www.getfitcrew.com - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned www.getfitcrew.com and returned a suspicious verdict (score 42). The page resolved to 66.198.240.48 on A2 Hosting, Inc. in US. The domain was registered 6384 days ago through NameSilo, LLC. 1 domain and 1 IP were contacted. 13 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 42) · Confidence 51%
- Scanned URL:
https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/161368f76481e6---momugufajulet.pdf - Domain: www.getfitcrew.com · IP: 66.198.240.48 · AS55293 · US
- Server: LiteSpeed
- HTTP status: 200 · application/pdf
- Registrar: NameSilo, LLC · domain age 6384 days · created 2009-02-28
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Nov 9 12: · subject CN=www.getfitcrew.dyfme.com
- Scan tier: fast · observed 2026-08-23 16:06:47 UTC
Malware communicating with this URL (13)
These samples were observed contacting or being served from www.getfitcrew.com. Each links to its full analysis.
- Phishing - referenced ·
7fac477bf15fbba59637818c08579d7b· first seen 2026-08-23 - Phishing - referenced ·
86db2c3128255762ddd7aabc0dd89168· first seen 2026-08-21 - Phishing - referenced ·
f2fd678112bbbd671d1cd03539e5d7f6· first seen 2026-08-20 - Phishing - referenced ·
3bd286cac9df1abb368ce56d6d28a47d· first seen 2026-08-19 - Phishing - referenced ·
56d0629e9fbd0730001b7850ec8ea686· first seen 2026-08-16 - Phishing - referenced ·
190c72ff22af003de6391ccf28192e57· first seen 2026-08-15 - Phishing - referenced ·
95413e68cf4722c75dad5c34887947b0· first seen 2026-08-15 - Phishing - referenced ·
d449af0c0a5de6078cf8bc48b742d3e3· first seen 2026-08-14 - Phishing - referenced ·
0c1985e0a9415be0db6e21701f2a03a0· first seen 2026-08-14 - Phishing - referenced ·
21162e28d09d36ee5ab43cdec2596804· first seen 2026-08-14 - Phishing - referenced ·
b5ceb6c0a3e825d18cf450f54689de6a· first seen 2026-08-13 - Phishing - referenced ·
882496a53024a9b8b638b731c761dc51· first seen 2026-08-13 - Phishing - referenced ·
e767dead45eca7d789e429835f57b859· first seen 2026-08-13
Antivirus & YARA (1 of 48 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- File download routed to the malware sandbox (161368f76481e6---momugufajulet.pdf)
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- LiteSpeed
Contacted infrastructure
- 66.198.240.48 - AS55293 A2 Hosting, Inc. (United States)
Files served by this page
- 161368f76481e6---momugufajulet.pdf ·
bee97d8de795cb72113dc438d2c54f3c
Observed indicators
- www.getfitcrew.com
- 66.198.240.48
- https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/161368f76481e6---momugufajulet.pdf
Other scans of www.getfitcrew.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - suspicious ·
https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607afedc23 - 13 Aug 2026 - suspicious ·
https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070b51632 - 13 Aug 2026 - suspicious ·
https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/16070b51632 - 13 Aug 2026 - suspicious ·
https://www.getfitcrew.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ca3864a7
Questions about www.getfitcrew.com
- Is www.getfitcrew.com safe?
- No. MalwareAnalyzer scanned www.getfitcrew.com on 23 Aug 2026 and returned a suspicious verdict with a score of 42 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.getfitcrew.com?
- 13 analysed samples communicate with this URL, including Phishing.
- How was www.getfitcrew.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.getfitcrew.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan