vibrobeton.by - suspicious URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned vibrobeton.by and returned a suspicious verdict (score 24), categorised as credential-harvest. The page resolved to 87.232.64.131 on Magnet Networks in IE. 6 domains and 1 IP were contacted, over 32 HTTP requests. 4 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 24) · Confidence 30%
- Scanned URL:
http://vibrobeton.by/pics/files/73911333167.pdf - Domain: vibrobeton.by · IP: 87.232.64.131 · AS34245 · IE
- Server: nginx/1.30.4
- Page title: Ошибка 404
- HTTP status: 404 · text/html; charset=utf-8
- HTTP requests captured: 32
- Scan tier: fast · observed 2026-08-24 06:47:09 UTC
Malware communicating with this URL (4)
These samples were observed contacting or being served from vibrobeton.by. Each links to its full analysis.
- Phishing - referenced ·
fc6a41169b14b564ed87c386e30315c3· first seen 2026-08-24 - Phishing - referenced ·
dcb36bd697c605e975c0a5fe1f7a3c52· first seen 2026-08-24 - Phishing - referenced ·
557d2b30839505456e29a93415153fae· first seen 2026-08-22 - Phishing - referenced ·
7b1e943b868df0ad2520172707d372e7· first seen 2026-08-22
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Nginx
- PHP
- Google Analytics
- jQuery
Contacted infrastructure
- 87.232.64.131 - AS34245 Magnet Networks (Ireland)
Observed indicators
- vibrobeton.by
- www.googletagmanager.com
- cdnjs.cloudflare.com
- yandex.by
- mc.yandex.ru
- code.jivo.ru
- 87.232.64.131
- http://vibrobeton.by/pics/files/73911333167.pdf
- https://www.googletagmanager.com/gtm.js?id=
- https://www.googletagmanager.com/gtag/js?id=G-YBERC5NQR4
- https://www.googletagmanager.com/gtag/js?id=AW-17214128470
- https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.0/css/all.min.css
- https://vibrobeton.by/mg-templates/mg-william/components/pagination/pagination.css?rev=1589885238
- https://vibrobeton.by/mg-plugins/blog/css/style.css?rev=1591603480
- https://vibrobeton.by/mg-plugins/mg-brand/css/brand.css?rev=1591278740
- https://vibrobeton.by/mg-plugins/mg-brand/css/owl.carousel.css?rev=1591278740
- https://vibrobeton.by/mg-plugins/buy-click/css/style.css?rev=1593670652
- https://vibrobeton.by/mg-plugins/buy-click/css/jquery.fancybox.min.css?rev=1593670652
- https://vibrobeton.by/mg-templates/mg-william/lib/dialog-polyfill/dialog-polyfill.css?rev=1589885238
- https://vibrobeton.by/mg-templates/mg-william/components/agreement/agreement.css?rev=1589885238
Other scans of vibrobeton.by (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 24 Aug 2026 - suspicious
- 22 Aug 2026 - suspicious ·
http://vibrobeton.by/pics/files/62969189573.pdf
Questions about vibrobeton.by
- Is vibrobeton.by safe?
- No. MalwareAnalyzer scanned vibrobeton.by on 24 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with vibrobeton.by?
- 4 analysed samples communicate with this URL, including Phishing.
- How was vibrobeton.by checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of vibrobeton.by
Scanned on MalwareAnalyzer by Cyble · Open interactive scan