serahi.rozblog.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned serahi.rozblog.com and returned a suspicious verdict (score 36), categorised as credential-harvest. The page resolved to 178.216.251.232 on Asiatech Data Transmission company in IR. The domain was registered 6100 days ago through Key-Systems GmbH. 11 domains and 1 IP were contacted, over 5 HTTP requests. 1 malware sample communicates with this URL. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 36) · Confidence 45%
- Scanned URL:
http://serahi.rozblog.com/ - Domain: serahi.rozblog.com · IP: 178.216.251.232 · AS43754 · IR
- Server: LiteSpeed
- Page title: سه راهی
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: Key-Systems GmbH · domain age 6100 days · created 2009-12-07
- HTTP requests captured: 5
- Scan tier: fast · observed 2026-08-21 15:52:22 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from serahi.rozblog.com. Each links to its full analysis.
- 32319409744622768bdaef899a4d829dba00a2cc555b70d6395c3eef96b0fd49 - referenced ·
32319409744622768bdaef899a4d829d· first seen 2026-08-21
Antivirus & YARA (1 of 47 engines)
- YARA: Yara-Rules community [yara]: YR_AntiVM_Sandbox (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- A signature matched text in the page (YR_AntiVM_Sandbox) — pages that discuss malware can match, so this alone is not a malicious verdict
- Served over plaintext HTTP
Detected technologies
- LiteSpeed
Contacted infrastructure
- 178.216.251.232 - AS43754 Asiatech Data Transmission company (Iran, Islamic Republic of)
Observed indicators
- serahi.rozblog.com
- rozblog.com
- www.rozblog.com
- navaran.com
- www.multijob.ir
- up.multijob.ir
- multijob.ir
- rasekhoon.net
- chabudai.sakura.ne.jp
- rozup.ir
- dl.bourseiness.com
- 178.216.251.232
- http://serahi.rozblog.com/
- https://rozblog.com/include/rozblog_ads_js.php?6
- https://rozblog.com/temp/site.css?38.8
- https://serahi.rozblog.com/
- https://serahi.rozblog.com/rss.xml
- https://serahi.rozblog.com/pages/2
- http://serahi.rozblog.com/temp/ghalebgraph/eshghafarin/images/favicon.png
- http://serahi.rozblog.com/temp/ghalebgraph/eshghafarin/style2.css
Other scans of serahi.rozblog.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - suspicious ·
http://serahi.rozblog.com/post/39
Questions about serahi.rozblog.com
- Is serahi.rozblog.com safe?
- No. MalwareAnalyzer scanned serahi.rozblog.com on 21 Aug 2026 and returned a suspicious verdict with a score of 36 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with serahi.rozblog.com?
- 1 analysed samples communicate with this URL.
- How was serahi.rozblog.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of serahi.rozblog.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan