tubietelbar.hu - suspicious URL scan, 15 Aug 2026
MalwareAnalyzer by Cyble scanned tubietelbar.hu and returned a suspicious verdict (score 35), categorised as credential-harvest, impersonating paypal. The page resolved to 172.67.196.210 on Cloudflare, Inc. in US. 2 domains and 1 IP were contacted, over 4 HTTP requests. 6 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 15 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 35) · Confidence 44%
- Scanned URL:
http://tubietelbar.hu/uploadfile/65622438628.pdf - Domain: tubietelbar.hu · IP: 172.67.196.210 · AS13335 · US
- Server: cloudflare
- HTTP status: 200 · text/html
- HTTP requests captured: 4
- Scan tier: standard · observed 2026-08-15 17:40:07 UTC
Malware communicating with this URL (6)
These samples were observed contacting or being served from tubietelbar.hu. Each links to its full analysis.
- Phishing - referenced ·
ba9f90df632382ed0cf2c3ed85ff69c6· first seen 2026-08-15 - Phishing - referenced ·
760d67cb3b4a0bf2331e396494472e31· first seen 2026-08-15 - Phishing - referenced ·
7cf940f56680805da4b9344c422a6fce· first seen 2026-08-14 - Phishing - referenced ·
1f3cc641371dbd7e9f9543713eb9d544· first seen 2026-08-14 - Phishing - referenced ·
5cfec46ab291341c99b369adfa8bfbab· first seen 2026-08-13 - Phishing - referenced ·
11e24720519c340b35619defa9df4f4c· first seen 2026-08-13
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Matches phishing-kit family "Generic PayPal Harvester"
- Served over plaintext HTTP
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.67.196.210 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- tubietelbar.hu
- www.facebook.com
- 172.67.196.210
- http://tubietelbar.hu/uploadfile/65622438628.pdf
- http://tubietelbar.hu/style/main.css?1
- http://tubietelbar.hu/style/lightbox.css
- http://tubietelbar.hu/script/prototype.js
- http://tubietelbar.hu/script/scriptaculous.js?load=effects,builder
- http://tubietelbar.hu/script/lightbox.js
- http://tubietelbar.hu/
- http://tubietelbar.hu/etlap
- http://tubietelbar.hu/galeria
- http://tubietelbar.hu/regisztracio
- http://tubietelbar.hu/elfelejtett_jelszo
- http://tubietelbar.hu/images/utalvanyok.jpg
- http://tubietelbar.hu/images/bankkartyak.jpg
- http://www.facebook.com/plugins/likebox.php?href=http%3A%2F%2Fwww.facebook.com%2Ftubietelbar.hu&width=185&height=300&show_faces=true&colorscheme=light&stream=false&border_color&header=false&appId=180405208688413
- http://tubietelbar.hu/images/banner.png
- https://www.facebook.com/tubietelbar/?ref=aymt_homepage_panel&eid=ARBEQlVfY7u4J7zSurtjdjU21xMe6DIkBr1XyIj0Bau8fiVy4b9N9m0rEYlYBVGaf89rD0VKezsey8Zo
- http://tubietelbar.hu/cdn-cgi/l/email-protection
Other scans of tubietelbar.hu (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/bozaxukepa.pdf - 23 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/bozaxukepa.pdf - 22 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/rimix.pdf - 20 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/41412955759.pdf - 15 Aug 2026 - suspicious
- 15 Aug 2026 - suspicious
- 13 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/22596144052.pdf - 13 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/14320038857.pdf - 13 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/14320038857.pdf - 13 Aug 2026 - suspicious ·
http://tubietelbar.hu/uploadfile/14320038857.pdf
Questions about tubietelbar.hu
- Is tubietelbar.hu safe?
- No. MalwareAnalyzer scanned tubietelbar.hu on 15 Aug 2026 and returned a suspicious verdict with a score of 35 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- Does tubietelbar.hu belong to paypal?
- No. This page claims the identity of paypal but nothing establishes that paypal operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- What malware is associated with tubietelbar.hu?
- 6 analysed samples communicate with this URL, including Phishing.
- How was tubietelbar.hu checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of tubietelbar.hu · Other paypal phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan