uralstar.ru - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned uralstar.ru and returned a unknown verdict (score 16), categorised as credential-harvest. The page resolved to 185.173.94.221 on Adman LLC in RU. 7 domains and 1 IP were contacted, over 4 HTTP requests. 1 malware sample communicates with this URL. The request followed 1 redirect before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 16) · Confidence 22%
- Scanned URL:
http://www.uralstar.ru/upload/iblock/f79/f79616ba1ed4d46fbe80495523755ee5.jpeg - Domain: uralstar.ru · IP: 185.173.94.221 · AS57494 · RU
- Server: nginx/1.20.2
- Page title: Website uralstar.ru
- HTTP status: 404 · text/html; charset=UTF-8
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-24 04:02:31 UTC
Redirect chain
http://www.uralstar.ru/upload/iblock/f79/f79616ba1ed4d46fbe80495523755ee5.jpeghttp://uralstar.ru/upload/iblock/f79/f79616ba1ed4d46fbe80495523755ee5.jpeg
Malware communicating with this URL (1)
These samples were observed contacting or being served from uralstar.ru. Each links to its full analysis.
- 2f935614fdfbd291b5643fdb596bd8f0e08df17735043fb67783abd11cde19e0 - referenced ·
2f935614fdfbd291b5643fdb596bd8f0· first seen 2026-08-24
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Nginx
- PHP
- jQuery
- Bootstrap
Contacted infrastructure
- 185.173.94.221 - AS57494 Adman LLC (Russian Federation)
Observed indicators
- uralstar.ru
- kit.fontawesome.com
- fonts.googleapis.com
- use.fontawesome.com
- t.me
- max.ru
- mc.yandex.ru
- 185.173.94.221
- http://uralstar.ru/upload/iblock/f79/f79616ba1ed4d46fbe80495523755ee5.jpeg
- http://uralstar.ru/i/favicon2.jpg
- https://kit.fontawesome.com/96d608bac5.js
- https://fonts.googleapis.com/css?family=Poppins:100,200,300,400,500,600,700,800,900
- http://uralstar.ru/themes/2/vendor/bootstrap/css/bootstrap.min.css
- http://uralstar.ru/themes/2/vendor/font-awesome/css/all.min.css
- http://uralstar.ru/themes/2/css/stylesheet.css
- https://use.fontawesome.com/releases/v6.4.4/css/all.css
- http://uralstar.ru/?lang=ru
- http://uralstar.ru/?lang=en
- https://t.me/Grossgroupru
- https://max.ru/u/f9LHodD0cOK4I2vS7dqiABo7dyAFG8XaSes-YjLBfEzTGBwNkVVgucPXV8U
Questions about uralstar.ru
- Is uralstar.ru safe?
- The scan of uralstar.ru on 24 Aug 2026 reached no verdict either way (score 16). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with uralstar.ru?
- 1 analysed samples communicate with this URL.
- How was uralstar.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of uralstar.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan