led7.ru - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned led7.ru and returned a unknown verdict (score -2), categorised as credential-harvest. The page resolved to 185.221.152.235 on RuWeb LLC in RU. 9 domains and 1 IP were contacted, over 9 HTTP requests. 7 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -2) · Confidence 8%
- Scanned URL:
https://led7.ru/file/23636083240.pdf - Domain: led7.ru · IP: 185.221.152.235 · AS210079 · RU
- Server: nginx/1.20.2
- Page title: Запрашиваемая страница не найдена!
- HTTP status: 404 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 5 23: · subject CN=led7.ru
- HTTP requests captured: 9
- Scan tier: standard · observed 2026-08-19 18:04:47 UTC
Malware communicating with this URL (7)
These samples were observed contacting or being served from led7.ru. Each links to its full analysis.
- Phishing - referenced ·
405685975d3db3e1d852f27106578adb· first seen 2026-08-19 - Phishing - referenced ·
f86d86c092f9a523809dcdb041eb9303· first seen 2026-08-18 - Phishing - referenced ·
0b17a729133e1e5a54cd7b7dc7b85f05· first seen 2026-08-15 - Phishing - referenced ·
ca853677977eb2e424646d8d14c41954· first seen 2026-08-15 - Phishing - referenced ·
2949f4905f07573c6448833305bfc741· first seen 2026-08-14 - Phishing - referenced ·
9141ac7cabfded9a32702c4d28a5ecb4· first seen 2026-08-13 - Phishing - referenced ·
0f9dae55fcd0839764477530af710ae5· first seen 2026-08-13
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
Detected technologies
- Nginx
- PHP
- jQuery
- Bootstrap
Contacted infrastructure
- 185.221.152.235 - AS210079 RuWeb LLC (RU)
Observed indicators
- led7.ru
- oss.maxcdn.com
- widget.yourgood.app
- wa.me
- www.instagram.com
- www.youtube.com
- vk.com
- matrixnet.ru
- mc.yandex.ru
- 185.221.152.235
- https://led7.ru/file/23636083240.pdf
- https://led7.ru/
- https://led7.ru/file/catalog/view/javascript/jquery/jquery-2.1.1.min.js
- https://led7.ru/file/catalog/view/javascript/bootstrap/css/bootstrap.min.css
- https://led7.ru/file/catalog/view/javascript/font-awesome/css/font-awesome.min.css
- https://led7.ru/file/catalog/view/theme/default/stylesheet/stylesheet.css
- https://led7.ru/file/catalog/view/theme/default/stylesheet/main.css
- https://led7.ru/file/catalog/view/theme/default/stylesheet/media.css
- https://led7.ru/file/catalog/view/javascript/progroman/progroman.citymanager.css?v=8.3-0
- https://led7.ru/image/catalog/cart.png
Other scans of led7.ru (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown
- 19 Aug 2026 - unknown
Questions about led7.ru
- Is led7.ru safe?
- The scan of led7.ru on 19 Aug 2026 reached no verdict either way (score -2). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with led7.ru?
- 7 analysed samples communicate with this URL, including Phishing.
- How was led7.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of led7.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan