files.christthehealer.org - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned files.christthehealer.org and returned a unknown verdict (score -2), categorised as credential-harvest. The page resolved to 185.146.167.195 on 20i Limited in GB. 10 domains and 1 IP were contacted, over 24 HTTP requests. 1 malware sample communicates with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -2) · Confidence 8%
- Scanned URL:
http://files.christthehealer.org/uploads/1/3/1/4/131410870/jovunedolonufa.pdf - Domain: files.christthehealer.org · IP: 185.146.167.195 · AS48254 · GB
- Server: Apache
- Page title: Page not found - Christ the Healer
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Sep 22 17: · subject CN=*.christthehealer.org
- HTTP requests captured: 24
- Scan tier: fast · observed 2026-08-19 15:49:14 UTC
Redirect chain
http://files.christthehealer.org/uploads/1/3/1/4/131410870/jovunedolonufa.pdfhttps://files.christthehealer.org/uploads/1/3/1/4/131410870/jovunedolonufa.pdf
Malware communicating with this URL (1)
These samples were observed contacting or being served from files.christthehealer.org. Each links to its full analysis.
- 57250683457.pdf - referenced ·
7a226f6a638fb08f747240e5456c836c· first seen 2026-08-19
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
Detected technologies
- Apache
- PHP
- WordPress
- jQuery
Contacted infrastructure
- 185.146.167.195 - AS48254 20i Limited (United Kingdom)
Observed indicators
- files.christthehealer.org
- christthehealer.org
- fonts.googleapis.com
- maps.google.com
- www.paypal.com
- www.facebook.com
- www.youtube.com
- instagram.com
- www.linkedin.com
- christthehealer-org.us.stackstaging.com
- 185.146.167.195
- https://files.christthehealer.org/uploads/1/3/1/4/131410870/jovunedolonufa.pdf
- https://christthehealer.org/
- https://christthehealer.org/feed/
- https://christthehealer.org/comments/feed/
- https://christthehealer.org/wp-includes/css/dist/block-library/style.min.css?ver=7.0.4
- https://christthehealer.org/wp-content/plugins/custom-twitter-feeds/css/ctf-styles.min.css?ver=2.1.2
- https://christthehealer.org/wp-content/plugins/give/assets/dist/css/give.css?ver=2.33.0
- https://christthehealer.org/wp-content/plugins/give/assets/dist/css/give-donation-summary.css?ver=2.33.0
- https://christthehealer.org/wp-content/plugins/kirki/assets/css/kirki.min.css?ver=6.0.3
Questions about files.christthehealer.org
- Is files.christthehealer.org safe?
- The scan of files.christthehealer.org on 19 Aug 2026 reached no verdict either way (score -2). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with files.christthehealer.org?
- 1 analysed samples communicate with this URL.
- How was files.christthehealer.org checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of files.christthehealer.org
Scanned on MalwareAnalyzer by Cyble · Open interactive scan