plusbateria.com - URL scan, 16 Aug 2026
MalwareAnalyzer by Cyble scanned plusbateria.com and returned a unknown verdict (score 10), categorised as credential-harvest. The page resolved to 81.169.145.163 on STRATO AG in DE. The domain was registered 5265 days ago through Cronon GmbH. 7 domains and 1 IP were contacted, over 15 HTTP requests. 6 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 16 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 10) · Confidence 13%
- Scanned URL:
http://plusbateria.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607cc4cb90236---39727595893.pdf - Domain: plusbateria.com · IP: 81.169.145.163 · AS6724 · DE
- Server: Apache/2.4.68 (Unix)
- Page title: PlusBatería – No se encontró la página
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: Cronon GmbH · domain age 5265 days · created 2012-03-16
- HTTP requests captured: 15
- Scan tier: fast · observed 2026-08-16 04:37:29 UTC
Redirect chain
http://plusbateria.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607cc4cb90236---39727595893.pdfhttps://plusbateria.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607cc4cb90236---39727595893.pdf
Malware communicating with this URL (6)
These samples were observed contacting or being served from plusbateria.com. Each links to its full analysis.
- Phishing - referenced ·
c92e73fb5cb0333dbbdf6c4b35932e84· first seen 2026-08-16 - Phishing - referenced ·
f8ad9f0a851c28a251fc99d195583ce3· first seen 2026-08-16 - Phishing - referenced ·
e0f37e1c1c16754a922406f34e261895· first seen 2026-08-13 - Phishing - referenced ·
680bd78200998af48bfccd788546cb16· first seen 2026-08-13 - Phishing - referenced ·
db437cff9a4ddc19a1b77a1e85a16b9a· first seen 2026-08-13 - Phishing - referenced ·
d34f896521df0a0679e24aff99b38877· first seen 2026-08-13
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- Apache
- PHP
- WordPress
- jQuery
Contacted infrastructure
- 81.169.145.163 - AS6724 STRATO AG (Germany)
Observed indicators
- plusbateria.com
- www.youtube.com
- a.vimeocdn.com
- fonts.googleapis.com
- twitter.com
- www.facebook.com
- www.creadoreswebciudadreal.com
- 81.169.145.163
- https://plusbateria.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607cc4cb90236---39727595893.pdf
- http://plusbateria.com/wp-content/uploads/2015/03/favicon.jpg
- https://plusbateria.com/feed/
- https://plusbateria.com/feed/atom/
- https://plusbateria.com/xmlrpc.php
- https://plusbateria.com/wp-content/themes/jupiter/js/html5shiv.js
- https://plusbateria.com/wp-content/themes/jupiter/stylesheet/css/ie.css
- https://plusbateria.com/wp-content/themes/jupiter/stylesheet/css/ie7.css
- https://plusbateria.com/wp-content/themes/jupiter/stylesheet/css/ie8.css
- https://plusbateria.com/wp-content/themes/jupiter/js/respond.js
- http://www.youtube.com/player_api
- http://a.vimeocdn.com/js/froogaloop2.min.js
Other scans of plusbateria.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - unknown ·
https://plusbateria.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607713919b8d3
Questions about plusbateria.com
- Is plusbateria.com safe?
- The scan of plusbateria.com on 16 Aug 2026 reached no verdict either way (score 10). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with plusbateria.com?
- 6 analysed samples communicate with this URL, including Phishing.
- How was plusbateria.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of plusbateria.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan