helices-evra.com - URL scan, 16 Aug 2026
MalwareAnalyzer by Cyble scanned helices-evra.com and returned a unknown verdict (score 13), categorised as credential-harvest. The page resolved to 191.96.63.63 on AS-HOSTINGER - Hostinger International Limited, CY in AE. The domain was registered 7148 days ago through HOSTINGER operations, UAB. 5 domains and 1 IP were contacted, over 16 HTTP requests. The request followed 1 redirect before landing. This is a point-in-time observation from 16 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 13) · Confidence 25%
- Scanned URL:
https://helices-evra.com/userfiles/file/zepizokizonujiv.pdf - Domain: helices-evra.com · IP: 191.96.63.63 · AS47583 · AE
- Server: LiteSpeed
- Page title: Hélices d'avion et d'ULM sur mesure - Production Evra
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: HOSTINGER operations, UAB · domain age 7148 days · created 2007-01-19
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 13 17: · subject CN=helices-evra.com
- HTTP requests captured: 16
- Scan tier: standard · observed 2026-08-16 08:14:39 UTC
Redirect chain
https://helices-evra.com/userfiles/file/zepizokizonujiv.pdfhttps://helices-evra.com/
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
- Certificate issued < 48h ago
- Matches phishing-kit family "CryptoDrainer"
Detected technologies
- LiteSpeed
- PHP
- WordPress
- jQuery
Contacted infrastructure
- 191.96.63.63 - AS47583 AS-HOSTINGER - Hostinger International Limited, CY (AE)
Observed indicators
- helices-evra.com
- cdn-cookieyes.com
- stats.wp.com
- www.youtube.com
- fr.wikipedia.org
- 191.96.63.63
- https://helices-evra.com/
- https://helices-evra.com/xmlrpc.php
- https://cdn-cookieyes.com/client_data/d1ace42ef5b44ee057881fb2/script.js
- https://stats.wp.com/
- https://helices-evra.com/feed/
- https://helices-evra.com/comments/feed/
- https://helices-evra.com/wp-content/plugins/formidable/css/formidableforms.css?ver=6261357
- https://helices-evra.com/wp-content/plugins/all-in-one-seo-pack/dist/Lite/assets/css/table-of-contents/global.e90f6d47.css?ver=4.9.9
- https://helices-evra.com/wp-includes/js/mediaelement/mediaelementplayer-legacy.min.css?ver=4.2.17
- https://helices-evra.com/wp-includes/js/mediaelement/wp-mediaelement.min.css?ver=6.4.10
- https://helices-evra.com/wp-content/et-cache/14/et-divi-dynamic-14.css?ver=1785760748
- https://helices-evra.com/wp-content/plugins/supreme-modules-pro-for-divi/styles/style.min.css?ver=4.9.66
- https://helices-evra.com/wp-content/plugins/wpforms-lite/assets/css/integrations/divi/choices.min.css?ver=10.2.0
- https://helices-evra.com/wp-content/themes/Divi/includes/builder/feature/dynamic-assets/assets/css/magnific_popup.css?ver=4.9.66
Other scans of helices-evra.com (5)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown
- 17 Aug 2026 - unknown
- 17 Aug 2026 - unknown
- 16 Aug 2026 - unknown
- 8 Aug 2026 - unknown
Questions about helices-evra.com
- Is helices-evra.com safe?
- The scan of helices-evra.com on 16 Aug 2026 reached no verdict either way (score 13). Too little was captured to judge it, which is an unknown rather than a pass.
- How was helices-evra.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of helices-evra.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan