tomboy2.com - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned tomboy2.com and returned a unknown verdict (score 6). The page resolved to 94.177.167.12 on Aruba S.p.A. - Dedicated servers in IT. The domain was registered 6696 days ago through GoDaddy.com, LLC. 1 domain and 1 IP were contacted. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 9%
- Scanned URL:
http://tomboy2.com/images/library/File/lobefos.pdf - Domain: tomboy2.com · IP: 94.177.167.12 · AS31034 · IT
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: GoDaddy.com, LLC · domain age 6696 days · created 2008-04-19
- Scan tier: standard · observed 2026-08-19 16:35:42 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from tomboy2.com. Each links to its full analysis.
- Phishing - referenced ·
8e30eba1f5d9bcf432fda2369e782bea· first seen 2026-08-14 - Phishing - referenced ·
2a0710ea903cfbb6c89c2e78fbba339b· first seen 2026-08-11
Why this verdict
- Served over plaintext HTTP
Detected technologies
- PHP
Contacted infrastructure
- 94.177.167.12 - AS31034 Aruba S.p.A. - Dedicated servers (Italy)
Observed indicators
- tomboy2.com
- 94.177.167.12
- http://tomboy2.com/images/library/File/lobefos.pdf
Other scans of tomboy2.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 11 Aug 2026 - unknown ·
http://tomboy2.com/images/library/File/mokozobavaxatezatez.pdf - 11 Aug 2026 - unknown ·
http://tomboy2.com/images/library/File/mokozobavaxatezatez.pdf
Questions about tomboy2.com
- Is tomboy2.com safe?
- The scan of tomboy2.com on 19 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with tomboy2.com?
- 2 analysed samples communicate with this URL, including Phishing.
- How was tomboy2.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of tomboy2.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan