img1.liveinternet.ru - suspicious URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned img1.liveinternet.ru and returned a suspicious verdict (score 20). The page resolved to 88.212.196.95 on EDINAYA SET LIMITED LIABILITY COMPANY in RU. 1 domain and 1 IP were contacted. 2093 malware samples communicate with this URL. This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 26%
- Scanned URL:
http://img1.liveinternet.ru/images/attach/c/7//4787/4787919_uchebnik__cifrovoy__fotografii_.pdf - Domain: img1.liveinternet.ru · IP: 88.212.196.95 · AS39134 · RU
- Server: nginx/1.12.2
- HTTP status: 200 · application/pdf
- Scan tier: fast · observed 2026-08-17 12:11:40 UTC
Malware communicating with this URL (2093)
These samples were observed contacting or being served from img1.liveinternet.ru. Each links to its full analysis.
- 4788054_skachat__film__put_.pdf - referenced ·
be47297542d981a376d4aa73c64dbc85· first seen 2026-08-17 - 4790895_miyadzaki__multfilmuy_.pdf - referenced ·
6adecda81e94b2af49421fa4a579123f· first seen 2026-08-17 - 4803419_skachat__vit__registry_.pdf - referenced ·
571ca8d004098c09516f8fccfea7d65c· first seen 2026-08-17 - 4803231_skachat__programmu__dlya_.pdf - referenced ·
f262e5adda881dcbcf1a8442d085d710· first seen 2026-08-17 - 4787916_skachat__maynkraft__164_.pdf - referenced ·
53a2190dffbb69dc92eb6f7611f0244a· first seen 2026-08-17 - 4788009_rukovodstvo__po__yekspluatacii_.pdf - referenced ·
af38674f0ebeabccab6e1567590a0c11· first seen 2026-08-17 - 4789135_torg__12__skachat_.pdf - referenced ·
9239196aa937b8adca98bb7593205431· first seen 2026-08-17 - 4788268_skachat__igru__papinuy_.pdf - referenced ·
fac8167a4d0d8e546b02de6d8cb7ab22· first seen 2026-08-17 - 4790826_protokol__o__vuyhode_.pdf - referenced ·
2e2fb5ed3901ca9bee9f5a3aba1185d1· first seen 2026-08-17 - 4791066_kniga__bogatuyy__papa_.pdf - referenced ·
c2b8f2c7048c6266ef1183547fa0aaf4· first seen 2026-08-17 - 4788034_zayavlenie__o__predostavlenii_.pdf - referenced ·
a0ee0c0d83eaa4da028ed625463c665d· first seen 2026-08-17 - 4803151_itogovuyy__test__po_.pdf - referenced ·
3a5761b06ed9a003444efd9eeb837f90· first seen 2026-08-17 - 4787828_skachat__usilitel__zvuka_.pdf - referenced ·
c10de02d11d7db2a9be4ebb3cb63f502· first seen 2026-08-17 - 4787817_chto__delat__esli_.pdf - referenced ·
e2e47581b18e0397f57feb3d9ef949d5· first seen 2026-08-17 - 4683712_shablonuy_vizitok_dlya_microsoft_publisher.pdf - referenced (hosted here) ·
ce0c88c8ab340e3ee2ba701c4cfdab68· first seen 2026-08-17
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- File download routed to the malware sandbox (4787919_uchebnik__cifrovoy__fotografii_.pdf)
- Served over plaintext HTTP
Detected technologies
- Nginx
Contacted infrastructure
- 88.212.196.95 - AS39134 EDINAYA SET LIMITED LIABILITY COMPANY (Russian Federation)
Files served by this page
- 4787919_uchebnik__cifrovoy__fotografii_.pdf ·
809040edb2bf32b3982eb2cc5cccee73
Observed indicators
- img1.liveinternet.ru
- 88.212.196.95
- http://img1.liveinternet.ru/images/attach/c/7//4787/4787919_uchebnik__cifrovoy__fotografii_.pdf
Other scans of img1.liveinternet.ru (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4829/4829977_umenshenie__iskovuyh__trebovaniy_.pdf - 23 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4829/4829826_programma__dlya__sozdaniya_.pdf - 23 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4829/4829963_raspisanie__avtobusa__25_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4789/4789275_slava__petuhu__skachat_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4787/4787998_tom__i__dzherri_.pdf - 17 Aug 2026 - unknown ·
http://img1.liveinternet.ru/images/attach/c/7//4789/4789028_otvetuy__na__sbornik_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4803/4803374_kontrolnuye__zadaniya__po_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4803/4803035_skachat__besplatno__operu_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4787/4787882_leningrad__hna__skachat_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4787/4787772_dogovor__nayma__v_.pdf
Questions about img1.liveinternet.ru
- Is img1.liveinternet.ru safe?
- No. MalwareAnalyzer scanned img1.liveinternet.ru on 17 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with img1.liveinternet.ru?
- 2093 analysed samples communicate with this URL.
- How was img1.liveinternet.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of img1.liveinternet.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan