nam.it - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned nam.it and returned a suspicious verdict (score 22), categorised as credential-harvest. The page resolved to 104.21.27.108 on Cloudflare, Inc. in US. 4 domains and 1 IP were contacted, over 89 HTTP requests. 19 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 22) · Confidence 28%
- Scanned URL:
https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/1609199a9e95af---74589151041.pdf - Domain: nam.it · IP: 104.21.27.108 · AS13335 · US
- Server: cloudflare
- Page title: Pagina non trovata | NAM Milano - Ente di Formazione Musicale
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 89
- Scan tier: fast · observed 2026-08-21 07:41:13 UTC
Malware communicating with this URL (19)
These samples were observed contacting or being served from nam.it. Each links to its full analysis.
- Phishing - referenced ·
ff8ce241d09eb2ad2b30d3de4152cad5· first seen 2026-08-21 - Phishing - referenced ·
d28842a03719460cdca1a1df6195d7bc· first seen 2026-08-21 - Phishing - referenced ·
1b39dca56263abe31c81d57c1fdbdb57· first seen 2026-08-20 - Phishing - referenced ·
e7081f6aa227d33ec7ab2197cc0e9339· first seen 2026-08-20 - Phishing - referenced ·
f688ed8c33f35c05294f54a443f8e428· first seen 2026-08-17 - Phishing - referenced ·
f4b2ee651f439c8e97e775a423a7c635· first seen 2026-08-17 - Phishing - referenced ·
1aaabc54ba0f2df18c6e651efea2e172· first seen 2026-08-17 - Phishing - referenced ·
fd107476b84df18dad3ca9175e0bba1b· first seen 2026-08-16 - Phishing - referenced ·
222e2d132ab7cc54a1c7a9004bfe12ec· first seen 2026-08-16 - Phishing - referenced ·
3416f9d9f4dd8ea7d5fac8c7265286cb· first seen 2026-08-16 - Phishing - referenced ·
268b5b2f9a4cbf9298b1a29d30eac272· first seen 2026-08-15 - Phishing - referenced ·
442c94ea84a3268a269b5171d5f21dd7· first seen 2026-08-14 - Phishing - referenced ·
7c0af553c36b2185a6a83f30b95c01bb· first seen 2026-08-14 - Phishing - referenced ·
c74f9404022aa40744b5afb1d53b189f· first seen 2026-08-14 - Phishing - referenced ·
829d25a507d7b748db4acf51605cdf50· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Credential-harvesting form
Detected technologies
- Cloudflare
- WordPress
- React
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 104.21.27.108 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- nam.it
- js.retainful.com
- www.googletagmanager.com
- www.google.com
- 104.21.27.108
- https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/1609199a9e95af---74589151041.pdf
- https://nam.it/wp-content/uploads/siteground-optimizer-assets/siteground-optimizer-combined-css-43bfff6c5c029f4ea48759a583b96d98.css
- https://nam.it/wp-content/themes/emmemedia/dist/img/favicon.png
- https://js.retainful.com/
- https://www.googletagmanager.com/
- https://nam.it/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://nam.it/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://nam.it/wp-content/plugins/waitlist-woocommerce/xoo-form-fields-fw/assets/js/xoo-aff-js.js?&ver=2.1.0
- https://nam.it/wp-includes/js/dist/vendor/react.min.js?&ver=18.3.1.1
- https://nam.it/wp-includes/js/dist/vendor/react-jsx-runtime.min.js?&ver=18.3.1
- https://nam.it/wp-includes/js/dist/autop.min.js?&ver=4e10a18cb6f21a043fc0
- https://nam.it/wp-includes/js/dist/blob.min.js?&ver=c7582a735ddd2edc9731
- https://nam.it/wp-includes/js/dist/block-serialization-default-parser.min.js?&ver=4c6f3dd40077f7c17604
- https://nam.it/wp-includes/js/dist/hooks.min.js?ver=f0f188028580e8dc1255
- https://nam.it/wp-includes/js/dist/deprecated.min.js?&ver=fe587bac92b7d0ef760e
Other scans of nam.it (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 16 Aug 2026 - suspicious ·
https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/1613037ea8c643---mutizo - 15 Aug 2026 - suspicious ·
https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/160ab5fd7456b3---dokemo - 14 Aug 2026 - suspicious ·
https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/161323ba19ecdb---funama - 14 Aug 2026 - suspicious ·
https://nam.it/wp-content/plugins/formcraft/file-upload/server/content/files/1607f3b5d01814---949722
Questions about nam.it
- Is nam.it safe?
- No. MalwareAnalyzer scanned nam.it on 21 Aug 2026 and returned a suspicious verdict with a score of 22 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with nam.it?
- 19 analysed samples communicate with this URL, including Phishing.
- How was nam.it checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of nam.it
Scanned on MalwareAnalyzer by Cyble · Open interactive scan