trafffi.ru - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned trafffi.ru and returned a unknown verdict (score 0). The page resolved to 103.224.182.253 on Trellian Pty. Limited in US. 1 domain and 1 IP were contacted, over 1 HTTP request. 706 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 0%
- Scanned URL:
https://trafffi.ru/123?utm_term=visual+basic+for+applications+excel+pdf - Domain: trafffi.ru · IP: 103.224.182.253 · AS133618 · US
- Server: Apache
- Page title: trafffi.ru
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-19 14:18:42 UTC
Malware communicating with this URL (706)
These samples were observed contacting or being served from trafffi.ru. Each links to its full analysis.
- Phishing - referenced ·
cc3bf6d93376abb4435dc4a5fa9cb1a3· first seen 2026-08-19 - Phishing - referenced ·
f3c46d3fdad35ffa7d0edb2d2779836b· first seen 2026-08-19 - Phishing - referenced ·
0d0cda07763810ebe872293ab74ce44b· first seen 2026-08-19 - Phishing - referenced ·
5e4ae5e2f8ec08140272c114d77f3b35· first seen 2026-08-19 - Phishing - referenced ·
b62770ef751698340b7a90a28b5ddbe4· first seen 2026-08-19 - Phishing - referenced ·
4df3168e73272eb0033af9980f626079· first seen 2026-08-19 - Phishing - referenced ·
faab6ca1cafdbf1147c6387241e67b64· first seen 2026-08-19 - normal_60102d2d59625.pdf - referenced ·
1ad87c6c9d8749c312c968eee446b969· first seen 2026-08-19 - Phishing - referenced ·
61c4e49c58309b42d15f5abe8f9a8795· first seen 2026-08-19 - Phishing - referenced ·
525d4cecaa0cd80a205b79677e4ec660· first seen 2026-08-19 - Phishing - referenced ·
8c964bc6250553a476d6eee2b78650ae· first seen 2026-08-17 - Phishing - referenced ·
d80984efeff1d6d4e150e2e4678177e4· first seen 2026-08-17 - normal_5fa5679473c83.pdf - referenced ·
523542278a5d1c37850b3e98ccf9296e· first seen 2026-08-17 - Phishing - referenced ·
19496fdde5752993e599c39d4ac35d8c· first seen 2026-08-17 - Phishing - referenced ·
7d5f7d7fa546615e392dffce9c6b6d01· first seen 2026-08-17
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Detected technologies
- Apache
Contacted infrastructure
- 103.224.182.253 - AS133618 Trellian Pty. Limited (United States)
Observed indicators
- trafffi.ru
- 103.224.182.253
- https://trafffi.ru/123?utm_term=visual+basic+for+applications+excel+pdf
- https://trafffi.ru/js/fingerprint/iife.min.js
- http://trafffi.ru/123?utm_term=visual+basic+for+applications+excel+pdf&tr_uuid=20260820-0018-435a-8cba-d98e49836bec&fp=-3
Other scans of trafffi.ru (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=practice+direct+variation+worksheet+3.4+answers - 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=finding+the+equation+of+a+line+worksheet+kuta - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=shivprasad+koirala+7th+edition+pdf - 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=cedar+heights+apartments+omaha - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=bond+hearing+in+spanish - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=bond+hearing+in+spanish - 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=unit+4+worksheet+2 - 19 Aug 2026 - unknown ·
https://trafffi.ru/strik?utm_term=unit+4+worksheet+2 - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=tv+lg+42lb5800+manual - 19 Aug 2026 - unknown ·
https://trafffi.ru/123?utm_term=tv+lg+42lb5800+manual
Questions about trafffi.ru
- Is trafffi.ru safe?
- The scan of trafffi.ru on 19 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with trafffi.ru?
- 706 analysed samples communicate with this URL, including Phishing.
- How was trafffi.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of trafffi.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan