iomax.ru - suspicious URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned iomax.ru and returned a suspicious verdict (score 28). The page resolved to 185.114.245.124 on TimeWeb Ltd. in RU. 6 domains and 1 IP were contacted, over 16 HTTP requests. 1 malware sample communicates with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
http://www.iomax.ru/images/geze-ts1000-m.jpg - Domain: iomax.ru · IP: 185.114.245.124 · AS9123 · RU
- Server: nginx/1.30.4
- Page title: Информация о компании
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Sep 15 08: · subject CN=iomax.ru
- HTTP requests captured: 16
- Scan tier: fast · observed 2026-08-24 06:17:13 UTC
Redirect chain
http://www.iomax.ru/images/geze-ts1000-m.jpghttps://iomax.ru/images/geze-ts1000-m.jpg
Malware communicating with this URL (1)
These samples were observed contacting or being served from iomax.ru. Each links to its full analysis.
- b207d74bec93f19f6341ce96503cba4d651cab9b4d346f131491244d7b21fea8 - referenced ·
b207d74bec93f19f6341ce96503cba4d· first seen 2026-08-24
Antivirus & YARA (1 of 48 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- jQuery
Contacted infrastructure
- 185.114.245.124 - AS9123 TimeWeb Ltd. (Russian Federation)
Observed indicators
- iomax.ru
- code.jquery.com
- ajax.googleapis.com
- metrika.yandex.ru
- informer.yandex.ru
- mc.yandex.ru
- 185.114.245.124
- https://iomax.ru/images/geze-ts1000-m.jpg
- https://iomax.ru/bitrix/css/main/bootstrap.css?1535371723141508
- https://iomax.ru/bitrix/css/main/font-awesome.css?151118375328777
- https://iomax.ru/local/templates/iomax/components/bitrix/search.title/visual/style.css?15317424114041
- https://iomax.ru/local/templates/iomax/template_styles.css?17426070814023
- https://iomax.ru/bitrix/js/main/core/core.js?1756884817511455
- https://iomax.ru/bitrix/components/bitrix/search.title/script.js?174653493610542
- https://iomax.ru/newtemplate/img/favicon.ico
- https://iomax.ru/newtemplate/css/styles.css
- https://iomax.ru/newtemplate/css/jquery.background-video.css
- https://iomax.ru/newtemplate/css/remodal.css
- https://iomax.ru/newtemplate/css/remodal-default-theme.css
- https://iomax.ru/newtemplate/css/font-awesome.min.css
Questions about iomax.ru
- Is iomax.ru safe?
- No. MalwareAnalyzer scanned iomax.ru on 24 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with iomax.ru?
- 1 analysed samples communicate with this URL.
- How was iomax.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of iomax.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan