kaufdeinauto.de - suspicious URL scan, 12 Aug 2026
MalwareAnalyzer by Cyble scanned kaufdeinauto.de and returned a suspicious verdict (score 24), categorised as credential-harvest. The page resolved to 85.13.141.216 on Neue Medien Muennich GmbH in DE. 3 domains and 1 IP were contacted, over 4 HTTP requests. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 12 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 24) · Confidence 30%
- Scanned URL:
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160781c138720c---91228384691.pdf - Domain: kaufdeinauto.de · IP: 85.13.141.216 · AS34788 · DE
- Server: Apache
- Page title: Site is undergoing maintenance
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-12 19:11:58 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from kaufdeinauto.de. Each links to its full analysis.
- Phishing - referenced ·
354d686606640cf550e25c4e48b95730· first seen 2026-08-12 - Phishing - referenced ·
ba66e39935f1e0206a1c9f8a3d8b8c84· first seen 2026-08-12
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Apache
- WordPress
- jQuery
Contacted infrastructure
- 85.13.141.216 - AS34788 Neue Medien Muennich GmbH (Germany)
Observed indicators
- kaufdeinauto.de
- gmpg.org
- fonts.bunny.net
- 85.13.141.216
- http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160781c138720c---91228384691.pdf
- http://gmpg.org/xfn/11
- http://kaufdeinauto.de/xmlrpc.php
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/css/style.css
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/css/fonts.css
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/js/jquery.backstretch.min.js
- https://fonts.bunny.net/css?family=OpenSans:300,300italic,regular,italic,600,600italic,700,700italic,800,800italic:Latin
- http://kaufdeinauto.de/wp-content/uploads/2025/04/mt-sample-background.jpg
- http://kaufdeinauto.de/wp-login.php?action=lostpassword
- http://kaufdeinauto.de/wp-includes/js/jquery/jquery.js
- http://kaufdeinauto.de/wp-includes/js/jquery/jquery-migrate.min.js
- http://kaufdeinauto.de/wp-content/plugins/maintenance/load/js/jquery.frontend.js
Other scans of kaufdeinauto.de (7)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1606eb7576dc40- - 17 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160b6b364611f1- - 16 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/16144fb4a640e5- - 16 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613e30c86adce- - 16 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/1613e30c86adce- - 15 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160771efc00f77- - 13 Aug 2026 - suspicious ·
http://kaufdeinauto.de/wp-content/plugins/formcraft/file-upload/server/content/files/160803cf2a842a-
Questions about kaufdeinauto.de
- Is kaufdeinauto.de safe?
- No. MalwareAnalyzer scanned kaufdeinauto.de on 12 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with kaufdeinauto.de?
- 2 analysed samples communicate with this URL, including Phishing.
- How was kaufdeinauto.de checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of kaufdeinauto.de
Scanned on MalwareAnalyzer by Cyble · Open interactive scan