na-nule.ru - URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned na-nule.ru and returned a unknown verdict (score 0). The page resolved to 172.67.202.227 on Cloudflare, Inc. in US. 3 domains and 2 IPs were contacted, over 1 HTTP request. 15 malware samples communicate with this URL (Phishing). The request followed 2 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 0%
- Scanned URL:
https://na-nule.ru/wp-content/plugins/super-forms/uploads/php/files/8kale6b9pvhpon60l3pumjkvm4/84746350318.pdf - Domain: na-nule.ru · IP: 172.67.202.227 · AS13335 · US
- Server: cloudflare
- Page title: Jozz casino / Джозз казино официальный сайт / зеркало 2026 ᐈ вход и регистрация
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-23 04:36:30 UTC
Redirect chain
https://na-nule.ru/wp-content/plugins/super-forms/uploads/php/files/8kale6b9pvhpon60l3pumjkvm4/84746350318.pdfhttp://na-nule.ru/https://na-nule.ru/
Malware communicating with this URL (15)
These samples were observed contacting or being served from na-nule.ru. Each links to its full analysis.
- Phishing - referenced ·
3075c94b6598da0fbd1ffdbe466bf1c3· first seen 2026-08-23 - Phishing - referenced ·
157e8d550e5d1608cbfca2517018ce01· first seen 2026-08-21 - Phishing - referenced ·
a3fa0fe70b1b6f5127a612d0ccd67c8a· first seen 2026-08-21 - Phishing - referenced ·
e4613f022c02ab69f3dcb502e0539e06· first seen 2026-08-20 - Phishing - referenced ·
afbd9db022f188dffa7ea0a9ac339c01· first seen 2026-08-19 - Phishing - referenced ·
ec2f7eb142c2e6104754193792930ee9· first seen 2026-08-17 - Phishing - referenced ·
d870fce0c67f7d0853e5335d7b8e42d9· first seen 2026-08-17 - Phishing - referenced ·
a8ac43c4e4006fa18c56c5440320e881· first seen 2026-08-16 - Phishing - referenced ·
e1043bfbb5c30de7f61a66e14a374e82· first seen 2026-08-16 - Phishing - referenced ·
ef260225f61757658d82897d1573fad4· first seen 2026-08-15 - Phishing - referenced ·
e931154fd0b24c35c309e6ea573906ad· first seen 2026-08-15 - Phishing - referenced ·
42e375b6bf1ffa0b484de9cda3a28ee8· first seen 2026-08-15 - Phishing - referenced ·
f76e312cc5a52b8c56e9d620152af558· first seen 2026-08-15 - 95770adfb029db7c1561d103b3424f644b5d5ffb25e9dfa89fe58ab0359e35a7 - referenced ·
95770adfb029db7c1561d103b3424f64· first seen 2026-08-14 - Phishing - referenced ·
4ebdae3647e8bbbfca303ef7432b61e6· first seen 2026-08-14
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Detected technologies
- Cloudflare
- Cloudflare Insights
Contacted infrastructure
- 172.67.202.227 - AS13335 Cloudflare, Inc. (United States)
- 104.21.44.189 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- na-nule.ru
- jozz716.na-nule.ru
- static.cloudflareinsights.com
- 172.67.202.227
- 104.21.44.189
- https://na-nule.ru/
- https://na-nule.ru/favicon.png
- https://jozz716.na-nule.ru/
- https://na-nule.ru/amp
- https://na-nule.ru/#
- https://na-nule.ru/slots/mission-cash.jpg
- https://na-nule.ru/slots/four-seasons.jpg
- https://na-nule.ru/slots/cash-streak.jpg
- https://na-nule.ru/slots/monster-pop.jpg
- https://na-nule.ru/slots/boat-bonanza-rider.jpg
- https://na-nule.ru/slots/beware-the-deep-megaways.jpg
- https://na-nule.ru/slots/spinfinity-man.jpg
- https://na-nule.ru/slots/mermaid-s-diamond.jpg
- https://na-nule.ru/slots/mafia-gold.jpg
- https://na-nule.ru/img2.webp
Other scans of na-nule.ru (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 15 Aug 2026 - unknown
- 14 Aug 2026 - unknown
Questions about na-nule.ru
- Is na-nule.ru safe?
- The scan of na-nule.ru on 23 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with na-nule.ru?
- 15 analysed samples communicate with this URL, including Phishing.
- How was na-nule.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of na-nule.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan