www.eggerwirt.at - malicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.eggerwirt.at and returned a malicious verdict (score 100), categorised as credential-harvest. The page resolved to 37.186.138.155 on ZEPPELIN GROUP GMBH in IT. 27 domains and 18 IPs were contacted, over 84 HTTP requests. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 100) · Confidence 100%
- Scanned URL:
https://www.eggerwirt.at/en/spa-hotel-austria/1-0.html - Domain: www.eggerwirt.at · IP: 37.186.138.155 · AS20811 · IT
- Server: Microsoft-IIS/8.5
- Page title: Spa Hotel in Austria | Hotel Eggerwirt****s
- HTTP status: 200 · text/html; Charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Oct 26 06: · subject CN=eggerwirt.at
- HTTP requests captured: 84 · cookies set: 10 · outgoing links: 125
- Scan tier: standard · observed 2026-08-21 20:12:36 UTC
Antivirus & YARA (1 of 47 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
Categories
- credential-harvest
Why this verdict
- Runtime data beacon to api.userway.org
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Runtime data beacon to consent-api.service.consent.usercentrics.eu
- Runtime data beacon to app.manychat.com
- Credential-harvesting form
- Runtime data beacon to eggerwirt.onetoone.at
Detected technologies
- Microsoft IIS
Contacted infrastructure
- 37.186.138.155 - AS20811 ZEPPELIN GROUP GMBH (Italy)
- 142.250.183.40 - AS15169 Google LLC (US)
- 142.250.195.131 - AS15169 Google LLC (India)
- 162.159.138.60 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- www.eggerwirt.at
- fonts.gstatic.com
- www.googletagmanager.com
- shop.eggerwirt.at
- booking.eggerwirt.at
- jobs.eggerwirt.at
- my.matterport.com
- player.vimeo.com
- flow.cleverreach.com
- www.facebook.com
- www.youtube.com
- www.instagram.com
- www.zeppelinhotel.tech
- cloud.zeppelin-group.com
- fonts.googleapis.com
- widget.manychat.com
- eggerwirt.onetoone.at
- web.cmp.usercentrics.eu
- cdn.userway.org
- v1.api.service.cmp.usercentrics.eu
Questions about www.eggerwirt.at
- Is www.eggerwirt.at safe?
- No. MalwareAnalyzer scanned www.eggerwirt.at on 21 Aug 2026 and returned a malicious verdict with a score of 100 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- How was www.eggerwirt.at checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.eggerwirt.at
Scanned on MalwareAnalyzer by Cyble · Open interactive scan