playpt2.store - suspicious URL scan, 23 Aug 2026

MalwareAnalyzer by Cyble scanned playpt2.store and returned a suspicious verdict (score 35), categorised as credential-harvest. The page resolved to 172.67.144.16 on Cloudflare, Inc. in US. 40 domains and 4 IPs were contacted, over 12 HTTP requests. The request followed 4 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.

Scan result

Redirect chain

  1. https://pasarantogel2.com/contents/files/regug.pdf
  2. http://pasarantogel2.com/
  3. https://pasarantogel2.com/
  4. http://playpt2.store/
  5. https://playpt2.store/

Antivirus & YARA (0 of 48 engines)

No engine flagged this page's content.

Categories

Why this verdict

Detected technologies

Contacted infrastructure

Observed indicators

Questions about playpt2.store

Is playpt2.store safe?
No. MalwareAnalyzer scanned playpt2.store on 23 Aug 2026 and returned a suspicious verdict with a score of 35 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
How was playpt2.store checked?
A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.

Scanned at the standard tier - see how URL scanning works.

Scan another URL · Latest analyzed threats · All scans of playpt2.store

Scanned on MalwareAnalyzer by Cyble · Open interactive scan