jockmurray.com - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned jockmurray.com and returned a suspicious verdict (score 46). The page resolved to 198.54.115.16 on Namecheap, Inc. in US. The domain was registered 8544 days ago through DNC Holdings, Inc.. 4 domains and 1 IP were contacted, over 6 HTTP requests. 17 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 46) · Confidence 52%
- Scanned URL:
http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093f9f6e5a4a---34945516815.pdf - Domain: jockmurray.com · IP: 198.54.115.16 · AS22612 · US
- Server: LiteSpeed
- Page title: Page not found - Jock Murray Group
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: DNC Holdings, Inc. · domain age 8544 days · created 2003-04-01
- HTTP requests captured: 6
- Scan tier: fast · observed 2026-08-23 05:22:04 UTC
Malware communicating with this URL (17)
These samples were observed contacting or being served from jockmurray.com. Each links to its full analysis.
- Phishing - referenced ·
d30aa197e6dd95e200b2c20d969e56f3· first seen 2026-08-23 - Phishing - referenced ·
e6b96ddc6029bdc3f1d0e814917a697b· first seen 2026-08-20 - Phishing - referenced ·
3ef984576f3e5cfdf5a812e8ac8439b3· first seen 2026-08-20 - Phishing - referenced ·
405685975d3db3e1d852f27106578adb· first seen 2026-08-19 - Phishing - referenced ·
7106347c06df10d6d68a330a686c50d7· first seen 2026-08-17 - Phishing - referenced ·
2292ec6bfdc9b859a9e45dd2a189d3ee· first seen 2026-08-16 - Phishing - referenced ·
e6b9fc6fcd60f6ec4863c965733d899d· first seen 2026-08-16 - Phishing - referenced ·
63c909260525a144d9a4851c6a4feaff· first seen 2026-08-15 - Phishing - referenced ·
97ae07d23c6dc39c8e4d7de453d1824e· first seen 2026-08-15 - Phishing - referenced ·
152932cda7855ce8d99851e24894e7dd· first seen 2026-08-15 - Phishing - referenced ·
5c2dd486f5fbd50c65bb799b52129198· first seen 2026-08-14 - Phishing - referenced ·
fc9c2c25878efd110e546faba63c02c8· first seen 2026-08-13 - vepukigaxigu.pdf - referenced ·
e3b881c2de52d2f308cc0d27a54036d1· first seen 2026-08-13 - Phishing - referenced ·
d475db4f7ff0d17acc50728503a6e9ba· first seen 2026-08-13 - Phishing - referenced ·
b4dcf1898e249280749ca169a619b016· first seen 2026-08-12
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_Maldoc_VBA_AutoExec
- Served over plaintext HTTP
Detected technologies
- LiteSpeed
- PHP
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 198.54.115.16 - AS22612 Namecheap, Inc. (United States)
Observed indicators
- jockmurray.com
- fonts.googleapis.com
- twitter.com
- www.linkedin.com
- 198.54.115.16
- http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/16093f9f6e5a4a---34945516815.pdf
- http://jockmurray.com/wp-content/themes/Avada/assets/js/html5shiv.js
- http://jockmurray.com/wp-content/uploads/2015/03/favicon.jpg
- http://fonts.googleapis.com/
- http://jockmurray.com/feed/
- http://jockmurray.com/comments/feed/
- http://jockmurray.com/wp-includes/css/dist/block-library/style.min.css?ver=6.2.11
- http://jockmurray.com/wp-includes/css/classic-themes.min.css?ver=6.2.11
- http://jockmurray.com/wp-content/plugins/formcraft/css/common.css?ver=2.5
- http://jockmurray.com/wp-content/plugins/formcraft/css/editor_form.css?ver=2.5
- http://jockmurray.com/wp-content/plugins/formcraft/css/fontello/css/formcraft.css?ver=2.5
- http://fonts.googleapis.com/css?family=Open+Sans%3A400%2C400italic%2C700%2C700italic%3Alatin%2Cgreek-ext%2Ccyrillic%2Clatin-ext%2Cgreek%2Ccyrillic-ext%2Cvietnamese%7CAntic+Slab%3A400%2C400italic%2C700%2C700italic%3Alatin%2Cgreek-ext%2Ccyrillic%2Clatin-ext%2Cgreek%2Ccyrillic-ext%2Cvietnamese%7CPT+Sans%3A400%2C400italic%2C700%2C700italic%3Alatin%2Cgreek-ext%2Ccyrillic%2Clatin-ext%2Cgreek%2Ccyrillic-ext%2Cvietnamese%7C&ver=6.2.11
- http://jockmurray.com/wp-content/themes/Avada/style.css?ver=3.8.3
- http://jockmurray.com/wp-content/themes/Avada/shortcodes.css?ver=3.8.3
- http://jockmurray.com/wp-content/themes/Avada/assets/fonts/fontawesome/font-awesome.css?ver=3.8.3
Other scans of jockmurray.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614e89c8eead6-- - 16 Aug 2026 - unknown ·
http://jockmurray.com/wp-content/plugins/formcraft/file-upload/server/content/files/160722af3672d0--
Questions about jockmurray.com
- Is jockmurray.com safe?
- No. MalwareAnalyzer scanned jockmurray.com on 23 Aug 2026 and returned a suspicious verdict with a score of 46 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with jockmurray.com?
- 17 analysed samples communicate with this URL, including Phishing.
- How was jockmurray.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of jockmurray.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan