htfcompact.com - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned htfcompact.com and returned a suspicious verdict (score 24), categorised as suspicious-infrastructure, credential-harvest. The page resolved to 35.214.204.226 on Google LLC in US. The domain was registered 3906 days ago through Tucows Domains Inc.. 7 domains and 1 IP were contacted, over 12 HTTP requests. 9 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 24) · Confidence 30%
- Scanned URL:
https://htfcompact.com/wp-content/plugins/super-forms/uploads/php/files/75f9cfabdc53b3e62e8c358eb306f76d/34795479728.pdf - Domain: htfcompact.com · IP: 35.214.204.226 · AS15169 · US
- Server: nginx
- Page title: Page not found - HTF Compact
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: Tucows Domains Inc. · domain age 3906 days · created 2015-12-09
- HTTP requests captured: 12
- Scan tier: fast · observed 2026-08-19 20:28:38 UTC
Malware communicating with this URL (9)
These samples were observed contacting or being served from htfcompact.com. Each links to its full analysis.
- Phishing - referenced ·
84d4d4c84d458719c1e1bebf5ad38d6a· first seen 2026-08-19 - Phishing - referenced ·
e9cd208de57b89ebc17d88458888a8f0· first seen 2026-08-16 - Phishing - referenced ·
34e1653fb94c2a5d91b649af47a8dcf1· first seen 2026-08-16 - Phishing - referenced ·
273fc648a9bb3acdd3f4bfca48aedd6b· first seen 2026-08-16 - Phishing - referenced ·
e71fddf5c26bf26e621240d02f22b04f· first seen 2026-08-15 - Phishing - referenced ·
2ce38e6819977611e7da2fdc82621133· first seen 2026-08-13 - Phishing - referenced ·
1fc2eca1348d90c08d86b4e6cdffcea6· first seen 2026-08-13 - Phishing - referenced ·
a88374c290222e0aedd31419dec79f12· first seen 2026-08-13 - Phishing - referenced ·
8ce436fb253dbf6ca3c2a06ebfcc37c3· first seen 2026-08-11
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- suspicious-infrastructure
- credential-harvest
Why this verdict
- Algorithmically-generated (DGA-like) hostname
- Credential-harvesting form
Detected technologies
- Nginx
- WordPress
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 35.214.204.226 - AS15169 Google LLC (US)
Observed indicators
- htfcompact.com
- gmpg.org
- www.googletagmanager.com
- fonts.googleapis.com
- html5shim.googlecode.com
- connect.facebook.net
- www.tctnanotech.com
- 35.214.204.226
- https://htfcompact.com/wp-content/plugins/super-forms/uploads/php/files/75f9cfabdc53b3e62e8c358eb306f76d/34795479728.pdf
- http://gmpg.org/xfn/11
- https://htfcompact.com/xmlrpc.php
- https://www.googletagmanager.com/gtm.js?id=
- https://fonts.googleapis.com/
- https://htfcompact.com/feed/
- https://htfcompact.com/comments/feed/
- https://htfcompact.com/wp-content/themes/kallyas/style.css?ver=4.18.1
- https://htfcompact.com/wp-content/themes/kallyas/css/pages/page404.css?ver=4.18.1
- https://fonts.googleapis.com/css?family=Lato:100,300,regular,700,900|Open+Sans:300,regular,600,700,800&ver=7.0.4
- https://htfcompact.com/wp-content/plugins/sitepress-multilingual-cms/templates/language-switchers/legacy-list-horizontal/style.min.css?ver=1
- https://htfcompact.com/wp-content/themes/kallyas/css/bootstrap.min.css?ver=4.18.1
Other scans of htfcompact.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 13 Aug 2026 - suspicious ·
https://htfcompact.com/wp-content/plugins/super-forms/uploads/php/files/e4bd7911b4dabbb54ef93cfe7f24
Questions about htfcompact.com
- Is htfcompact.com safe?
- No. MalwareAnalyzer scanned htfcompact.com on 19 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as suspicious-infrastructure and credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with htfcompact.com?
- 9 analysed samples communicate with this URL, including Phishing.
- How was htfcompact.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of htfcompact.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan