www.countrycuredhams.com - malicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned www.countrycuredhams.com and returned a malicious verdict (score 74), categorised as credential-harvest. The page resolved to 172.67.182.157 on Cloudflare, Inc. in US. The domain was registered 9639 days ago through Network Solutions, LLC. 23 domains and 3 IPs were contacted, over 21 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 2 redirects before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 74) · Confidence 86%
- Scanned URL:
http://ginzaoakland.com/uploads/files/83626256322.pdf - Domain: www.countrycuredhams.com · IP: 172.67.182.157 · AS13335 · US
- Server: cloudflare
- Page title: SLOT777: Link Slot Gacor 777 Gampang Maxwin Situs Resmi Gwp168 Terpercaya
- HTTP status: 200 · text/html
- Registrar: Network Solutions, LLC · domain age 9639 days · created 2000-03-29
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Oct 6 12: · subject CN=countrycuredhams.com
- HTTP requests captured: 21
- Scan tier: standard · observed 2026-08-19 18:40:06 UTC
Redirect chain
http://ginzaoakland.com/uploads/files/83626256322.pdfhttps://ginzaoakland.com/uploads/files/83626256322.pdfhttps://www.countrycuredhams.com/
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.countrycuredhams.com. Each links to its full analysis.
- Phishing - referenced ·
ecc4faa014bcb8a94c7dd7452b410681· first seen 2026-08-19
Antivirus & YARA (1 of 47 engines)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Antivirus/YARA detection in page content: JPCERT_LODEINFO
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Detected technologies
- Cloudflare
Contacted infrastructure
- 172.67.182.157 - AS13335 Cloudflare, Inc. (United States)
- 104.21.51.161 - AS13335 Cloudflare, Inc. (United States)
- 172.67.182.131 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- www.countrycuredhams.com
- made.countrycuredhams.com
- www.samsung.com
- images.samsung.com
- assets.adobedtm.com
- in2.ecom-qa.samsung.com
- account.samsung.com
- shop.samsung.com
- r1.community.samsung.com
- via.placeholder.com
- cerahgwp168.top
- sekolahkehidupan.com
- facebook.com
- twitter.com
- instagram.com
- youtube.com
- cdnjs.cloudflare.com
- www.google.com
- play.google.com
- apps.apple.com
Other scans of www.countrycuredhams.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - malicious
- 19 Aug 2026 - malicious
- 16 Aug 2026 - malicious
- 16 Aug 2026 - suspicious
Questions about www.countrycuredhams.com
- Is www.countrycuredhams.com safe?
- No. MalwareAnalyzer scanned www.countrycuredhams.com on 19 Aug 2026 and returned a malicious verdict with a score of 74 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with www.countrycuredhams.com?
- 1 analysed samples communicate with this URL, including Phishing.
- How was www.countrycuredhams.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.countrycuredhams.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan