webmodels.studio - suspicious URL scan, 14 Aug 2026
MalwareAnalyzer by Cyble scanned webmodels.studio and returned a suspicious verdict (score 28). The page resolved to 78.140.140.250 on Webzilla B.V. in NL. The domain was registered 3445 days ago through GoDaddy.com, LLC. 7 domains and 1 IP were contacted, over 7 HTTP requests. 8 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 14 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/160725b2194eef---34505242850.pdf - Domain: webmodels.studio · IP: 78.140.140.250 · AS35415 · NL
- Page title: Ничего не найдено для % request_words%
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: GoDaddy.com, LLC · domain age 3445 days · created 2017-03-08
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Oct 25 13: · subject CN=*.lux.cam
- HTTP requests captured: 7
- Scan tier: fast · observed 2026-08-14 10:18:39 UTC
Malware communicating with this URL (8)
These samples were observed contacting or being served from webmodels.studio. Each links to its full analysis.
- Phishing - referenced ·
fd03f63b87387a347943e8a84e7f86cc· first seen 2026-08-14 - Phishing - referenced ·
d31c4b7a5d10076243ffc663912933a0· first seen 2026-08-14 - 0c9bb327f7da975e5ab9d13d1fe75c377443c01bade1907906d34bdd47572e36 - referenced ·
0c9bb327f7da975e5ab9d13d1fe75c37· first seen 2026-08-14 - Phishing - referenced ·
a50967c16db7859363cb6c03ba9608c4· first seen 2026-08-13 - Phishing - referenced ·
ac9e3110b2a7a513745902151df13a1e· first seen 2026-08-13 - Phishing - referenced ·
6c244f4c6f2be5d3f1191df345c77820· first seen 2026-08-13 - Phishing - referenced ·
ed06a3f8b4ae6bf3697f87526ae2c291· first seen 2026-08-12 - Phishing - referenced ·
e8266a0239725d519bc7d6c52458c85e· first seen 2026-08-12
Antivirus & YARA (1 of 44 engines)
- YARA: delivr.to detections [yara]: DLV_Maldoc_VBA_AutoExec (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_Maldoc_VBA_AutoExec
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 78.140.140.250 - AS35415 Webzilla B.V. (Netherlands)
Observed indicators
- webmodels.studio
- mc.yandex.ru
- fonts.googleapis.com
- ajax.googleapis.com
- code.jquery.com
- www.tenlister.me
- www.themekiller.me
- 78.140.140.250
- https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/160725b2194eef---34505242850.pdf
- https://mc.yandex.ru/metrika/watch.js
- https://mc.yandex.ru/watch/45143346
- https://fonts.googleapis.com/css?family=Roboto
- https://webmodels.studio/wp-content/themes/Avada/assets/js/html5shiv.js
- https://ajax.googleapis.com/ajax/libs/webfont/1.5.3/webfont.js
- https://webmodels.studio/feed/
- https://webmodels.studio/comments/feed/
- https://webmodels.studio/wp-content/uploads/2017/06/51XXJWSlqGL-1.png
- https://webmodels.studio/wp-content/plugins/formcraft/css/common.css?ver=2.0.3
- https://webmodels.studio/wp-content/plugins/formcraft/css/editor_form.css?ver=2.0.3
- https://webmodels.studio/wp-content/plugins/formcraft/css/fontello/css/formcraft.css?ver=2.0.3
Other scans of webmodels.studio (6)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - suspicious ·
https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/16138e07b1003 - 19 Aug 2026 - suspicious ·
https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/160bbd8056bd8 - 17 Aug 2026 - suspicious ·
https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/1607026d795f3 - 15 Aug 2026 - suspicious ·
https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/1607b03487ecf - 14 Aug 2026 - suspicious ·
https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/160bb53776ee7 - 12 Aug 2026 - unknown ·
https://webmodels.studio/wp-content/plugins/formcraft/file-upload/server/content/files/1611311fd67d3
Questions about webmodels.studio
- Is webmodels.studio safe?
- No. MalwareAnalyzer scanned webmodels.studio on 14 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with webmodels.studio?
- 8 analysed samples communicate with this URL, including Phishing.
- How was webmodels.studio checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of webmodels.studio
Scanned on MalwareAnalyzer by Cyble · Open interactive scan