pm2pavba27wr4m34.onion - suspicious URL scan, 22 Aug 2026

MalwareAnalyzer by Cyble scanned pm2pavba27wr4m34.onion and returned a suspicious verdict (score 22), categorised as suspicious-infrastructure. 1 domain and 0 IPs were contacted. 11 malware samples communicate with this URL (Ulise). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.

Scan result

Malware communicating with this URL (11)

These samples were observed contacting or being served from pm2pavba27wr4m34.onion. Each links to its full analysis.

Categories

Why this verdict

Observed indicators

Other scans of pm2pavba27wr4m34.onion (10)

This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.

Questions about pm2pavba27wr4m34.onion

Is pm2pavba27wr4m34.onion safe?
No. MalwareAnalyzer scanned pm2pavba27wr4m34.onion on 22 Aug 2026 and returned a suspicious verdict with a score of 22 out of 100, categorised as suspicious-infrastructure. Treat it as hostile until it is re-checked.
What malware is associated with pm2pavba27wr4m34.onion?
11 analysed samples communicate with this URL, including Ulise.
How was pm2pavba27wr4m34.onion checked?
A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.

Scanned at the fast tier - see how URL scanning works.

Scan another URL · Latest analyzed threats · All scans of pm2pavba27wr4m34.onion

Scanned on MalwareAnalyzer by Cyble · Open interactive scan