www.aledrukujemy.pl - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned www.aledrukujemy.pl and returned a suspicious verdict (score 38), categorised as credential-harvest. The page resolved to 185.110.48.17 on IQ PL Sp. z o.o. in PL. The domain was registered 5269 days ago through OVH SAS. 3 domains and 1 IP were contacted, over 4 HTTP requests. 2 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 38) · Confidence 47%
- Scanned URL:
https://www.aledrukujemy.pl/ckfinder/userfiles/files/zoman.pdf - Domain: www.aledrukujemy.pl · IP: 185.110.48.17 · PL
- Server: LiteSpeed
- Page title: Aledrukujemy.pl - Błąd
- HTTP status: 404 · text/html
- Registrar: OVH SAS · domain age 5269 days · created 2012-03-20
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Sep 10 16: · subject CN=aledrukujemy.pl
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-23 10:57:18 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from www.aledrukujemy.pl. Each links to its full analysis.
- Phishing - referenced ·
f830e935fbaacd76573eb23ab9fb5b25· first seen 2026-08-19 - Phishing - referenced ·
93e84db180293acf822c7686d3f35199· first seen 2026-08-13
Antivirus & YARA (1 of 48 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
Detected technologies
- LiteSpeed
- Google Analytics
- Bootstrap
Contacted infrastructure
- 185.110.48.17 IQ PL Sp. z o.o. (Poland)
Observed indicators
- www.aledrukujemy.pl
- www.googletagmanager.com
- s3-eu-west-1.amazonaws.com
- 185.110.48.17
- https://www.aledrukujemy.pl/ckfinder/userfiles/files/zoman.pdf
- https://www.aledrukujemy.pl/css/bootstrap/css/bootstrap.min.css
- https://www.aledrukujemy.pl/css/style.css?_1
- https://www.aledrukujemy.pl/css/style.extra.css
- https://www.aledrukujemy.pl/assets/f9fddf41/jquery.js
- https://www.aledrukujemy.pl/css/bootstrap/js/bootstrap.min.js
- https://www.aledrukujemy.pl/css/jquery.easing.js
- https://www.aledrukujemy.pl/
- https://www.aledrukujemy.pl/favicon.ico
- https://www.googletagmanager.com/gtm.js?id=
- https://www.googletagmanager.com/ns.html?id=GTM-N33SKTMD
- https://www.aledrukujemy.pl/ckfinder/userfiles/files/koszyk
- https://www.aledrukujemy.pl/ckfinder/userfiles/files/panel
- https://www.aledrukujemy.pl/pl/s28,kontakt.html#contactform
- https://www.aledrukujemy.pl/o-nas
- https://www.aledrukujemy.pl/panel
Other scans of www.aledrukujemy.pl (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://www.aledrukujemy.pl/ckfinder/userfiles/files/94791996963.pdf - 23 Aug 2026 - suspicious ·
https://www.aledrukujemy.pl/ckfinder/userfiles/files/94791996963.pdf - 23 Aug 2026 - suspicious
Questions about www.aledrukujemy.pl
- Is www.aledrukujemy.pl safe?
- No. MalwareAnalyzer scanned www.aledrukujemy.pl on 23 Aug 2026 and returned a suspicious verdict with a score of 38 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with www.aledrukujemy.pl?
- 2 analysed samples communicate with this URL, including Phishing.
- How was www.aledrukujemy.pl checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.aledrukujemy.pl
Scanned on MalwareAnalyzer by Cyble · Open interactive scan