goactive.hu - suspicious URL scan, 15 Aug 2026
MalwareAnalyzer by Cyble scanned goactive.hu and returned a suspicious verdict (score 22), categorised as credential-harvest. The page resolved to 35.214.205.248 on Google LLC in NL. 7 domains and 1 IP were contacted, over 39 HTTP requests. 3 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 15 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 22) · Confidence 28%
- Scanned URL:
https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/339b320c83971acd2108bd2475dce8d2/37120525026.pdf - Domain: goactive.hu · IP: 35.214.205.248 · AS19527 · NL
- Server: nginx
- Page title: Page not found - GoActive
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 39
- Scan tier: fast · observed 2026-08-15 05:31:08 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from goactive.hu. Each links to its full analysis.
- Phishing - referenced ·
5b5960eb459cf5a5e7701313631e6a23· first seen 2026-08-15 - Phishing - referenced ·
bed41cdd695d2f0355c8bf57701b866c· first seen 2026-08-15 - Phishing - referenced ·
f001234ec8fc620987ea7b2f97944008· first seen 2026-08-13
Antivirus & YARA (1 of 44 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Credential-harvesting form
Detected technologies
- Nginx
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 35.214.205.248 - AS19527 Google LLC (Netherlands)
Observed indicators
- goactive.hu
- gmpg.org
- fonts.googleapis.com
- www.googletagmanager.com
- cdn.cookie-script.com
- www.facebook.com
- pixel.barion.com
- 35.214.205.248
- https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/339b320c83971acd2108bd2475dce8d2/37120525026.pdf
- http://gmpg.org/xfn/11
- https://fonts.googleapis.com/
- https://www.googletagmanager.com/
- https://goactive.hu/en/feed/
- https://goactive.hu/en/comments/feed/
- https://goactive.hu/wp-content/plugins/integration-for-szamlazzhu-woocommerce/build/style-vat-number-block.css?ver=6.2.1
- https://goactive.hu/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-11.0.0
- https://goactive.hu/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.6
- https://goactive.hu/wp-content/plugins/convertplug-vc//assets/css/style.css?ver=1.0.0
- https://goactive.hu/wp-content/plugins/convertplug-vc//assets/css/cpvc-addon-grid.css?ver=1.0.0
- https://goactive.hu/wp-content/plugins/mp-timetable/media/css/style.css?ver=2.3.4
Other scans of goactive.hu (5)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/a60475b369c455be45ab061ab56a96a - 21 Aug 2026 - suspicious ·
https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/0857d6663765b82e0989c5522efce51 - 15 Aug 2026 - suspicious ·
https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/ef43d7c77dd3b10c0e220e907474f41 - 15 Aug 2026 - suspicious ·
https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/735a80ae4c1be54042ed7de2a1c5f5e - 15 Aug 2026 - suspicious ·
https://goactive.hu/wp-content/plugins/super-forms/uploads/php/files/39cbe9edf389b4cb961a2777cd0d56e
Questions about goactive.hu
- Is goactive.hu safe?
- No. MalwareAnalyzer scanned goactive.hu on 15 Aug 2026 and returned a suspicious verdict with a score of 22 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with goactive.hu?
- 3 analysed samples communicate with this URL, including Phishing.
- How was goactive.hu checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of goactive.hu
Scanned on MalwareAnalyzer by Cyble · Open interactive scan