otdelkamos.ru - suspicious URL scan, 15 Aug 2026
MalwareAnalyzer by Cyble scanned otdelkamos.ru and returned a suspicious verdict (score 28). The page resolved to 95.163.244.138 on Domain names registrar REG.RU, Ltd in RU. 8 domains and 1 IP were contacted, over 4 HTTP requests. 6 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 15 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/11e3ddddac8a2d16c05d7f3a64926ac2/joxumapajexizi.pdf - Domain: otdelkamos.ru · IP: 95.163.244.138 · AS197695 · RU
- Server: openresty
- Page title: otdelkamos.ru
- HTTP status: 404 · text/html
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Oct 15 18: · subject CN=otdelkamos.ru
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-15 19:55:40 UTC
Malware communicating with this URL (6)
These samples were observed contacting or being served from otdelkamos.ru. Each links to its full analysis.
- Phishing - referenced ·
c7a3d2d69fa19d2cb49dfb80117efaa8· first seen 2026-08-15 - Phishing - referenced ·
e2e8cd1f8140fc6f62cc1c12ebe951b9· first seen 2026-08-15 - Phishing - referenced ·
adf5aca45dc5df1f06df40a4d48193fd· first seen 2026-08-14 - Phishing - referenced ·
fd3895fccc96846587fbeb0051c81a05· first seen 2026-08-13 - Phishing - referenced ·
dbbe0e83f567d2946e54180d64e2ddbe· first seen 2026-08-13 - Phishing - referenced ·
453a0c00629dfa6381710d47daa8464c· first seen 2026-08-12
Antivirus & YARA (1 of 44 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 95.163.244.138 - AS197695 Domain names registrar REG.RU, Ltd (Russian Federation)
Observed indicators
- otdelkamos.ru
- yandex.ru
- reg.ru
- www.reg.ru
- help.reg.ru
- companies.rbc.ru
- www.rbc.ru
- mc.yandex.ru
- 95.163.244.138
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/11e3ddddac8a2d16c05d7f3a64926ac2/joxumapajexizi.pdf
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/11e3ddddac8a2d16c05d7f3a64926ac2/parking-rdap-auto.css
- https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/11e3ddddac8a2d16c05d7f3a64926ac2/favicon.ico?1
- https://otdelkamos.ru/manifest.js
- https://otdelkamos.ru/head-scripts.js
- https://yandex.ru/ads/system/context.js
- https://reg.ru/
- https://www.reg.ru/whois/?check=&dname=otdelkamos.ru&reg_source=parking_auto
- https://www.reg.ru/domain/new/?utm_source=otdelkamos.ru&utm_medium=parking&utm_campaign=s_land_new&reg_source=parking_auto
- https://www.reg.ru/hosting/?utm_source=otdelkamos.ru&utm_medium=parking&utm_campaign=s_land_host&reg_source=parking_auto
- https://www.reg.ru/dedicated/?utm_source=otdelkamos.ru&utm_medium=parking&utm_campaign=s_land_server&reg_source=parking_auto
Other scans of otdelkamos.ru (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious ·
https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/858bbc0c6e4bedcc83d70eba64e8c - 15 Aug 2026 - suspicious ·
https://otdelkamos.ru/wp-content/plugins/super-forms/uploads/php/files/04d7a1b8a0397244b042b30635f67
Questions about otdelkamos.ru
- Is otdelkamos.ru safe?
- No. MalwareAnalyzer scanned otdelkamos.ru on 15 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with otdelkamos.ru?
- 6 analysed samples communicate with this URL, including Phishing.
- How was otdelkamos.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of otdelkamos.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan