gl.applenty.ru - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned gl.applenty.ru and returned a suspicious verdict (score 50), categorised as phishing, credential-harvest. The page resolved to 155.212.145.254 on Windstream Communications LLC in US. 3 domains and 1 IP were contacted, over 36 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 50) · Confidence 62%
- Scanned URL:
https://gl.applenty.ru/users/sign_in - Domain: gl.applenty.ru · IP: 155.212.145.254 · US
- Server: nginx/1.29.6
- Page title: Sign in · GitLab
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 20 02: · subject CN=gl.applenty.ru
- HTTP requests captured: 36 · cookies set: 4 · outgoing links: 6
- Scan tier: standard · observed 2026-08-22 03:53:12 UTC
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- phishing
- credential-harvest
Why this verdict
- Domain impersonates apple (combosquat)
- Credential-harvesting form
- Certificate issued < 48h ago
- Matches phishing-kit family "u-admin (uAdmin)"
Detected technologies
- Nginx
Contacted infrastructure
- 155.212.145.254 Windstream Communications LLC (United States)
Observed indicators
- gl.applenty.ru
- about.gitlab.com
- forum.gitlab.com
- 155.212.145.254
- https://gl.applenty.ru/users/sign_in
- https://gl.applenty.ru/assets/application-a525a9c3daa1038938085abda446450bfe2d6baa47f15350d586ae0f5adb0c07.css
- https://gl.applenty.ru/assets/application_dark-42668a4432435baac4d8f78933673d975b723cd8b6d5282a6069d14b109b115f.css
- https://gl.applenty.ru/assets/page_bundles/login-7240ec00cf3969b710fe5e8959f8ef8eeff66d635ded28839b1b4256ae8d96a3.css
- https://gl.applenty.ru/assets/page_bundles/commit_description-9e7efe20f0cef17d0606edabfad0418e9eb224aaeaa2dae32c817060fa60abcc.css
- https://gl.applenty.ru/assets/page_bundles/work_items-af321897c3b1ae7c1f6f0cb993681211b837df7ec8e5ff59e3795fd08ab83a13.css
- https://gl.applenty.ru/assets/page_bundles/notes_shared-8f7a9513332533cc4a53b3be3d16e69570e82bc87b3f8913578eaeb0dce57e21.css
- https://gl.applenty.ru/assets/tailwind_cqs-15f40f04ff54d50d70cce143d1d2fe1fc5c721ac1c17ab7fb3f04b23f468a9b2.css
- https://gl.applenty.ru/assets/fonts-deb7ad1d55ca77c0172d8538d53442af63604ff490c74acc2859db295c125bdb.css
- https://gl.applenty.ru/assets/highlight/themes/white-9c3096bebbc271536c91d4e96afdef34cf54f198accca96d32008405a3a398da.css
- https://gl.applenty.ru/assets/highlight/themes/dark-bab508e186c8119f0cfb965d3a8a74c6ee2b10c5d2cf129a41c0bc522b98655d.css
- https://gl.applenty.ru/assets/webpack/runtime.b7b96ebd.bundle.js
- https://gl.applenty.ru/assets/webpack/main.10fef0ae.chunk.js
- https://gl.applenty.ru/assets/webpack/tracker.f99708a3.chunk.js
- https://gl.applenty.ru/assets/webpack/commons-pages.explore.catalog-pages.groups.harbor.repositories-pages.groups.issues-pages.groups.new--aa29c505.2054bcd5.chunk.js
- https://gl.applenty.ru/assets/webpack/commons-pages.search.show-super_sidebar.74556b00.chunk.js
Questions about gl.applenty.ru
- Is gl.applenty.ru safe?
- No. MalwareAnalyzer scanned gl.applenty.ru on 22 Aug 2026 and returned a suspicious verdict with a score of 50 out of 100, categorised as phishing and credential-harvest. Treat it as hostile until it is re-checked.
- How was gl.applenty.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of gl.applenty.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan