img0.liveinternet.ru - suspicious URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned img0.liveinternet.ru and returned a suspicious verdict (score 20). The page resolved to 88.212.196.95 on EDINAYA SET LIMITED LIABILITY COMPANY in RU. 1 domain and 1 IP were contacted. 1782 malware samples communicate with this URL. This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 26%
- Scanned URL:
http://img0.liveinternet.ru/images/attach/c/7//4790/4790707_skachat__besplatno__skayp_.pdf - Domain: img0.liveinternet.ru · IP: 88.212.196.95 · AS39134 · RU
- Server: nginx/1.12.2
- HTTP status: 200 · application/pdf
- Scan tier: fast · observed 2026-08-17 12:11:27 UTC
Malware communicating with this URL (1782)
These samples were observed contacting or being served from img0.liveinternet.ru. Each links to its full analysis.
- 4790895_miyadzaki__multfilmuy_.pdf - referenced ·
6adecda81e94b2af49421fa4a579123f· first seen 2026-08-17 - 4803419_skachat__vit__registry_.pdf - referenced ·
571ca8d004098c09516f8fccfea7d65c· first seen 2026-08-17 - 4803231_skachat__programmu__dlya_.pdf - referenced ·
f262e5adda881dcbcf1a8442d085d710· first seen 2026-08-17 - 4788302_mushmellow__skachat__diskografiyu_.pdf - referenced ·
85a35e561ab42e9c1fb58e6fe1009866· first seen 2026-08-17 - 4802413_zadachnik__po__fizike_.pdf - referenced (hosted here) ·
eba514c9680dc502bc190b85bbac6092· first seen 2026-08-17 - 4802605_kak__uznat__rezultatuy_.pdf - referenced ·
47ca8604868d9794a35217ae47a2c5c8· first seen 2026-08-17 - 4788742_kak__platnuye__igruy_.pdf - referenced ·
763d883b3ebadd2b4570cd546fb7553b· first seen 2026-08-17 - 4788586_proekt__moya__semya_.pdf - referenced ·
66579c0e785323feae3cb73868db2637· first seen 2026-08-17 - 4802966_vladimir__zhdamirov__vesna_.pdf - referenced ·
71d21daf1eda42e7e2d0e6cfd09e8451· first seen 2026-08-17 - 4789135_torg__12__skachat_.pdf - referenced ·
9239196aa937b8adca98bb7593205431· first seen 2026-08-17 - 4788268_skachat__igru__papinuy_.pdf - referenced ·
fac8167a4d0d8e546b02de6d8cb7ab22· first seen 2026-08-17 - 4790826_protokol__o__vuyhode_.pdf - referenced ·
2e2fb5ed3901ca9bee9f5a3aba1185d1· first seen 2026-08-17 - 4803207_abba__notuy__dlya_.pdf - referenced ·
4eb0015e8f54df282bbed1ea2c6f6997· first seen 2026-08-17 - 4791066_kniga__bogatuyy__papa_.pdf - referenced ·
c2b8f2c7048c6266ef1183547fa0aaf4· first seen 2026-08-17 - 4802639_skachat__igru__gurmaniya_.pdf - referenced ·
aba73935709c5156f3783663b4bc9385· first seen 2026-08-17
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- File download routed to the malware sandbox (4790707_skachat__besplatno__skayp_.pdf)
- Served over plaintext HTTP
Detected technologies
- Nginx
Contacted infrastructure
- 88.212.196.95 - AS39134 EDINAYA SET LIMITED LIABILITY COMPANY (Russian Federation)
Files served by this page
- 4790707_skachat__besplatno__skayp_.pdf ·
488e793c85314657bbf0496b94894ee5
Observed indicators
- img0.liveinternet.ru
- 88.212.196.95
- http://img0.liveinternet.ru/images/attach/c/7//4790/4790707_skachat__besplatno__skayp_.pdf
Other scans of img0.liveinternet.ru (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://img0.liveinternet.ru/images/attach/c/5/89/151/89151434_large_P12.jpg - 22 Aug 2026 - unknown ·
http://img0.liveinternet.ru/images/attach/c/4/80/99/80099222_Potryasayuschiy_dizayn_upakovki_7.jpg - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4788/4788482_dogovor__kupliprodazhi__avtomobilya_.pdf - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4788/4788152_filmuy__na__telefon_.pdf - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4788/4788542_onore__de__balzak_.pdf - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4802/4802848_raspisanie__avtobusov__naberezhnuye_.pdf - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4802/4802841_skachat__knigu__pera_.pdf - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4788/4788121_referatuy__po__russkomu_.pdf - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4788/4788452_cifrovaya__zerkalka__dlya_.pdf - 17 Aug 2026 - suspicious ·
http://img0.liveinternet.ru/images/attach/c/7//4802/4802469_skachat__goat_.pdf
Questions about img0.liveinternet.ru
- Is img0.liveinternet.ru safe?
- No. MalwareAnalyzer scanned img0.liveinternet.ru on 17 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with img0.liveinternet.ru?
- 1782 analysed samples communicate with this URL.
- How was img0.liveinternet.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of img0.liveinternet.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan