spec-so.ru - suspicious URL scan, 14 Aug 2026
MalwareAnalyzer by Cyble scanned spec-so.ru and returned a suspicious verdict (score 28). The page resolved to 87.236.16.9 on Beget Ltd in RU. 1 domain and 1 IP were contacted, over 50 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 14 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
http://spec-so.ru/sites/default/files/file/93807508150.pdf - Domain: spec-so.ru · IP: 87.236.16.9 · AS198610 · RU
- Server: nginx-reuseport/1.21.1
- Page title: Страница не найдена
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 4 03: · subject CN=spec-so.ru
- HTTP requests captured: 50
- Scan tier: standard · observed 2026-08-14 23:34:02 UTC
Redirect chain
http://spec-so.ru/sites/default/files/file/93807508150.pdfhttps://spec-so.ru/sites/default/files/file/93807508150.pdf
Malware communicating with this URL (1)
These samples were observed contacting or being served from spec-so.ru. Each links to its full analysis.
- Phishing - referenced ·
d8b0f88f62dc9fbc1736bb46b0eae7cd· first seen 2026-08-14
Antivirus & YARA (1 of 44 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- PHP
- Drupal
- jQuery
Contacted infrastructure
- 87.236.16.9 - AS198610 Beget Ltd (Russian Federation)
Observed indicators
- spec-so.ru
- 87.236.16.9
- https://spec-so.ru/sites/default/files/file/93807508150.pdf
- https://spec-so.ru/bitrix/templates/aspro_max/css/fonts/montserrat/css/montserrat.min.css?16232359985716
- https://spec-so.ru/bitrix/templates/aspro_max/vendor/css/bootstrap.css?1619091982114216
- https://spec-so.ru/bitrix/templates/aspro_max/css/jquery.fancybox.css?161909198217412
- https://spec-so.ru/bitrix/templates/aspro_max/vendor/css/carousel/owl/owl.carousel.css?16190919824744
- https://spec-so.ru/bitrix/templates/aspro_max/vendor/css/carousel/owl/owl.theme.default.css?16190919821380
- https://spec-so.ru/bitrix/templates/aspro_max/css/styles.css?1623235998175384
- https://spec-so.ru/bitrix/templates/aspro_max/css/blocks/blocks.css?161909198218769
- https://spec-so.ru/bitrix/templates/aspro_max/css/blocks/common.blocks/counter-state/counter-state.css?1619091982320
- https://spec-so.ru/bitrix/templates/aspro_max/css/banners.css?161909198213096
- https://spec-so.ru/bitrix/templates/aspro_max/css/menu.css?161909198270758
- https://spec-so.ru/bitrix/templates/aspro_max/css/catalog.css?162323599810435
- https://spec-so.ru/bitrix/templates/aspro_max/css/animation/animation_ext.css?16190919824934
- https://spec-so.ru/bitrix/templates/aspro_max/css/jquery.mCustomScrollbar.min.css?161909198242839
- https://spec-so.ru/bitrix/templates/aspro_max/vendor/css/ripple.css?1619091982854
- https://spec-so.ru/bitrix/templates/aspro_max/css/left_block_main_page.css?161909198221557
- https://spec-so.ru/bitrix/templates/aspro_max/css/stores.css?161909198210017
- https://spec-so.ru/bitrix/templates/aspro_max/css/yandex_map.css?16190919827688
Other scans of spec-so.ru (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - suspicious ·
https://spec-so.ru/sites/default/files/file/ratopunorozatezojubi.pdf - 14 Aug 2026 - suspicious
Questions about spec-so.ru
- Is spec-so.ru safe?
- No. MalwareAnalyzer scanned spec-so.ru on 14 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with spec-so.ru?
- 1 analysed samples communicate with this URL, including Phishing.
- How was spec-so.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of spec-so.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan