deshdunya.com - URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned deshdunya.com and returned a unknown verdict (score -2), categorised as credential-harvest. The page resolved to 37.98.151.184 on GCI Network Solutions Limited in AU. 14 domains and 2 IPs were contacted, over 17 HTTP requests. 3 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -2) · Confidence 8%
- Scanned URL:
http://deshdunya.com/blogimage/file/96657463789.pdf - Domain: deshdunya.com · IP: 37.98.151.184 · AS47583 · AU
- Server: hcdn
- Page title: Page not found - Deshdunya
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Oct 10 02: · subject CN=deshdunya.com
- HTTP requests captured: 17
- Scan tier: standard · observed 2026-08-24 01:57:01 UTC
Redirect chain
http://deshdunya.com/blogimage/file/96657463789.pdfhttps://deshdunya.com/blogimage/file/96657463789.pdf
Malware communicating with this URL (3)
These samples were observed contacting or being served from deshdunya.com. Each links to its full analysis.
- Phishing - referenced ·
145b006ad3960d7b85f6fc8b550994a3· first seen 2026-08-22 - Phishing - referenced ·
6f5466d8aa0856e09066a7feeb56b1f0· first seen 2026-08-21 - Phishing - referenced ·
1958fdc0f23263df9f8568de9db485a9· first seen 2026-08-13
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- Credential-harvesting form
Detected technologies
- PHP
- WordPress
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 37.98.151.184 - AS47583 GCI Network Solutions Limited (Australia)
- 91.108.99.174 - AS47583 IPFFM Internet Provider Frankfurt GmbH (Australia)
Observed indicators
- deshdunya.com
- cdn.jsdelivr.net
- fonts.googleapis.com
- kit.fontawesome.com
- www.googletagmanager.com
- www.facebook.com
- twitter.com
- www.youtube.com
- www.pinterest.com
- web.whatsapp.com
- maps.app.goo.gl
- www.netqueuetech.com
- www.google.com
- ajax.googleapis.com
- 37.98.151.184
- 91.108.99.174
- https://deshdunya.com/blogimage/file/96657463789.pdf
- https://deshdunya.com/feed/
- https://deshdunya.com/comments/feed/
- https://deshdunya.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.7.6
Other scans of deshdunya.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown ·
https://deshdunya.com/blogimage/file/87636414119.pdf
Questions about deshdunya.com
- Is deshdunya.com safe?
- The scan of deshdunya.com on 24 Aug 2026 reached no verdict either way (score -2). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with deshdunya.com?
- 3 analysed samples communicate with this URL, including Phishing.
- How was deshdunya.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of deshdunya.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan