nd-58.ru - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned nd-58.ru and returned a unknown verdict (score 6). 1 domain and 0 IPs were contacted. 17 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 12%
- Scanned URL:
http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/676bf91d8252ffbaa8e0a57005dddef3/16598521739.pdf - Domain: nd-58.ru
- Scan tier: fast · observed 2026-08-24 04:17:38 UTC
Malware communicating with this URL (17)
These samples were observed contacting or being served from nd-58.ru. Each links to its full analysis.
- Phishing - referenced ·
1754e03f6dc73161349b3ca750980d08· first seen 2026-08-24 - Phishing - referenced ·
901fab9c159c76c93909cdaf47cfbd09· first seen 2026-08-23 - Phishing - referenced ·
96f087b288027082f7ceaca99044e6ea· first seen 2026-08-22 - Phishing - referenced ·
7fda84e2da1592928c103945e4f302c3· first seen 2026-08-19 - Phishing - referenced ·
11afad9b7682b6332dbaed3a09c54533· first seen 2026-08-16 - Phishing - referenced ·
88f1fb1eb10a7303a93e5b69797f5528· first seen 2026-08-16 - Phishing - referenced ·
905207413babd9204ae15530482d1858· first seen 2026-08-16 - Phishing - referenced ·
ec5896ddcd901e5f77093ee8d71fe0dd· first seen 2026-08-16 - Phishing - referenced ·
408a73ebf8e300cfa8430a94ec7d6255· first seen 2026-08-15 - Phishing - referenced ·
ca696237b4ca3afbe00bc2a1cbdfa387· first seen 2026-08-15 - Phishing - referenced ·
a9a6800f3d5467656745158daa1bc708· first seen 2026-08-15 - Phishing - referenced ·
2a22b503dfd2b6d0b853c91c601040f6· first seen 2026-08-15 - Phishing - referenced ·
c581c6b01a970ce5c1a62482df3562b5· first seen 2026-08-13 - Phishing - referenced ·
ad9d46e8a698d772945f838896b3a1f0· first seen 2026-08-13 - Phishing - referenced ·
e800bc6cc5713eb597a26804ddd0afb5· first seen 2026-08-13
Why this verdict
- Served over plaintext HTTP
- Target did not respond (DNS/connection failure or timeout); verdict from URL structure only
Observed indicators
- nd-58.ru
- http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/676bf91d8252ffbaa8e0a57005dddef3/16598521739.pdf
Other scans of nd-58.ru (5)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/838f4f69ea6074169b9d6b95790000d6/lo - 15 Aug 2026 - unknown ·
http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/a33ce7cc26e7ddbdb8121b1f0d2cca91/29 - 13 Aug 2026 - unknown ·
http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/6a8069c04bce95bc77cff90c0c48b15c/96 - 13 Aug 2026 - unknown ·
http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/618b6e37126cd7688b8a4be9f5c99281/38 - 13 Aug 2026 - unknown ·
http://nd-58.ru/wp-content/plugins/super-forms/uploads/php/files/55537dac0d11dddaf4a65532b908c20a/xa
Questions about nd-58.ru
- Is nd-58.ru safe?
- The scan of nd-58.ru on 24 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with nd-58.ru?
- 17 analysed samples communicate with this URL, including Phishing.
- How was nd-58.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of nd-58.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan