presstone.hu - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned presstone.hu and returned a suspicious verdict (score 42). The page resolved to 84.2.35.185 on Magyar Telekom plc. in HU. 1 domain and 1 IP were contacted. 8 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 42) · Confidence 51%
- Scanned URL:
https://presstone.hu/userfiles/file/menofugunile.pdf - Domain: presstone.hu · IP: 84.2.35.185 · AS5483 · HU
- Server: LiteSpeed
- HTTP status: 200 · application/pdf
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 18 17: · subject CN=*.presstone.hu
- Scan tier: fast · observed 2026-08-23 10:31:09 UTC
Malware communicating with this URL (8)
These samples were observed contacting or being served from presstone.hu. Each links to its full analysis.
- Phishing - referenced ·
a55ed3a388f4a59f8ccf5a847fdd93c3· first seen 2026-08-23 - Phishing - referenced ·
6af43ba1de7221f3474c0cf58f3f7b52· first seen 2026-08-21 - Phishing - referenced ·
044b4f87185bff9c9c5eb4dbd26ff61b· first seen 2026-08-19 - Phishing - referenced ·
91ea48178a965b4e604ef3e4380a9e25· first seen 2026-08-17 - Phishing - referenced ·
4f754845d2250c5dfc528508852f7409· first seen 2026-08-16 - Phishing - referenced ·
2da6bd63f26243e492456005e8e3926e· first seen 2026-08-15 - Phishing - referenced ·
d449af0c0a5de6078cf8bc48b742d3e3· first seen 2026-08-14 - Phishing - referenced ·
59fbd166a8166b66da348036c63f3073· first seen 2026-08-13
Antivirus & YARA (1 of 48 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- File download routed to the malware sandbox (menofugunile.pdf)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- LiteSpeed
Contacted infrastructure
- 84.2.35.185 - AS5483 Magyar Telekom plc. (Hungary)
Files served by this page
- menofugunile.pdf ·
569fef15dcea33d188b55b824d14d2a6
Observed indicators
- presstone.hu
- 84.2.35.185
- https://presstone.hu/userfiles/file/menofugunile.pdf
Other scans of presstone.hu (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious
- 13 Aug 2026 - suspicious ·
https://presstone.hu/userfiles/file/vezadifovajafum.pdf - 13 Aug 2026 - suspicious ·
https://presstone.hu/userfiles/file/vezadifovajafum.pdf - 13 Aug 2026 - suspicious ·
https://presstone.hu/userfiles/file/vezadifovajafum.pdf
Questions about presstone.hu
- Is presstone.hu safe?
- No. MalwareAnalyzer scanned presstone.hu on 23 Aug 2026 and returned a suspicious verdict with a score of 42 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with presstone.hu?
- 8 analysed samples communicate with this URL, including Phishing.
- How was presstone.hu checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of presstone.hu
Scanned on MalwareAnalyzer by Cyble · Open interactive scan