spaslask.pl - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned spaslask.pl and returned a unknown verdict (score 12). The page resolved to 185.135.91.92 on LH.pl Sp. z o.o. in PL. The domain was registered 2969 days ago through LH.pl Sp. z o.o.. 4 domains and 1 IP were contacted, over 20 HTTP requests. 8 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 12) · Confidence 15%
- Scanned URL:
https://spaslask.pl/wp-content/plugins/super-forms/uploads/php/files/3oa57os82sif81u7al7uhlmvgk/29839803132.pdf - Domain: spaslask.pl · IP: 185.135.91.92 · AS203417 · PL
- Server: Apache
- Page title: Strona nie została znaleziona – Holistic Spa
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: LH.pl Sp. z o.o. · domain age 2969 days · created 2018-07-03
- Registrant country: PL
- Evidenced operator: Marcin Pohl
- HTTP requests captured: 20
- Scan tier: fast · observed 2026-08-19 21:09:07 UTC
Malware communicating with this URL (8)
These samples were observed contacting or being served from spaslask.pl. Each links to its full analysis.
- Phishing - referenced ·
a56ad28dabcfe8ecdcba068c1d23ebd2· first seen 2026-08-19 - Phishing - referenced ·
d938b78002592800bd66c72ae7615bfc· first seen 2026-08-17 - Phishing - referenced ·
2188114a6848df41724226e37d09ccc3· first seen 2026-08-17 - Phishing - referenced ·
8677c346f095297e68cc23ebd5f3240a· first seen 2026-08-16 - Phishing - referenced ·
fc9e5ad76f479864395ef2c842fd1ca4· first seen 2026-08-15 - Phishing - referenced ·
a5eda7183dfd1bc95bea23bb8fa41a1b· first seen 2026-08-13 - Phishing - referenced ·
872e038993c8246a634b171e11154f31· first seen 2026-08-13 - Phishing - referenced ·
4fe0b0504e41cf2e182f1c3885cd4f04· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
Detected technologies
- Apache
- PHP
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 185.135.91.92 - AS203417 LH.pl Sp. z o.o. (Poland)
Observed indicators
- spaslask.pl
- www.googletagmanager.com
- fonts.googleapis.com
- www.facebook.com
- 185.135.91.92
- https://spaslask.pl/wp-content/plugins/super-forms/uploads/php/files/3oa57os82sif81u7al7uhlmvgk/29839803132.pdf
- https://spaslask.pl/feed/
- https://spaslask.pl/comments/feed/
- https://spaslask.pl/wp-includes/css/dist/block-library/style.min.css?ver=6.9.5
- https://spaslask.pl/wp-content/plugins/woocommerce/assets/client/blocks/wc-blocks.css?ver=wc-9.8.5
- https://spaslask.pl/wp-content/plugins/woo-przelewy24/assets/css/styles.css?ver=1.0.11
- https://spaslask.pl/wp-content/plugins/woocommerce/assets/css/brands.css?ver=9.8.5
- https://spaslask.pl/wp-content/themes/kadence/assets/css/global.min.css?ver=1.2.22
- https://spaslask.pl/wp-content/themes/kadence/assets/css/header.min.css?ver=1.2.22
- https://spaslask.pl/wp-content/themes/kadence/assets/css/content.min.css?ver=1.2.22
- https://spaslask.pl/wp-content/themes/kadence/assets/css/woocommerce.min.css?ver=1.2.22
- https://spaslask.pl/wp-content/themes/kadence/assets/css/footer.min.css?ver=1.2.22
- https://spaslask.pl/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://spaslask.pl/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
- https://spaslask.pl/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.7.0-wc.9.8.5
Questions about spaslask.pl
- Is spaslask.pl safe?
- The scan of spaslask.pl on 19 Aug 2026 reached no verdict either way (score 12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with spaslask.pl?
- 8 analysed samples communicate with this URL, including Phishing.
- How was spaslask.pl checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of spaslask.pl
Scanned on MalwareAnalyzer by Cyble · Open interactive scan