www.batik77.me - malicious URL scan, 16 Aug 2026
MalwareAnalyzer by Cyble scanned www.batik77.me and returned a malicious verdict (score 74), categorised as credential-harvest. The page resolved to 104.21.26.215 on Cloudflare, Inc. in US. 21 domains and 3 IPs were contacted, over 23 HTTP requests. 15 malware samples communicate with this URL (HUILoader, Genpack). The request followed 3 redirects before landing. This is a point-in-time observation from 16 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 74) · Confidence 86%
- Scanned URL:
http://fsmsh.com/2753 - Domain: www.batik77.me · IP: 104.21.26.215 · AS13335 · US
- Server: cloudflare
- Page title: BATIK77 # Sekali Jalan Banyak Hal Seru Ikut Terbuka
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 11 23: · subject CN=batik77.me
- HTTP requests captured: 23
- Scan tier: fast · observed 2026-08-16 23:15:24 UTC
Redirect chain
http://fsmsh.com/2753https://fsmsh.com/2753https://fsmsh.com/https://www.batik77.me/
Malware communicating with this URL (15)
These samples were observed contacting or being served from www.batik77.me. Each links to its full analysis.
- ee1151c0bc7e127363105145ba04e6f290a2847079dc961de6dd707f20b5abbd - referenced ·
ee1151c0bc7e127363105145ba04e6f2· first seen 2026-08-16 - HUILoader - referenced ·
23f6a14177671adb06fd770e2e5af8dd· first seen 2026-08-16 - Genpack - referenced ·
f82f22c99c20a589f871cf7f17779fe7· first seen 2026-08-15 - Genpack - referenced ·
eb6c9c99b5c76f7bbb8e2a8018196731· first seen 2026-08-15 - Genpack - referenced ·
8add281333f0daf5be6c09966c38f940· first seen 2026-08-14 - Genpack - referenced ·
9c2a7e83c343736b85c5c4187bb6ee20· first seen 2026-08-14 - Genpack - referenced ·
65ab6b1a1be9ae56d12d5e12d6e747cc· first seen 2026-08-14 - Genpack - referenced ·
dc7125474f985fa0b8d0c878a7e93274· first seen 2026-08-14 - 94d17baa8941d7d351f579daad899dbb14261f409aea4a5158163ab130025606 - referenced ·
94d17baa8941d7d351f579daad899dbb· first seen 2026-08-14 - Genpack - referenced ·
c388041a696b1cdbdb43b25061a4d087· first seen 2026-08-13 - Genpack - referenced ·
cbba704df6150e737b7c4169ac8c1f33· first seen 2026-08-13 - Genpack - referenced ·
30517b9c37d08d7de478c9c390bf42f8· first seen 2026-08-13 - HUILoader - referenced ·
ebf1d7d38bf90ac2b033257719210b34· first seen 2026-08-12 - d0bdfaa5c6ad1f960ca3a3b65237fd392223eb6468c478fa5056776f923c316e - referenced ·
d0bdfaa5c6ad1f960ca3a3b65237fd39· first seen 2026-08-12 - Genpack - referenced ·
2438779c375d622307c64d4b88ba3672· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Antivirus/YARA detection in page content: JPCERT_LODEINFO
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Detected technologies
- Cloudflare
- WordPress
Contacted infrastructure
- 104.21.26.215 - AS13335 Cloudflare, Inc. (United States)
- 104.21.24.181 - AS13335 Cloudflare, Inc. (United States)
- 172.67.219.225 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- www.batik77.me
- m.amp-strong10.lol
- meubelkayumurah.pics
- www.samsung.com
- images.samsung.com
- assets.adobedtm.com
- in2.ecom-qa.samsung.com
- account.samsung.com
- shop.samsung.com
- r1.community.samsung.com
- via.placeholder.com
- static.cloudflareinsights.com
- facebook.com
- twitter.com
- instagram.com
- youtube.com
- cdnjs.cloudflare.com
- play.google.com
- apps.apple.com
- links.s-gift.app
Other scans of www.batik77.me (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 21 Aug 2026 - unknown
- 20 Aug 2026 - unknown
- 20 Aug 2026 - unknown
- 19 Aug 2026 - unknown
- 19 Aug 2026 - unknown
- 14 Aug 2026 - malicious
- 14 Aug 2026 - malicious
Questions about www.batik77.me
- Is www.batik77.me safe?
- No. MalwareAnalyzer scanned www.batik77.me on 16 Aug 2026 and returned a malicious verdict with a score of 74 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with www.batik77.me?
- 15 analysed samples communicate with this URL, including HUILoader, Genpack.
- How was www.batik77.me checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.batik77.me
Scanned on MalwareAnalyzer by Cyble · Open interactive scan