webmaster.yandex.ru - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned webmaster.yandex.ru and returned a suspicious verdict (score 42). The page resolved to 87.250.251.217 on Yandex enterprise network in RU. 6 domains and 3 IPs were contacted, over 3 HTTP requests. 1 malware sample communicates with this URL. The request followed 4 redirects before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 42) · Confidence 54%
- Scanned URL:
http://yandex.ru/cy?base=0& - Domain: webmaster.yandex.ru · IP: 87.250.251.217 · AS13238 · RU
- Page title: Are you not a robot?
- HTTP status: 200 · text/html
- TLS issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign GCC R46 OV TLS CA 2025 · valid to Feb 3 20: · subject C=RU, ST=Moscow, L=Moscow, O=YANDEX LLC, CN=webmaster.yandex.ru
- Evidenced operator: YANDEX LLC
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-22 13:42:07 UTC
Redirect chain
http://yandex.ru/cy?base=0&https://yandex.ru/cy?base=0&https://webmaster.yandex.ru/tic/?base=0&https://webmaster.yandex.ru/siteinfo/?base=0&https://webmaster.yandex.ru/showcaptcha?cc=1&form-fb-hint=2.23&mt=089009CEF5F60AEC3B1E014F8E2216DC706331A1D1B3625848598653BD05F2C7F381EA9733AE60AF77C0BAEE53555AB42DD848282A3C9C2354306879566F795F3302E26C9895D7A3028EFB0AEC3F0731B81C014AC32416AF7C96192C176134BFF95E20F35219A554DDC7A596E3BAB702978767C0FCB9F97EE98CBB365B41B0D81022FE3979D8B2ED4E02A145D534F956118173B7C197B2E931F139BABC1C98390DCBAB64812E04DD79E79F941B85462A22590F69D6C8FA56BBE3A36FE54F08421445582690BD80321E26AED84762A15ED700EA4EEA3E691AB8353E8F94238CA2704B387286C80FFD3F81064867D018D0FF&retpath=aHR0cHM6Ly93ZWJtYXN0ZXIueWFuZGV4LnJ1L3NpdGVpbmZvP2Jhc2U9MCZhbXA%2C_b46b4e4e8d95a4303c02991a836b24e9&t=2%252F1787406132%252Ff4a071ab927203ed2570b9b30b0f1c70&u=9270330622022028591&s=08d8a0ad470d1b282ea53376e589bfd7
Malware communicating with this URL (1)
These samples were observed contacting or being served from webmaster.yandex.ru. Each links to its full analysis.
- f9910712ef77f0a0aea9405495d88e548bd8d17614656cf11e9c1e86bc1ea6cc - referenced ·
f9910712ef77f0a0aea9405495d88e54· first seen 2026-08-22
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
- Long redirect chain (4 hops)
- Cross-host redirect chain
Contacted infrastructure
- 87.250.251.217 - AS13238 Yandex enterprise network (Russian Federation)
- 77.88.44.55 - AS13238 Yandex enterprise network (Russian Federation)
- 5.255.255.77 - AS13238 Yandex enterprise network (Russian Federation)
Observed indicators
- webmaster.yandex.ru
- www.yandex.com
- yandex.com
- yandex.cloud
- mc.yandex.ru
- adfstat.yandex.ru
- 87.250.251.217
- 77.88.44.55
- 5.255.255.77
- https://webmaster.yandex.ru/showcaptcha?cc=1&form-fb-hint=2.23&mt=089009CEF5F60AEC3B1E014F8E2216DC706331A1D1B3625848598653BD05F2C7F381EA9733AE60AF77C0BAEE53555AB42DD848282A3C9C2354306879566F795F3302E26C9895D7A3028EFB0AEC3F0731B81C014AC32416AF7C96192C176134BFF95E20F35219A554DDC7A596E3BAB702978767C0FCB9F97EE98CBB365B41B0D81022FE3979D8B2ED4E02A145D534F956118173B7C197B2E931F139BABC1C98390DCBAB64812E04DD79E79F941B85462A22590F69D6C8FA56BBE3A36FE54F08421445582690BD80321E26AED84762A15ED700EA4EEA3E691AB8353E8F94238CA2704B387286C80FFD3F81064867D018D0FF&retpath=aHR0cHM6Ly93ZWJtYXN0ZXIueWFuZGV4LnJ1L3NpdGVpbmZvP2Jhc2U9MCZhbXA%2C_b46b4e4e8d95a4303c02991a836b24e9&t=2%252F1787406132%252Ff4a071ab927203ed2570b9b30b0f1c70&u=9270330622022028591&s=08d8a0ad470d1b282ea53376e589bfd7
- https://webmaster.yandex.ru/captcha_smart.777469aa44ab5078.min.css?k=1784114118880
- https://www.yandex.com/
- https://webmaster.yandex.ru/checkcaptcha?key=b041068d-ccf0ed67-91ec8bce-c14edf68_2/1787406132/f4a071ab927203ed2570b9b30b0f1c70_a32eee66de99bb0ad3b8745af25a3774&mt=74547E65CE1991A39944F56664FEF4B9F0188AE9B9939E8E633BC77E645600C6959D5CB20B0B1BF654AC6E341DBFDAF177840E820C35B6F703C0D0E1445D2A45DB856F3DB62074C30E7CDD19A032576D6A5922EBD0CF554EADCE5F37D48A8F5F5729D2F5256E59CED7EF1F210A7F37FBCB0B5C77C00AA3811C11E15D656087CE6C95D4198EFC3C9A4195985A357681840823648BA91D226C7FE3A998EE7879193D1CA91645703605EBBBDD2D9207D81CBE2ABE14CF42608513954049B4ED0FFD20085758AC3EDC5D68AA1B900EC750E2646B53DCFF680A53E163E694A3384E916AAEE68EA31AD2C8F2C51B990E2637B827&retpath=aHR0cHM6Ly93ZWJtYXN0ZXIueWFuZGV4LnJ1L3NpdGVpbmZvP2Jhc2U9MCZhbXA%2C_b46b4e4e8d95a4303c02991a836b24e9&u=9270330622022028591&s=8b21698dc1eee902fc93c5c1f484b349
- https://yandex.com/support/smart-captcha/problems.html?form-unique_key=9270330622022028591&form-fb-hint=2.23
- https://yandex.com/support/common/browsers-settings/browsers-java-js-settings.html
- https://yandex.cloud/en/services/smartcaptcha?utm_source=captcha&utm_medium=chbx&utm_campaign=security
- https://webmaster.yandex.ru/captcha_smart_error.15fc2e891ddec37d.min.js?k=1784114118880
- https://webmaster.yandex.ru/captcha_smart_react.min.js?k=1784114118880
- https://webmaster.yandex.ru/captcha_smart.97fa680e43938985.js?k=1784114118880
- https://mc.yandex.ru/metrika/tag.js
Other scans of webmaster.yandex.ru (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - unknown ·
https://z-oleg.com/
Questions about webmaster.yandex.ru
- Is webmaster.yandex.ru safe?
- No. MalwareAnalyzer scanned webmaster.yandex.ru on 22 Aug 2026 and returned a suspicious verdict with a score of 42 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with webmaster.yandex.ru?
- 1 analysed samples communicate with this URL.
- How was webmaster.yandex.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of webmaster.yandex.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan