jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com and returned a unknown verdict (score -4). The page resolved to 217.77.1.160 on Contabo GmbH in US. The domain was registered 71 days ago through Dynadot Inc. 1 domain and 1 IP were contacted, over 1 HTTP request. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -4) · Confidence 10%
- Scanned URL:
https://jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com/ - Domain: jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com · IP: 217.77.1.160 · AS40021 · US
- Server: Caddy
- HTTP status: 200 · text/plain; charset=utf-8
- Registrar: Dynadot Inc · domain age 71 days · created 2026-06-11
- TLS issuer: C=AT, O=ZeroSSL GmbH, CN=ZeroSSL ECC DV SSL CA 2 · valid to Nov 18 23:
- HTTP requests captured: 1
- Scan tier: standard · observed 2026-08-21 19:28:08 UTC
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
Detected technologies
- Caddy
Contacted infrastructure
- 217.77.1.160 - AS40021 Contabo GmbH (United States)
Observed indicators
- jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com
- 217.77.1.160
- https://jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com/
Questions about jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com
- Is jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com safe?
- The scan of jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com on 21 Aug 2026 reached no verdict either way (score -4). Too little was captured to judge it, which is an unknown rather than a pass.
- How was jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of jihkjihgbednotexists65476143210d-49fa-848a-d1acc7altlinkedin123.t.jfdir.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan