img1.liveinternet.ru - suspicious URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned img1.liveinternet.ru and returned a suspicious verdict (score 20). The page resolved to 88.212.196.95 on EDINAYA SET LIMITED LIABILITY COMPANY in RU. 1 domain and 1 IP were contacted. 2089 malware samples communicate with this URL. This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 26%
- Scanned URL:
http://img1.liveinternet.ru/images/attach/c/7//4787/4787882_leningrad__hna__skachat_.pdf - Domain: img1.liveinternet.ru · IP: 88.212.196.95 · AS39134 · RU
- Server: nginx/1.12.2
- HTTP status: 200 · application/pdf
- Scan tier: fast · observed 2026-08-17 12:10:36 UTC
Malware communicating with this URL (2089)
These samples were observed contacting or being served from img1.liveinternet.ru. Each links to its full analysis.
- 4787916_skachat__maynkraft__164_.pdf - referenced ·
53a2190dffbb69dc92eb6f7611f0244a· first seen 2026-08-17 - 4788009_rukovodstvo__po__yekspluatacii_.pdf - referenced ·
af38674f0ebeabccab6e1567590a0c11· first seen 2026-08-17 - 4789135_torg__12__skachat_.pdf - referenced ·
9239196aa937b8adca98bb7593205431· first seen 2026-08-17 - 4788268_skachat__igru__papinuy_.pdf - referenced ·
fac8167a4d0d8e546b02de6d8cb7ab22· first seen 2026-08-17 - 4790826_protokol__o__vuyhode_.pdf - referenced ·
2e2fb5ed3901ca9bee9f5a3aba1185d1· first seen 2026-08-17 - 4791066_kniga__bogatuyy__papa_.pdf - referenced ·
c2b8f2c7048c6266ef1183547fa0aaf4· first seen 2026-08-17 - 4788034_zayavlenie__o__predostavlenii_.pdf - referenced ·
a0ee0c0d83eaa4da028ed625463c665d· first seen 2026-08-17 - 4803151_itogovuyy__test__po_.pdf - referenced ·
3a5761b06ed9a003444efd9eeb837f90· first seen 2026-08-17 - 4787828_skachat__usilitel__zvuka_.pdf - referenced ·
c10de02d11d7db2a9be4ebb3cb63f502· first seen 2026-08-17 - 4787817_chto__delat__esli_.pdf - referenced ·
e2e47581b18e0397f57feb3d9ef949d5· first seen 2026-08-17 - 4683712_shablonuy_vizitok_dlya_microsoft_publisher.pdf - referenced (hosted here) ·
ce0c88c8ab340e3ee2ba701c4cfdab68· first seen 2026-08-17 - 4788436_obnovlenie__sp2__do_.pdf - referenced ·
382705f5821854c1a78ac0a6f20ae771· first seen 2026-08-17 - 4788913_godovaya__kontrolnaya__rabota_.pdf - referenced ·
cab68607eb51babdd5380212788ead9e· first seen 2026-08-17 - 4803271_hudeem__s__marinoy_.pdf - referenced ·
c6711555fc0e13729146f3cb7572b3c5· first seen 2026-08-17 - 4683679_roditelskie_sobraniya_v_5_klasse_fgos_temuy_na_ves_god.pdf - referenced ·
2cf1566b0fdb56ff7938d2b21e3626b2· first seen 2026-08-17
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- File download routed to the malware sandbox (4787882_leningrad__hna__skachat_.pdf)
- Served over plaintext HTTP
Detected technologies
- Nginx
Contacted infrastructure
- 88.212.196.95 - AS39134 EDINAYA SET LIMITED LIABILITY COMPANY (Russian Federation)
Files served by this page
- 4787882_leningrad__hna__skachat_.pdf ·
df5ef73b8f5acb90e7c44bbd7a4a8b2f
Observed indicators
- img1.liveinternet.ru
- 88.212.196.95
- http://img1.liveinternet.ru/images/attach/c/7//4787/4787882_leningrad__hna__skachat_.pdf
Other scans of img1.liveinternet.ru (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4829/4829977_umenshenie__iskovuyh__trebovaniy_.pdf - 23 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4829/4829826_programma__dlya__sozdaniya_.pdf - 23 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4829/4829963_raspisanie__avtobusa__25_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4789/4789275_slava__petuhu__skachat_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4787/4787919_uchebnik__cifrovoy__fotografii_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4787/4787998_tom__i__dzherri_.pdf - 17 Aug 2026 - unknown ·
http://img1.liveinternet.ru/images/attach/c/7//4789/4789028_otvetuy__na__sbornik_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4803/4803374_kontrolnuye__zadaniya__po_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4803/4803035_skachat__besplatno__operu_.pdf - 17 Aug 2026 - suspicious ·
http://img1.liveinternet.ru/images/attach/c/7//4787/4787772_dogovor__nayma__v_.pdf
Questions about img1.liveinternet.ru
- Is img1.liveinternet.ru safe?
- No. MalwareAnalyzer scanned img1.liveinternet.ru on 17 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with img1.liveinternet.ru?
- 2089 analysed samples communicate with this URL.
- How was img1.liveinternet.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of img1.liveinternet.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan