purchasecloud.io - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned purchasecloud.io and returned a suspicious verdict (score 31), categorised as phishing. The page resolved to 104.21.96.100 on Cloudflare, Inc. in US. 10 domains and 5 IPs were contacted, over 19 HTTP requests. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 31) · Confidence 37%
- Scanned URL:
http://purchasecloud.io/ - Domain: purchasecloud.io · IP: 104.21.96.100 · AS13335 · US
- Server: cloudflare
- Page title: TransIP - Reserved domain
- HTTP status: 200 · text/html
- HTTP requests captured: 19 · outgoing links: 25
- Scan tier: standard · observed 2026-08-22 23:09:15 UTC
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Domain impersonates chase (combosquat)
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.21.96.100 - AS13335 Cloudflare, Inc. (United States)
- 172.67.176.147 - AS13335 Cloudflare, Inc. (United States)
- 37.97.254.27 - AS20857 Signet B.V. (Netherlands)
- 142.250.207.3 - AS15169 Google LLC (Japan)
Observed indicators
- purchasecloud.io
- reserved.transip.nl
- fonts.googleapis.com
- transip.nl
- transip.eu
- www.transip.nl
- www.transip.eu
- nl.trustpilot.com
- trustpilot.com
- fonts.gstatic.com
- 104.21.96.100
- 172.67.176.147
- 142.250.195.170
- 37.97.254.27
- 142.250.207.3
- http://purchasecloud.io/
- http://reserved.transip.nl/assets/img/favicon.ico
- https://fonts.googleapis.com/css?family=Source+Sans+Pro:400,900
- http://reserved.transip.nl/assets/css/combined-min.css
- https://transip.nl/
Questions about purchasecloud.io
- Is purchasecloud.io safe?
- No. MalwareAnalyzer scanned purchasecloud.io on 22 Aug 2026 and returned a suspicious verdict with a score of 31 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- How was purchasecloud.io checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of purchasecloud.io
Scanned on MalwareAnalyzer by Cyble · Open interactive scan