kinofilms.tv - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned kinofilms.tv and returned a suspicious verdict (score 46), categorised as credential-harvest. The page resolved to 162.0.235.237 on Namecheap, Inc. in US. The domain was registered 327 days ago through NameCheap, Inc.. 11 domains and 1 IP were contacted, over 17 HTTP requests. 2 malware samples communicate with this URL. The request followed 2 redirects before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 46) · Confidence 55%
- Scanned URL:
http://kinofilms.tv/images/films/19/18701/pict/8.jpg - Domain: kinofilms.tv · IP: 162.0.235.237 · AS22612 · US
- Server: LiteSpeed
- Page title: КиноФильмы.TV - смотреть кино фильмы онлайн бесплатно и без регистрации!
- HTTP status: 200 · text/html
- Registrar: NameCheap, Inc. · domain age 327 days · created 2025-09-26
- Registrant country: IS
- TLS issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV R36 · valid to Sep 26 23: · subject CN=kinofilms.tv
- HTTP requests captured: 17
- Scan tier: fast · observed 2026-08-19 23:02:10 UTC
Redirect chain
http://kinofilms.tv/images/films/19/18701/pict/8.jpghttps://kinofilms.tv/images/films/19/18701/pict/8.jpghttps://kinofilms.tv/
Malware communicating with this URL (2)
These samples were observed contacting or being served from kinofilms.tv. Each links to its full analysis.
- 9a838d282b78b253100681953b544da6c36ee2761840024782f84134cdf7cddc - referenced ·
9a838d282b78b253100681953b544da6· first seen 2026-08-19 - 4d7bcbb03700331c5d937c692055c4a4e69e81bb7698804ab4dca700c18d6cb3 - referenced ·
4d7bcbb03700331c5d937c692055c4a4· first seen 2026-08-16
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- LiteSpeed
Contacted infrastructure
- 162.0.235.237 - AS22612 Namecheap, Inc. (United States)
Observed indicators
- kinofilms.tv
- analytics.ahrefs.com
- www.adobe.com
- post.rmbn.ru
- onlyfilms.ws
- www.liveinternet.ru
- counter.yadro.ru
- top100.rambler.ru
- n.adonweb.ru
- jsc.dt00.net
- ad.adriver.ru
- 162.0.235.237
- https://kinofilms.tv/
- https://kinofilms.tv/ruffle/ruffle.js
- https://analytics.ahrefs.com/analytics.js
- https://kinofilms.tv/themes/tvnew/style.css
- https://kinofilms.tv/themes/tvnew/images/favicon.ico
- https://kinofilms.tv/themes/tvnew/style.ie6.css
- https://kinofilms.tv/themes/tvnew/style.ie7.css
- https://kinofilms.tv/themes/tvnew/jquery.js
Questions about kinofilms.tv
- Is kinofilms.tv safe?
- No. MalwareAnalyzer scanned kinofilms.tv on 19 Aug 2026 and returned a suspicious verdict with a score of 46 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with kinofilms.tv?
- 2 analysed samples communicate with this URL.
- How was kinofilms.tv checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of kinofilms.tv
Scanned on MalwareAnalyzer by Cyble · Open interactive scan