kormed.ru - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned kormed.ru and returned a unknown verdict (score 4), categorised as credential-harvest. The page resolved to 45.130.41.156 on Beget LLC in RU. 8 domains and 1 IP were contacted, over 8 HTTP requests. 1 malware sample communicates with this URL. The request followed 2 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 4) · Confidence 13%
- Scanned URL:
http://www.kormed.ru/files/upload/medialibrary/b31/b31690b97324346a1ec945c4f9bfa912.gif - Domain: kormed.ru · IP: 45.130.41.156 · AS198610 · RU
- Server: nginx-reuseport/1.21.1
- Page title: Страница не найдена — Факультет Медицинского Права
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 28 05: · subject CN=kormed.ru
- HTTP requests captured: 8
- Scan tier: fast · observed 2026-08-23 14:37:32 UTC
Redirect chain
http://www.kormed.ru/files/upload/medialibrary/b31/b31690b97324346a1ec945c4f9bfa912.gifhttps://www.kormed.ru/files/upload/medialibrary/b31/b31690b97324346a1ec945c4f9bfa912.gifhttps://kormed.ru/files/upload/medialibrary/b31/b31690b97324346a1ec945c4f9bfa912.gif
Malware communicating with this URL (1)
These samples were observed contacting or being served from kormed.ru. Each links to its full analysis.
- 0f0126085c1a1cb0c686fdf152fbe6355e43fc025a72e67f21c9643c912df5e7 - referenced ·
0f0126085c1a1cb0c686fdf152fbe635· first seen 2026-08-23
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
- Cross-host redirect chain
Detected technologies
- Nginx
- PHP
- WordPress
- jQuery
Contacted infrastructure
- 45.130.41.156 - AS198610 Beget LLC (Russian Federation)
Observed indicators
- kormed.ru
- cdnjs.cloudflare.com
- vk.com
- rutube.ru
- t.me
- dzen.ru
- abeta.ru
- mc.yandex.ru
- 45.130.41.156
- https://kormed.ru/files/upload/medialibrary/b31/b31690b97324346a1ec945c4f9bfa912.gif
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-57x57.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-60x60.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-72x72.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-76x76.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-114x114.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-120x120.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-144x144.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-152x152.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/apple-icon-180x180.png
- https://kormed.ru/wp-content/themes/kormed/images/favicon/android-icon-192x192.png
Questions about kormed.ru
- Is kormed.ru safe?
- The scan of kormed.ru on 23 Aug 2026 reached no verdict either way (score 4). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with kormed.ru?
- 1 analysed samples communicate with this URL.
- How was kormed.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of kormed.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan