manhremhoangvan.com - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned manhremhoangvan.com and returned a suspicious verdict (score 26), categorised as credential-harvest. The page resolved to 103.77.162.44 on P.A Viet Nam company limited in VN. The domain was registered 5269 days ago through Nhan Hoa Software Company Ltd.. 11 domains and 1 IP were contacted, over 28 HTTP requests. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 26) · Confidence 38%
- Scanned URL:
https://manhremhoangvan.com/wp-content/uploads/files/14743469885.pdf - Domain: manhremhoangvan.com · IP: 103.77.162.44 · AS45544 · VN
- Server: LiteSpeed
- Page title: Không tìm thấy trang này – Mành Rèm Hoàng Vân
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: Nhan Hoa Software Company Ltd. · domain age 5269 days · created 2012-03-16
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 5 03: · subject CN=hoangvan.vn
- HTTP requests captured: 28
- Scan tier: standard · observed 2026-08-19 18:06:12 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from manhremhoangvan.com. Each links to its full analysis.
- Phishing - referenced ·
3c2a8fbc3629125e0cb72832695d9ef9· first seen 2026-08-19 - Phishing - referenced ·
da7fd923e937a0067078d28e5fd9d7d4· first seen 2026-08-16
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Matches phishing-kit family "Meta / Facebook Login Kit"
Detected technologies
- LiteSpeed
- WordPress
- jQuery
Contacted infrastructure
- 103.77.162.44 - AS45544 P.A Viet Nam company limited (Viet Nam)
Observed indicators
- manhremhoangvan.com
- gmpg.org
- manhremhoangvan.vn
- fonts.googleapis.com
- cdnjs.cloudflare.com
- connect.facebook.net
- www.facebook.com
- twitter.com
- zalo.me
- www.messenger.com
- m.me
- 103.77.162.44
- https://manhremhoangvan.com/wp-content/uploads/files/14743469885.pdf
- http://gmpg.org/xfn/11
- https://manhremhoangvan.vn/xmlrpc.php
- https://manhremhoangvan.vn/
- https://fonts.googleapis.com/
- https://manhremhoangvan.vn/feed/
- https://manhremhoangvan.vn/comments/feed/
- https://manhremhoangvan.vn/wp-includes/css/dashicons.min.css?ver=6.8.8
Other scans of manhremhoangvan.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - suspicious
Questions about manhremhoangvan.com
- Is manhremhoangvan.com safe?
- No. MalwareAnalyzer scanned manhremhoangvan.com on 19 Aug 2026 and returned a suspicious verdict with a score of 26 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with manhremhoangvan.com?
- 2 analysed samples communicate with this URL, including Phishing.
- How was manhremhoangvan.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of manhremhoangvan.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan