glasschneider.koeln - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned glasschneider.koeln and returned a unknown verdict (score 0). The page resolved to 82.165.166.165 on IONOS SE in DE. The domain was registered 4367 days ago through CrononAG. 6 domains and 1 IP were contacted, over 48 HTTP requests. 11 malware samples communicate with this URL (Phishing, Phish). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 0%
- Scanned URL:
https://glasschneider.koeln/wp-content/plugins/super-forms/uploads/php/files/egiemk40chnq3q4sqcecichja7/kozujosinenenewejasif.pdf - Domain: glasschneider.koeln · IP: 82.165.166.165 · AS8560 · DE
- Server: nginx
- Page title: Seite nicht gefunden - Glas Schneider
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: CrononAG · domain age 4367 days · created 2014-09-05
- Registrant country: DE
- HTTP requests captured: 48
- Scan tier: fast · observed 2026-08-20 23:42:11 UTC
Malware communicating with this URL (11)
These samples were observed contacting or being served from glasschneider.koeln. Each links to its full analysis.
- Phishing - referenced ·
7ac2c9010089b2ab8a532ccd06113974· first seen 2026-08-20 - Phishing - referenced ·
fa55301d83978e4ee0775e12d845b9ae· first seen 2026-08-20 - Phishing - referenced ·
82b31f48475ac6071af7b836af355fae· first seen 2026-08-17 - Phishing - referenced ·
a05f461c4461172bdba526a4615584af· first seen 2026-08-15 - Phishing - referenced ·
aa0c8d19150e850c35588b08b23ee88c· first seen 2026-08-15 - Phishing - referenced ·
05d558b4dddc3d410efee4c1b784fb85· first seen 2026-08-14 - Phish - referenced ·
3b10e87d3ba157bf361a235ddd69bcba· first seen 2026-08-14 - Phishing - referenced ·
00c652ebe161a275e99ba8fe9ac9ceca· first seen 2026-08-13 - Phishing - referenced ·
d07157a31a7e3c29311545b7a98afdb9· first seen 2026-08-13 - Phishing - referenced ·
1b2a6ee0b1d20f2af659bb292f8d4211· first seen 2026-08-13 - Phishing - referenced ·
f6ca043adcf7b8f22d37777b2085d81f· first seen 2026-08-12
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Detected technologies
- Nginx
- PHP
- WordPress
- jQuery
Contacted infrastructure
- 82.165.166.165 - AS8560 IONOS SE (Germany)
Observed indicators
- glasschneider.koeln
- fonts.googleapis.com
- gmpg.org
- search.google.com
- www.google.com
- lh3.googleusercontent.com
- 82.165.166.165
- https://glasschneider.koeln/wp-content/plugins/super-forms/uploads/php/files/egiemk40chnq3q4sqcecichja7/kozujosinenenewejasif.pdf
- https://glasschneider.koeln/feed/
- https://fonts.googleapis.com/css?family=Open+Sans:400,600%7CBarlow:400,500,600,700
- https://glasschneider.koeln/wp-includes/css/dist/block-library/style.min.css?ver=5.8.15
- https://glasschneider.koeln/wp-content/plugins/cookie-law-info/public/css/cookie-law-info-public.css?ver=2.0.6
- https://glasschneider.koeln/wp-content/plugins/cookie-law-info/public/css/cookie-law-info-gdpr.css?ver=2.0.6
- https://glasschneider.koeln/wp-content/plugins/g-business-reviews-rating/wp/css/css.css?ver=5.8.15
- https://glasschneider.koeln/wp-includes/js/mediaelement/mediaelementplayer-legacy.min.css?ver=4.2.16
- https://glasschneider.koeln/wp-includes/js/mediaelement/wp-mediaelement.min.css?ver=5.8.15
- https://glasschneider.koeln/wp-content/uploads/dynamic_avia/avia-merged-styles-c42f171fcef843ca014e3f08b9a32b26---657ac3c07c004.css
- https://glasschneider.koeln/wp-includes/js/jquery/jquery.min.js?ver=3.6.0
- https://glasschneider.koeln/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
- https://glasschneider.koeln/wp-content/plugins/cookie-law-info/public/js/cookie-law-info-public.js?ver=2.0.6
Questions about glasschneider.koeln
- Is glasschneider.koeln safe?
- The scan of glasschneider.koeln on 20 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with glasschneider.koeln?
- 11 analysed samples communicate with this URL, including Phishing, Phish.
- How was glasschneider.koeln checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of glasschneider.koeln
Scanned on MalwareAnalyzer by Cyble · Open interactive scan