hylyt.co - suspicious URL scan, 15 Aug 2026
MalwareAnalyzer by Cyble scanned hylyt.co and returned a suspicious verdict (score 32), categorised as credential-harvest. The page resolved to 37.98.151.202 on EDGE - GCI Network Solutions Limited, GB in GB. 19 domains and 1 IP were contacted, over 38 HTTP requests. 6 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 15 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 32) · Confidence 35%
- Scanned URL:
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/fcdd85e908f71ae651fb32be2f15da6b/76368385250.pdf - Domain: hylyt.co · IP: 37.98.151.202 · AS8851 · GB
- Server: hcdn
- Page title: Page not found - HyLyt
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 38
- Scan tier: fast · observed 2026-08-15 02:56:49 UTC
Malware communicating with this URL (6)
These samples were observed contacting or being served from hylyt.co. Each links to its full analysis.
- Phishing - referenced ·
79c1e6931b53220047598956155b7b39· first seen 2026-08-15 - Phishing - referenced ·
2aace0b77e4826d934408791b0cf9213· first seen 2026-08-15 - Phishing - referenced ·
46483ec7253a508ff55fa1f7f68e4213· first seen 2026-08-14 - Phishing - referenced ·
df433e9a602669d758c5a26dde519aa5· first seen 2026-08-13 - Phishing - referenced ·
5de9dfafeb391e59ce5655eda543fd11· first seen 2026-08-13 - Phishing - referenced ·
166a6283ce027c1f076e4058d556a4b4· first seen 2026-08-13
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- PHP
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 37.98.151.202 - AS8851 EDGE - GCI Network Solutions Limited, GB (GB)
Observed indicators
- hylyt.co
- gmpg.org
- www.facebook.com
- js.hs-scripts.com
- fonts.googleapis.com
- www.googletagmanager.com
- www.clarity.ms
- web.sociorac.com
- forms.gle
- app.mailerlite.com
- track.mailerlite.com
- static.mailerlite.com
- maxcdn.bootstrapcdn.com
- api.whatsapp.com
- in.linkedin.com
- www.instagram.com
- twitter.com
- www.youtube.com
- code.tidio.co
- 37.98.151.202
Other scans of hylyt.co (5)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/12c12b42b1c7cb291269d0b6bee22bf6/3 - 15 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/cde235f29935d72674f46226ad6bab21/7 - 14 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/ee08b4e24f8f479ac83a02ae9b8f6e80/7 - 13 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/676c8f0dbc7fd88b0df1984d44948772/x - 13 Aug 2026 - suspicious ·
https://hylyt.co/wp-content/plugins/super-forms/uploads/php/files/17c0de90c6bf776526da3deba0690fb4/w
Questions about hylyt.co
- Is hylyt.co safe?
- No. MalwareAnalyzer scanned hylyt.co on 15 Aug 2026 and returned a suspicious verdict with a score of 32 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with hylyt.co?
- 6 analysed samples communicate with this URL, including Phishing.
- How was hylyt.co checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of hylyt.co
Scanned on MalwareAnalyzer by Cyble · Open interactive scan