prodesign31.ru - URL scan, 13 Aug 2026
MalwareAnalyzer by Cyble scanned prodesign31.ru and returned a unknown verdict (score 16), categorised as credential-harvest. The page resolved to 92.53.96.174 on TimeWeb Ltd. in RU. 20 domains and 1 IP were contacted, over 34 HTTP requests. 10 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 13 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 16) · Confidence 22%
- Scanned URL:
http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16130fd916ce72---89727043949.pdf - Domain: prodesign31.ru · IP: 92.53.96.174 · AS9123 · RU
- Server: nginx/1.30.4
- Page title: prodesign31.ru | Дизайн и проектирование интерьеров в Старом Осколе, Белгороде и Белгородской области
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 34
- Scan tier: fast · observed 2026-08-13 14:05:47 UTC
Redirect chain
http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16130fd916ce72---89727043949.pdfhttp://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16130fd916ce72---89727043949.pdf/
Malware communicating with this URL (10)
These samples were observed contacting or being served from prodesign31.ru. Each links to its full analysis.
- Phishing - referenced ·
30fcd6a072a0fbed69222f98403e0cf0· first seen 2026-08-13 - Phishing - referenced ·
fb6af4bbc6b1c01c25981853979623dc· first seen 2026-08-13 - Phishing - referenced ·
16e8e8f8e1529abe20225b55529517f2· first seen 2026-08-13 - Phishing - referenced ·
7acb12a5369d2d571ca244a97cfbe01a· first seen 2026-08-12 - Phishing - referenced ·
acf543cb50566e3bcc54b29ba8f72c6b· first seen 2026-08-12 - Phishing - referenced ·
7e3c66ef2b709048f2784eea470f94a8· first seen 2026-08-12 - 62962376954.pdf - referenced ·
118f7f285ae2cec2a241f99e9e034322· first seen 2026-08-12 - Phishing - referenced ·
ffa4242ec797bdcf9be6af3fa664dadb· first seen 2026-08-12 - Phishing - referenced ·
fc79704018bab66e6f99a9d882479a08· first seen 2026-08-11 - Phishing - referenced ·
772c221b7c7bf425e99f8ed3c6a48ce9· first seen 2026-08-11
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Nginx
- WordPress
- jQuery
Contacted infrastructure
- 92.53.96.174 - AS9123 TimeWeb Ltd. (Russian Federation)
Observed indicators
- prodesign31.ru
- gmpg.org
- fonts.googleapis.com
- www.google.com
- s.w.org
- www.proremont31.ru
- umnyj-doms.ru
- stroibat.pro
- stariy-oskol.estetdveri.ru
- oskol.ideya-parketa.ru
- ove-cfo.ru
- www.plasters.ru
- bioart-kamin.ru
- affresco.ru
- perfect-russia.ru
- www.artpole.ru
- svetitled.ru
- api-maps.yandex.ru
- advtandem.ru
- mc.yandex.ru
Other scans of prodesign31.ru (5)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/1613fe66bc11a2-- - 17 Aug 2026 - unknown ·
http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16085352d02015-- - 13 Aug 2026 - unknown ·
http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160c888d2c9a52-- - 12 Aug 2026 - unknown ·
http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/16134b88263882-- - 12 Aug 2026 - unknown ·
http://prodesign31.ru/wp-content/plugins/formcraft/file-upload/server/content/files/160a8ab3a945cb--
Questions about prodesign31.ru
- Is prodesign31.ru safe?
- The scan of prodesign31.ru on 13 Aug 2026 reached no verdict either way (score 16). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with prodesign31.ru?
- 10 analysed samples communicate with this URL, including Phishing.
- How was prodesign31.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of prodesign31.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan