trafffi.ru - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned trafffi.ru and returned a unknown verdict (score 0). The page resolved to 103.224.182.253 on Trellian Pty. Limited in US. 1 domain and 1 IP were contacted, over 1 HTTP request. 727 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 0%
- Scanned URL:
https://trafffi.ru/123?utm_term=practice+direct+variation+worksheet+3.4+answers - Domain: trafffi.ru · IP: 103.224.182.253 · AS133618 · US
- Server: Apache
- Page title: trafffi.ru
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-19 21:55:45 UTC
Malware communicating with this URL (727)
These samples were observed contacting or being served from trafffi.ru. Each links to its full analysis.
- Phishing - referenced ·
5b3acf6f20174c1b3a4b77dbab3827b6· first seen 2026-08-19 - Phishing - referenced ·
3ff0f6788b6b42dac97d9f3a357071d7· first seen 2026-08-19 - Phishing - referenced ·
c55a96dc878d89f3ee438eac19007601· first seen 2026-08-19 - Phishing - referenced ·
07234c1c76c8005998ce3cdc3f4ad38f· first seen 2026-08-19 - Phishing - referenced ·
228c1733e004c17f01393ce7b8f727cb· first seen 2026-08-19 - normal_5fa77f68e0f7c.pdf - referenced ·
e8fc2888416d79a772f459b7143dd269· first seen 2026-08-19 - Phishing - referenced ·
f7620f291dc1f9766fec7f2be2a5741d· first seen 2026-08-19 - normal_5fa6db32010ec.pdf - referenced ·
8e151ce72b4340dde9d47f905992c1fd· first seen 2026-08-19 - Phishing - referenced ·
5e69cc3f5b7c3f701f41e75a5d6599ed· first seen 2026-08-19 - Phishing - referenced ·
4c2d8384fd41b6bae5695f6c3a9f9ac0· first seen 2026-08-19 - Phishing - referenced ·
7d23a9a2b867c064e78e08e55a8fd5d8· first seen 2026-08-19 - Phishing - referenced ·
086f1afac4c031c747b759ba58a99429· first seen 2026-08-19 - Phishing - referenced ·
d5e585fdc2d6d463a16137bfab90199d· first seen 2026-08-19 - Phishing - referenced ·
a6f6ff7cce0110e3798ed479efad90b9· first seen 2026-08-19 - normal_5fa507067b84a.pdf - referenced ·
37849962d5c354e5af8035b2f6723aa9· first seen 2026-08-19
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Detected technologies
- Apache
Contacted infrastructure
- 103.224.182.253 - AS133618 Trellian Pty. Limited (United States)
Observed indicators
- trafffi.ru
- 103.224.182.253
- https://trafffi.ru/123?utm_term=practice+direct+variation+worksheet+3.4+answers
- https://trafffi.ru/js/fingerprint/iife.min.js
- http://trafffi.ru/123?utm_term=practice+direct+variation+worksheet+3.4+answers&tr_uuid=20260820-0755-45a4-91dd-ab3f00d54a25&fp=-3
Other scans of trafffi.ru (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=finding+the+equation+of+a+line+worksheet+kuta - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=shivprasad+koirala+7th+edition+pdf - 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=cedar+heights+apartments+omaha - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=bond+hearing+in+spanish - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=bond+hearing+in+spanish - 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=unit+4+worksheet+2 - 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=unit+4+worksheet+2 - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=tv+lg+42lb5800+manual - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=tv+lg+42lb5800+manual - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=serengeti+plain+physical+map
Questions about trafffi.ru
- Is trafffi.ru safe?
- The scan of trafffi.ru on 19 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with trafffi.ru?
- 727 analysed samples communicate with this URL, including Phishing.
- How was trafffi.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of trafffi.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan