gosoftdl.mail.ru - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned gosoftdl.mail.ru and returned a malicious verdict (score 66), categorised as phishing. The page resolved to 91.231.134.1 on VK Services in RU. 1 domain and 1 IP were contacted. 2 malware samples communicate with this URL (Mailru). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 66) · Confidence 49%
- Scanned URL:
https://gosoftdl.mail.ru/ - Domain: gosoftdl.mail.ru · IP: 91.231.134.1 · AS47764 · RU
- Server: kittenx
- Page title: 404 Not Found
- HTTP status: 404 · text/html
- TLS issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 · valid to Apr 12 06: · subject C=RU, ST=Moscow, L=Moscow, O=VK LLC, CN=*.mail.ru
- Evidenced operator: VK LLC
- Scan tier: fast · observed 2026-08-20 11:47:12 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from gosoftdl.mail.ru, and at least one was hosted here. Each links to its full analysis.
- Mailru - c2 (hosted here) ·
bd5c4c5178ff9b711a13baf5ad63da28· first seen 2026-08-20 - Mailru - referenced ·
377a2b3bae84b3551b21bab9c773585a· first seen 2026-08-12
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Hosts payload/config for 1 malware sample (Mailru)
- Domain impersonates gmail (typosquat)
- Untrusted certificate (CERT_HAS_EXPIRED)
Contacted infrastructure
- 91.231.134.1 - AS47764 VK Services (Russian Federation)
Observed indicators
- gosoftdl.mail.ru
- 91.231.134.1
- https://gosoftdl.mail.ru/
Other scans of gosoftdl.mail.ru (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - malicious ·
https://gosoftdl.mail.ru/switcher_pd_3_9.exe - 12 Aug 2026 - suspicious ·
https://gosoftdl.mail.ru/switcher_pd_3_9.exe
Questions about gosoftdl.mail.ru
- Is gosoftdl.mail.ru safe?
- No. MalwareAnalyzer scanned gosoftdl.mail.ru on 20 Aug 2026 and returned a malicious verdict with a score of 66 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with gosoftdl.mail.ru?
- 2 analysed samples communicate with this URL, including Mailru. At least one was served directly from this host.
- How was gosoftdl.mail.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of gosoftdl.mail.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan