fr.proxy.al - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned fr.proxy.al and returned a unknown verdict (score -12). The page resolved to 51.83.43.112 on OVH SAS in FR. 7 domains and 1 IP were contacted, over 3 HTTP requests. 1 malware sample communicates with this URL. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://fr.proxy.al/secure/sVs6yV~dnxWLjwaLMdVP8UHThbs1xJtvgyJ0TOG1IauPwpf0RX9RpRFNkEwXKe1UITRdAeI6Oqs33~~CJgBjZwjR1teYJSht9ShTwwAdY6kaH7Itb5FZKl4QaXW0VP_t - Domain: fr.proxy.al · IP: 51.83.43.112 · AS16276 · FR
- Server: Apache
- Page title: Request failed | proxy.al - Unblock YouTube, Facebook, Twitter, Adult Unblocker - Secure
- HTTP status: 503 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Oct 13 21: · subject CN=*.4everproxy.com
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-23 05:17:23 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from fr.proxy.al. Each links to its full analysis.
- f8232ddf2e585912ef6cf28c802c796058bfa6f0be475999614fd8e336f514bc - referenced ·
f8232ddf2e585912ef6cf28c802c7960· first seen 2026-08-23
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Apache
- PHP
- Google Analytics
- jQuery
Contacted infrastructure
- 51.83.43.112 - AS16276 OVH SAS (France)
Observed indicators
- fr.proxy.al
- code.jquery.com
- www.googletagmanager.com
- www.proxy.al
- m.4everproxy.com
- www.facebook.com
- twitter.com
- 51.83.43.112
- https://fr.proxy.al/secure/sVs6yV~dnxWLjwaLMdVP8UHThbs1xJtvgyJ0TOG1IauPwpf0RX9RpRFNkEwXKe1UITRdAeI6Oqs33~~CJgBjZwjR1teYJSht9ShTwwAdY6kaH7Itb5FZKl4QaXW0VP_t
- https://fr.proxy.al/themes/default/@img/favicon.ico
- https://fr.proxy.al/public/cache/4e66f7183e413fffe85fdd81e3309c6f.css
- https://code.jquery.com/jquery-2.1.4.min.js
- https://fr.proxy.al/public/cache/55137343e0b1d13f5684f69d24969ded.js
- https://www.googletagmanager.com/gtag/js?id=G-6595789CR3
- https://www.proxy.al/
- https://fr.proxy.al/themes/default/@img/logo.png
- https://m.4everproxy.com/
- https://www.facebook.com/4everproxy
- https://twitter.com/4everproxy
- https://www.proxy.al/privacy
Other scans of fr.proxy.al (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://fr.proxy.al/secure/sVs6yV~dnxWLjwaLMdVP8UHThbs1xJtvgyJ0TOG1IatoqCUGk4gVTALzcYw6KNSrg9iP5TnnX - 23 Aug 2026 - unknown ·
https://fr.proxy.al/direct/aHR0cHM6Ly9tLmZhY2Vib29rLmNvbS8_X3JkYz0xJl9yZHImcmVmc3JjPWRlcHJlY2F0ZWQ-
Questions about fr.proxy.al
- Is fr.proxy.al safe?
- The scan of fr.proxy.al on 23 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with fr.proxy.al?
- 1 analysed samples communicate with this URL.
- How was fr.proxy.al checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of fr.proxy.al
Scanned on MalwareAnalyzer by Cyble · Open interactive scan