otpetye.com - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned otpetye.com and returned a unknown verdict (score 10), categorised as credential-harvest. The page resolved to 45.130.41.122 on Beget LLC in RU. The domain was registered 5281 days ago through Regional Network Information Center, JSC dba RU-CENTER. 6 domains and 1 IP were contacted, over 26 HTTP requests. 2 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 10) · Confidence 19%
- Scanned URL:
http://otpetye.com/images/shared/file/luliz.pdf - Domain: otpetye.com · IP: 45.130.41.122 · AS198610 · RU
- Server: nginx-reuseport/1.21.1
- Page title: Страница не найдена — ОТПЕТЫЕ МОШЕННИКИ ОФИЦИАЛЬНЫЙ САЙТ
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: Regional Network Information Center, JSC dba RU-CENTER · domain age 5281 days · created 2012-03-05
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 29 04: · subject CN=otpetye.com
- HTTP requests captured: 26
- Scan tier: standard · observed 2026-08-21 05:01:00 UTC
Redirect chain
http://otpetye.com/images/shared/file/luliz.pdfhttps://otpetye.com/images/shared/file/luliz.pdf
Malware communicating with this URL (2)
These samples were observed contacting or being served from otpetye.com. Each links to its full analysis.
- Phishing - referenced ·
a76c5b9de0ff5dcc87ec15607c6bd03b· first seen 2026-08-20 - Phishing - referenced ·
bdeee35eb5e3b3f4c0e2471753d2cad4· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Credential-harvesting form
Detected technologies
- Nginx
- PHP
- WordPress
- jQuery
Contacted infrastructure
- 45.130.41.122 - AS198610 Beget LLC (Russian Federation)
Observed indicators
- otpetye.com
- gmpg.org
- fonts.googleapis.com
- fonts.gstatic.com
- mc.yandex.ru
- cdnjs.cloudflare.com
- 45.130.41.122
- https://otpetye.com/images/shared/file/luliz.pdf
- https://gmpg.org/xfn/11
- https://otpetye.com/wp-content/plugins/header-footer-elementor/inc/widgets-css/frontend.css?ver=2.2.0
- https://otpetye.com/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-9.6.4
- https://otpetye.com/wp-content/plugins/woocommerce/assets/css/woocommerce-layout.css?ver=9.6.4
- https://otpetye.com/wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css?ver=9.6.4
- https://otpetye.com/wp-content/plugins/woocommerce/assets/css/woocommerce.css?ver=9.6.4
- https://otpetye.com/wp-content/plugins/header-footer-elementor/assets/css/header-footer-elementor.css?ver=2.2.0
- https://otpetye.com/wp-content/plugins/jet-elements/assets/css/jet-elements.css?ver=2.6.14
- https://otpetye.com/wp-content/plugins/jet-elements/assets/css/jet-elements-skin.css?ver=2.6.14
- https://otpetye.com/wp-content/plugins/elementor/assets/lib/eicons/css/elementor-icons.min.css?ver=5.35.0
- https://otpetye.com/wp-content/plugins/elementor/assets/css/frontend.min.css?ver=3.27.4
- https://otpetye.com/wp-content/uploads/elementor/css/post-885.css?ver=1739659108
Other scans of otpetye.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - suspicious ·
https://otpetye.com/images/shared/file/pefuvasasekufubedo.pdf - 20 Aug 2026 - unknown ·
https://otpetye.com/images/shared/file/pefuvasasekufubedo.pdf
Questions about otpetye.com
- Is otpetye.com safe?
- The scan of otpetye.com on 21 Aug 2026 reached no verdict either way (score 10). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with otpetye.com?
- 2 analysed samples communicate with this URL, including Phishing.
- How was otpetye.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of otpetye.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan