gsoam.ge - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned gsoam.ge and returned a unknown verdict (score 12). The page resolved to 94.130.91.36 on Hetzner Online GmbH in DE. 5 domains and 1 IP were contacted, over 19 HTTP requests. 19 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 12) · Confidence 15%
- Scanned URL:
http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1609ed295a1d34---vuxoxawezivubofef.pdf - Domain: gsoam.ge · IP: 94.130.91.36 · AS24940 · DE
- Server: nginx
- Page title: გვერდი არ არის ნაპოვნი
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 19
- Scan tier: fast · observed 2026-08-19 13:28:02 UTC
Redirect chain
http://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1609ed295a1d34---vuxoxawezivubofef.pdfhttps://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1609ed295a1d34---vuxoxawezivubofef.pdf
Malware communicating with this URL (19)
These samples were observed contacting or being served from gsoam.ge. Each links to its full analysis.
- Phishing - referenced ·
42d7d98866317c427bbf6f9a5cd9c8de· first seen 2026-08-19 - Phishing - referenced ·
787604cc5680cdb439d5cb335b234a19· first seen 2026-08-18 - Phishing - referenced ·
441dbd9f4b3c83684cedd83af57bf4bc· first seen 2026-08-17 - Phishing - referenced ·
9b81c0348202cb92cbd1f1a4e2c2f84f· first seen 2026-08-16 - Phishing - referenced ·
4bc4a065a18a4dbdfdbf5938c3b3cf44· first seen 2026-08-16 - Phishing - referenced ·
756cf0ee70e3085a0c57e42d496b0163· first seen 2026-08-16 - Phishing - referenced ·
e71fddf5c26bf26e621240d02f22b04f· first seen 2026-08-15 - Phishing - referenced ·
3e884be1f3247678d9631a9d50fa771c· first seen 2026-08-15 - Phishing - referenced ·
6df64b1872cde74f2d45eeb8b9d28a99· first seen 2026-08-14 - Phishing - referenced ·
a6481815af7f4e55291f9b2a8521b6e1· first seen 2026-08-14 - Phishing - referenced ·
233f468e990445867d1441febdea60ce· first seen 2026-08-14 - Phishing - referenced ·
09374881fdb8342f023ace5cbe4e4d57· first seen 2026-08-14 - Phishing - referenced ·
3b254ae2e3a9c2747eb30dff21393251· first seen 2026-08-14 - Phishing - referenced ·
82a0617d426193c2a91aea7a8b8b1ba5· first seen 2026-08-14 - Phishing - referenced ·
6293622e068da73d04a17ff24198194b· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Nginx
- WordPress
- jQuery
Contacted infrastructure
- 94.130.91.36 - AS24940 Hetzner Online GmbH (Germany)
Observed indicators
- gsoam.ge
- gmpg.org
- fonts.googleapis.com
- www.uimeweb.org
- www.aaamed.org
- 94.130.91.36
- https://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1609ed295a1d34---vuxoxawezivubofef.pdf
- http://gmpg.org/xfn/11
- https://fonts.googleapis.com/
- https://gsoam.ge/feed
- https://gsoam.ge/comments/feed
- https://gsoam.ge/wp-content/plugins/ml-slider/admin/assets/dist/css/editor-block.css?ver=3.109.0
- https://gsoam.ge/wp-content/plugins/blossomthemes-email-newsletter/public/css/blossomthemes-email-newsletter-public.min.css?ver=2.2.11
- https://gsoam.ge/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.5
- https://gsoam.ge/wp-content/plugins/raratheme-companion/public/css/raratheme-companion-public.min.css?ver=1.4.4
- https://gsoam.ge/wp-content/themes/the-conference/css/animate.min.css?ver=3.5.2
- https://fonts.googleapis.com/css?family=Nunito%20Sans:200,200i,300,300i,400,400i,600,600i,700,700i,800,800i,900,900i&subset=latin,latin-ext
- https://gsoam.ge/wp-content/themes/the-conference/style.css?ver=1.2.7
- https://gsoam.ge/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://gsoam.ge/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
Other scans of gsoam.ge (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/16151e2f57a915---koko - 15 Aug 2026 - unknown ·
https://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1612659d1edfa6---7986 - 14 Aug 2026 - unknown ·
https://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/160823eb244569---faxi - 13 Aug 2026 - unknown ·
https://gsoam.ge/wp-content/plugins/formcraft/file-upload/server/content/files/1613f77c541eae---boki
Questions about gsoam.ge
- Is gsoam.ge safe?
- The scan of gsoam.ge on 19 Aug 2026 reached no verdict either way (score 12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with gsoam.ge?
- 19 analysed samples communicate with this URL, including Phishing.
- How was gsoam.ge checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of gsoam.ge
Scanned on MalwareAnalyzer by Cyble · Open interactive scan