suitefacebookleadintegration.varianceinfotech.net - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned suitefacebookleadintegration.varianceinfotech.net and returned a malicious verdict (score 61), categorised as credential-harvest. The page resolved to 159.89.34.122 on DigitalOcean, LLC in US. The domain was registered 3396 days ago through GoDaddy.com, LLC. 3 domains and 1 IP were contacted, over 40 HTTP requests. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 61) · Confidence 76%
- Scanned URL:
https://suitefacebookleadintegration.varianceinfotech.net/index.php?action=Login&module=Users - Domain: suitefacebookleadintegration.varianceinfotech.net · IP: 159.89.34.122 · AS14061 · US
- Server: Apache/2.4.29 (Ubuntu)
- Page title: SuiteCRM
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: GoDaddy.com, LLC · domain age 3396 days · created 2017-05-03
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 17 21: · subject CN=suitefacebookleadintegration.varianceinfotech.net
- HTTP requests captured: 40 · cookies set: 2 · outgoing links: 2
- Scan tier: standard · observed 2026-08-20 15:38:15 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_Maldoc_VBA_AutoExec
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Certificate issued < 48h ago
- Matches phishing-kit family "u-admin (uAdmin)"
Detected technologies
- Apache
Contacted infrastructure
- 159.89.34.122 - AS14061 DigitalOcean, LLC (United States)
Observed indicators
- suitefacebookleadintegration.varianceinfotech.net
- oss.maxcdn.com
- www.suitecrm.com
- 159.89.34.122
- https://suitefacebookleadintegration.varianceinfotech.net/index.php?action=Login&module=Users
- https://suitefacebookleadintegration.varianceinfotech.net/themes/SuiteP/images/sugar_icon.ico?v=9bipRPQYATglxw83jFOd3w
- https://suitefacebookleadintegration.varianceinfotech.net/themes/SuiteP/css/normalize.css
- https://suitefacebookleadintegration.varianceinfotech.net/themes/SuiteP/css/fonts.css
- https://suitefacebookleadintegration.varianceinfotech.net/themes/SuiteP/css/grid.css
- https://suitefacebookleadintegration.varianceinfotech.net/themes/SuiteP/css/footable.core.css
- https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js
- https://oss.maxcdn.com/respond/1.4.2/respond.min.js
- https://suitefacebookleadintegration.varianceinfotech.net/cache/include/javascript/sugar_grp1_jquery.js?v=9bipRPQYATglxw83jFOd3w
- https://suitefacebookleadintegration.varianceinfotech.net/cache/include/javascript/sugar_grp1_yui.js?v=9bipRPQYATglxw83jFOd3w
- https://suitefacebookleadintegration.varianceinfotech.net/cache/include/javascript/sugar_grp1.js?v=9bipRPQYATglxw83jFOd3w
- https://suitefacebookleadintegration.varianceinfotech.net/include/javascript/calendar.js?v=9bipRPQYATglxw83jFOd3w
- https://suitefacebookleadintegration.varianceinfotech.net/cache/themes/SuiteP/js/style.js?v=9bipRPQYATglxw83jFOd3w
- https://suitefacebookleadintegration.varianceinfotech.net/include/javascript/qtip/jquery.qtip.min.css
- https://suitefacebookleadintegration.varianceinfotech.net/include/javascript/jquery/themes/base/jquery.ui.all.css
- https://suitefacebookleadintegration.varianceinfotech.net/cache/themes/SuiteP/css/Dawn/style.css?v=9bipRPQYATglxw83jFOd3w
Questions about suitefacebookleadintegration.varianceinfotech.net
- Is suitefacebookleadintegration.varianceinfotech.net safe?
- No. MalwareAnalyzer scanned suitefacebookleadintegration.varianceinfotech.net on 20 Aug 2026 and returned a malicious verdict with a score of 61 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- How was suitefacebookleadintegration.varianceinfotech.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of suitefacebookleadintegration.varianceinfotech.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan