Internet Ltda. (United States)
Observed indicators
- emissor.atxsales.com.br
- 107.161.183.157
- https://emissor.atxsales.com.br/login.php?domain=atxemissor
- https://emissor.atxsales.com.br/favicon.ico
- https://emissor.atxsales.com.br/vendor/fortawesome/font-awesome/css/all.min.css
- https://emissor.atxsales.com.br/node_modules/simple-line-icons/css/simple-line-icons.css
- https://emissor.atxsales.com.br/node_modules/loaders.css/loaders.min.css
- https://emissor.atxsales.com.br/node_modules/animate.css/animate.min.css
- https://emissor.atxsales.com.br/css/bootstrap.css
- https://emissor.atxsales.com.br/css/app.css
- https://emissor.atxsales.com.br/img/logo.png
- https://emissor.atxsales.com.br/node_modules/jquery/dist/jquery.min.js
- https://emissor.atxsales.com.br/node_modules/bootstrap/dist/js/bootstrap.bundle.min.js
- https://emissor.atxsales.com.br/node_modules/bootstrap/dist/js/bootstrap.min.js
- https://emissor.atxsales.com.br/node_modules/parsleyjs/dist/parsley.min.js
- https://emissor.atxsales.com.br/node_modules/parsleyjs/dist/i18n/pt-br.js
- https://emissor.atxsales.com.br/node_modules/js-storage/js.storage.min.js
- https://emissor.atxsales.com.br/js/app.js?1787415795
- https://emissor.atxsales.com.br/js/login.js?1787415795
- https://emissor.atxsales.com.br/js/rotas.js?1787415795
Questions about emissor.atxsales.com.br
- Is emissor.atxsales.com.br safe?
- The scan of emissor.atxsales.com.br on 22 Aug 2026 reached no verdict either way (score 18). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with emissor.atxsales.com.br?
- 1 analysed samples communicate with this URL.
- How was emissor.atxsales.com.br checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of emissor.atxsales.com.br
Scanned on MalwareAnalyzer by Cyble · Open interactive scan