lorus.rs - URL scan, 14 Aug 2026
MalwareAnalyzer by Cyble scanned lorus.rs and returned a unknown verdict (score 10), categorised as credential-harvest. The page resolved to 144.76.78.71 on Hetzner Online GmbH in DE. 12 domains and 1 IP were contacted, over 14 HTTP requests. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 14 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 10) · Confidence 13%
- Scanned URL:
https://lorus.rs/files/99052582116.pdf - Domain: lorus.rs · IP: 144.76.78.71 · AS24940 · DE
- Server: Apache
- Page title: Page not found - Watch Salon by Vitanov
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 14
- Scan tier: fast · observed 2026-08-14 00:38:23 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from lorus.rs. Each links to its full analysis.
- Phishing - referenced ·
53d9fa5f24534b5da0d83caa6f7f80ae· first seen 2026-08-14 - Phishing - referenced ·
2852ba7fd3a8edbb825b661fa82b5748· first seen 2026-08-11
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- Apache
- WordPress
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 144.76.78.71 - AS24940 Hetzner Online GmbH (Germany)
Observed indicators
- lorus.rs
- cdn.jsdelivr.net
- fonts.googleapis.com
- fonts.gstatic.com
- www.watchsalon.rs
- cdnjs.cloudflare.com
- www.googletagmanager.com
- www.facebook.com
- watchsalon.rs
- redirekt.io
- www.instagram.com
- www.google.com
- 144.76.78.71
- https://lorus.rs/files/99052582116.pdf
- https://cdn.jsdelivr.net/npm/@fancyapps/ui/dist/fancybox.css
- https://cdn.jsdelivr.net/npm/bootstrap@5.2.0-beta1/dist/css/bootstrap.min.css
- https://fonts.googleapis.com/
- https://fonts.gstatic.com/
- https://fonts.googleapis.com/css2?family=Montserrat:wght@300;400;500;600;700&display=swap
- https://fonts.googleapis.com/css2?family=Old+Standard+TT:wght@400;700&display=swap
Other scans of lorus.rs (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://lorus.rs/files/17819634771.pdf - 14 Aug 2026 - unknown
Questions about lorus.rs
- Is lorus.rs safe?
- The scan of lorus.rs on 14 Aug 2026 reached no verdict either way (score 10). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with lorus.rs?
- 2 analysed samples communicate with this URL, including Phishing.
- How was lorus.rs checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of lorus.rs
Scanned on MalwareAnalyzer by Cyble · Open interactive scan