grawerlik.pl - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned grawerlik.pl and returned a suspicious verdict (score 38), categorised as credential-harvest. The page resolved to 51.83.195.66 on ITProCare Lucjan Weissbek in PL. 9 domains and 1 IP were contacted, over 52 HTTP requests. The request followed 1 redirect before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 38) · Confidence 50%
- Scanned URL:
http://grawerlik.pl/userfiles/file/90347870053.pdf - Domain: grawerlik.pl · IP: 51.83.195.66 · AS16276 · PL
- Server: Apache
- Page title: Strona nie została znaleziona - Grawerlik - Prezenty personalizowane
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 13 16: · subject CN=grawerlik.pl
- HTTP requests captured: 52
- Scan tier: standard · observed 2026-08-23 20:05:46 UTC
Redirect chain
http://grawerlik.pl/userfiles/file/90347870053.pdfhttps://grawerlik.pl/userfiles/file/90347870053.pdf
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Matches phishing-kit family "u-admin (uAdmin)"
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Apache
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 51.83.195.66 - AS16276 ITProCare Lucjan Weissbek (Poland)
Observed indicators
- grawerlik.pl
- www.googletagmanager.com
- www.facebook.com
- unpkg.com
- fonts.googleapis.com
- muffingroup.com
- 2qbs.pl
- connect.facebook.net
- www.google.com
- 51.83.195.66
- https://grawerlik.pl/userfiles/file/90347870053.pdf
- https://grawerlik.pl/wp-content/plugins/w3-total-cache/pub/js/lazyload.min.js
- https://www.googletagmanager.com/gtag/js?id=G-09RNRE24NB
- https://www.facebook.com/tr?id=486081996223570&ev=PageView&noscript=1
- https://www.googletagmanager.com/gtm.js?id=
- https://grawerlik.pl/wp-content/uploads/2022/06/grawerlik_favi.jpeg
- https://www.googletagmanager.com/
- https://unpkg.com/
- https://fonts.googleapis.com/
- https://grawerlik.pl/feed/
Questions about grawerlik.pl
- Is grawerlik.pl safe?
- No. MalwareAnalyzer scanned grawerlik.pl on 23 Aug 2026 and returned a suspicious verdict with a score of 38 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- How was grawerlik.pl checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of grawerlik.pl
Scanned on MalwareAnalyzer by Cyble · Open interactive scan