ferropula.hr - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned ferropula.hr and returned a unknown verdict (score 18), categorised as credential-harvest. The page resolved to 178.218.165.75 on DHH-AS - Plus Hosting Grupa d.o.o., HR in HR. 8 domains and 1 IP were contacted, over 8 HTTP requests. 3 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 18) · Confidence 21%
- Scanned URL:
https://ferropula.hr/files/73555027307.pdf - Domain: ferropula.hr · IP: 178.218.165.75 · AS12417 · HR
- Server: Apache
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 8
- Scan tier: fast · observed 2026-08-22 13:47:12 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from ferropula.hr. Each links to its full analysis.
- Phishing - referenced ·
4ea7b376f3ce484d89fee8a6eaf2f931· first seen 2026-08-22 - Phishing - referenced ·
984543f7f500bc88626667daf57e400e· first seen 2026-08-19 - Phishing - referenced ·
07fe4a5a284868147a90ccb5e66721dd· first seen 2026-08-14
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- Apache
- jQuery
- Bootstrap
Contacted infrastructure
- 178.218.165.75 - AS12417 DHH-AS - Plus Hosting Grupa d.o.o., HR (HR)
Observed indicators
- ferropula.hr
- use.fontawesome.com
- fonts.googleapis.com
- fonts.gstatic.com
- maps.google.com
- cdnjs.cloudflare.com
- code.jquery.com
- cdn.jsdelivr.net
- 178.218.165.75
- https://ferropula.hr/files/73555027307.pdf
- https://ferropula.hr/css/bootstrap.min.css
- https://use.fontawesome.com/releases/v5.6.1/css/all.css
- https://fonts.googleapis.com/icon?family=Material+Icons
- https://ferropula.hr/css/meni.css?v=f4d3b35247ea6410ea897d2dc60cc6a21d896ffe
- https://ferropula.hr/css/floatButtons.css?v=f4d3b35247ea6410ea897d2dc60cc6a21d896ffe
- https://ferropula.hr/css/moj.css?v=f4d3b35247ea6410ea897d2dc60cc6a21d896ffe
- https://ferropula.hr/css/flexslider.css
- https://fonts.gstatic.com/
- https://fonts.googleapis.com/css2?family=DM+Sans:wght@400;700&display=swap
- https://ferropula.hr/css/carousel.css?v=f4d3b35247ea6410ea897d2dc60cc6a21d896ffe
Other scans of ferropula.hr (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown
- 19 Aug 2026 - unknown ·
https://ferropula.hr/files/31991290994.pdf
Questions about ferropula.hr
- Is ferropula.hr safe?
- The scan of ferropula.hr on 22 Aug 2026 reached no verdict either way (score 18). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with ferropula.hr?
- 3 analysed samples communicate with this URL, including Phishing.
- How was ferropula.hr checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of ferropula.hr
Scanned on MalwareAnalyzer by Cyble · Open interactive scan