medkoreavgmail.store - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned medkoreavgmail.store and returned a malicious verdict (score 73), categorised as phishing. The page resolved to 95.163.244.138 on Domain names registrar REG.RU, Ltd in RU. The domain was registered 144 days ago through Registrar of Domain Names REG.RU LLC. 11 domains and 5 IPs were contacted, over 26 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 73) · Confidence 82%
- Scanned URL:
https://medkoreavgmail.store/ - Domain: medkoreavgmail.store · IP: 95.163.244.138 · AS197695 · RU
- Server: openresty
- Page title: medkoreavgmail.store
- HTTP status: 200 · text/html
- Registrar: Registrar of Domain Names REG.RU LLC · domain age 144 days · created 2026-03-30
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 17 23: · subject CN=medkoreavgmail.store
- HTTP requests captured: 26 · cookies set: 8 · outgoing links: 9
- Scan tier: standard · observed 2026-08-21 19:54:14 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
Categories
- phishing
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Domain impersonates gmail (combosquat)
- Certificate issued < 48h ago
Contacted infrastructure
- 95.163.244.138 - AS197695 Domain names registrar REG.RU, Ltd (Russian Federation)
- 87.250.250.119 - AS13238 Yandex enterprise network (Russian Federation)
Observed indicators
- medkoreavgmail.store
- yandex.ru
- reg.ru
- www.reg.ru
- help.reg.ru
- companies.rbc.ru
- www.rbc.ru
- mc.yandex.ru
- files.reg.ru
- yastatic.net
- mc.yandex.com
- 95.163.244.138
- 77.88.55.88
- 87.250.250.119
- 194.67.72.33
- 37.9.64.225
- https://medkoreavgmail.store/
- https://medkoreavgmail.store/parking-rdap-auto.css
- https://medkoreavgmail.store/favicon.ico?1
- https://medkoreavgmail.store/manifest.js
Questions about medkoreavgmail.store
- Is medkoreavgmail.store safe?
- No. MalwareAnalyzer scanned medkoreavgmail.store on 21 Aug 2026 and returned a malicious verdict with a score of 73 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was medkoreavgmail.store checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of medkoreavgmail.store
Scanned on MalwareAnalyzer by Cyble · Open interactive scan