kaufdeinauto.de - suspicious URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned kaufdeinauto.de and returned a suspicious verdict (score 24), categorised as credential-harvest. The page resolved to 85.13.141.216 on Neue Medien Muennich GmbH in DE. 3 domains and 1 IP were contacted, over 4 HTTP requests. 32 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 24) · Confidence 30%
- Scanned URL:
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160b6b364611f1---bewil.pdf - Domain: kaufdeinauto.de · IP: 85.13.141.216 · AS34788 · DE
- Server: Apache
- Page title: Site is undergoing maintenance
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-17 06:05:00 UTC
Malware communicating with this URL (32)
These samples were observed contacting or being served from kaufdeinauto.de. Each links to its full analysis.
- Phishing - referenced ·
be266313ae7d535cde5f1b69f264b58a· first seen 2026-08-17 - Phishing - referenced ·
7b75bd5cbbd68efb8a9bc996cf2a4028· first seen 2026-08-16 - Phishing - referenced ·
fdb6c86ac95a274689f0c5380a90d4b3· first seen 2026-08-16 - Phishing - referenced ·
94d23dfd2fe38b6ada349188bfc50168· first seen 2026-08-16 - Phishing - referenced ·
1c05147b6c9fd898b3452bb9f42c26a7· first seen 2026-08-16 - Phishing - referenced ·
222e2d132ab7cc54a1c7a9004bfe12ec· first seen 2026-08-16 - Phishing - referenced ·
80bd30da46ffde3e29a85bd3d2ea7566· first seen 2026-08-16 - Phishing - referenced ·
f877987514d8812a5a733a28823b679b· first seen 2026-08-16 - Phishing - referenced ·
32c4b8c0b223ac02d0433b8281d40ca8· first seen 2026-08-16 - Phishing - referenced ·
f8ad9f0a851c28a251fc99d195583ce3· first seen 2026-08-16 - Phishing - referenced ·
709d834a7dd3698a97b2f6969b9f77ed· first seen 2026-08-16 - Phishing - referenced ·
5fe07921b020d800c0795d9109c4efed· first seen 2026-08-16 - Phishing - referenced ·
c29b0dee87a22fde70270d73ea2a3b6d· first seen 2026-08-15 - Phishing - referenced ·
bbe354f59c3cfeb93111c74be71fa848· first seen 2026-08-15 - Phishing - referenced ·
129a4e90a561b4d491a85f5eb7d37c23· first seen 2026-08-15
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Apache
- WordPress
- jQuery
Contacted infrastructure
- 85.13.141.216 - AS34788 Neue Medien Muennich GmbH (Germany)
Observed indicators
- kaufdeinauto.de
- gmpg.org
- fonts.bunny.net
- 85.13.141.216
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160b6b364611f1---bewil.pdf
- http://gmpg.org/xfn/11
- http://kaufdeinauto.de/xmlrpc.php
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/css/style.css
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/css/fonts.css
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/js/jquery.backstretch.min.js
- https://fonts.bunny.net/css?family=OpenSans:300,300italic,regular,italic,600,600italic,700,700italic,800,800italic:Latin
- http://kaufdeinauto.de/wp-content/uploads/2025/04/mt-sample-background.jpg
- http://kaufdeinauto.de/wp-login.php?action=lostpassword
- http://kaufdeinauto.de/wp-includes/js/jquery/jquery.js
- http://kaufdeinauto.de/wp-includes/js/jquery/jquery-migrate.min.js
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/js/jquery.frontend.js
Other scans of kaufdeinauto.de (7)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1606eb7576dc40- - 16 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/16144fb4a640e5- - 16 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613e30c86adce- - 16 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613e30c86adce- - 15 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160771efc00f77- - 13 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160803cf2a842a- - 12 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160781c138720c-
Questions about kaufdeinauto.de
- Is kaufdeinauto.de safe?
- No. MalwareAnalyzer scanned kaufdeinauto.de on 17 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with kaufdeinauto.de?
- 32 analysed samples communicate with this URL, including Phishing.
- How was kaufdeinauto.de checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of kaufdeinauto.de
Scanned on MalwareAnalyzer by Cyble · Open interactive scan