m.vk.ru - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned m.vk.ru and returned a unknown verdict (score 6). The page resolved to 93.186.225.194 on VKontakte Services in RU. 7 domains and 3 IPs were contacted, over 15 HTTP requests. 2 malware samples communicate with this URL. The request followed 3 redirects before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 15%
- Scanned URL:
https://vkontakte.ru/ - Domain: m.vk.ru · IP: 93.186.225.194 · AS47541 · RU
- Server: kittenx
- Page title: VK.com | VK
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 14 07: · subject CN=vkontakte.ru
- HTTP requests captured: 15
- Scan tier: fast · observed 2026-08-22 02:57:51 UTC
Redirect chain
https://vkontakte.ru/https://vk.ru/login?act=vkcomredirect&to=https://vk.ru/https://m.vk.ru/
Malware communicating with this URL (2)
These samples were observed contacting or being served from m.vk.ru. Each links to its full analysis.
- 01ce80d25811e30901d314f8bb27596feed6d2f487533c4d7061158e0bb7f6fe - referenced ·
01ce80d25811e30901d314f8bb27596f· first seen 2026-08-22 - 3d8b407f6823d3b9dfb08ec1de5362790fc714ce995fafe755483c7e46b12348 - referenced ·
3d8b407f6823d3b9dfb08ec1de536279· first seen 2026-08-20
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_Maldoc_VBA_AutoExec) — pages that discuss malware can match, so this alone is not a malicious verdict
- Cross-host redirect chain
Detected technologies
- PHP
Contacted infrastructure
- 93.186.225.194 - AS47541 VKontakte Services (Russian Federation)
- 87.240.132.67 - AS47541 VKontakte Services (Russian Federation)
- 87.240.137.164 - AS47541 VKontakte Services (Russian Federation)
Observed indicators
- m.vk.ru
- st.vk.ru
- vk.ru
- top-fwz1.mail.ru
- sun9-5.vkuserphoto.ru
- sun9-25.vkuserphoto.ru
- sb.scorecardresearch.com
- 93.186.225.194
- 87.240.132.67
- 87.240.137.164
- https://m.vk.ru/
- https://m.vk.ru/images/icons/favicons/fav_logo.ico?10
- https://m.vk.ru/images/icons/pwa/favicon_32.png?12
- https://m.vk.ru/images/icons/pwa/apple/default.png?15
- https://st.vk.ru/css/fonts/VKSansDisplayDemiBoldFaux.v100.woff2
- https://st.vk.ru/dist/mobile/runtime.e594917e8948f884.js
- https://st.vk.ru/dist/mobile/f-vendors~sentry.ec07c66750a5fbb4.js
- https://st.vk.ru/dist/mobile/f-vendors.b253c5791bea04a3.js
- https://st.vk.ru/dist/mobile/f-vendors~vkjs.a5beca656f207faa.js
- https://st.vk.ru/dist/mobile/f-f33d8851c9cf4e66.ba28f37e4583a610.js
Other scans of m.vk.ru (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://m.vk.ru/share.php?url=http%3A%2F%2Falexchina.do.am%2F
Questions about m.vk.ru
- Is m.vk.ru safe?
- The scan of m.vk.ru on 22 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with m.vk.ru?
- 2 analysed samples communicate with this URL.
- How was m.vk.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of m.vk.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan