premo.at - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned premo.at and returned a unknown verdict (score 0). The page resolved to 104.21.77.206 on Cloudflare, Inc. in US. 5 domains and 2 IPs were contacted, over 38 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 6%
- Scanned URL:
http://premo.at/userfiles/file/27885790707.pdf - Domain: premo.at · IP: 104.21.77.206 · AS13335 · US
- Server: cloudflare
- Page title: Seite nicht gefunden – Premo Werbeagentur GmbH
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 16 05: · subject CN=premo.at
- HTTP requests captured: 38
- Scan tier: standard · observed 2026-08-20 06:15:36 UTC
Redirect chain
http://premo.at/userfiles/file/27885790707.pdfhttps://premo.at/userfiles/file/27885790707.pdf
Malware communicating with this URL (1)
These samples were observed contacting or being served from premo.at. Each links to its full analysis.
- Phishing - referenced ·
787604cc5680cdb439d5cb335b234a19· first seen 2026-08-18
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Cloudflare
- PHP
- WordPress
- jQuery
- Cloudflare Insights
Contacted infrastructure
- 104.21.77.206 - AS13335 Cloudflare, Inc. (United States)
- 172.67.211.131 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- premo.at
- gmpg.org
- 003web.premo.at
- devowl.io
- static.cloudflareinsights.com
- 104.21.77.206
- 172.67.211.131
- https://premo.at/userfiles/file/27885790707.pdf
- https://gmpg.org/xfn/11
- https://premo.at/feed/
- https://premo.at/comments/feed/
- https://premo.at/wp-content/ff92f76ea18cabc0719ee090e30befe9/dist/504325254.js?ver=af932e55e5f194c31fb69933f509c364
- https://premo.at/wp-content/ff92f76ea18cabc0719ee090e30befe9/dist/1477401325.js?ver=8450c62d8d5e4bfec4076ec2391ee419
- https://premo.at/wp-content/plugins/real-cookie-banner-pro/public/lib/animate.css/animate.min.css?ver=4.1.1
- https://premo.at/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=6.1.7
- https://premo.at/wp-content/themes/oceanwp/assets/fonts/fontawesome/css/all.min.css?ver=5.15.1
- https://premo.at/wp-content/themes/oceanwp/assets/css/third/simple-line-icons.min.css?ver=2.4.0
- https://premo.at/wp-content/themes/oceanwp/assets/css/style.min.css?ver=3.4.7
- https://premo.at/wp-content/plugins/exclusive-addons-for-elementor/assets/vendor/css/slick.min.css?ver=7.1
- https://premo.at/wp-content/plugins/exclusive-addons-for-elementor/assets/vendor/css/slick-theme.min.css?ver=7.1
Other scans of premo.at (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://premo.at/userfiles/file/vonuraxafiguwenesajemew.pdf - 18 Aug 2026 - unknown ·
http://premo.at/userfiles/file/voxugojor.pdf - 18 Aug 2026 - unknown ·
http://premo.at/userfiles/file/voxugojor.pdf
Questions about premo.at
- Is premo.at safe?
- The scan of premo.at on 20 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with premo.at?
- 1 analysed samples communicate with this URL, including Phishing.
- How was premo.at checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of premo.at
Scanned on MalwareAnalyzer by Cyble · Open interactive scan