demo3.milkmaid.it - suspicious URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned demo3.milkmaid.it and returned a suspicious verdict (score 24), categorised as credential-harvest. The page resolved to 51.89.21.114 on OVH GmbH in DE. 3 domains and 1 IP were contacted, over 8 HTTP requests. 2 malware samples communicate with this URL. The request followed 2 redirects before landing. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 24) · Confidence 30%
- Scanned URL:
https://demo3.milkmaid.it/ - Domain: demo3.milkmaid.it · IP: 51.89.21.114 · AS16276 · DE
- Server: nginx
- Page title: Login | RedOnion Social Report
- HTTP status: 200 · text/html; charset=UTF-8
- HTTP requests captured: 8
- Scan tier: fast · observed 2026-08-24 09:13:33 UTC
Redirect chain
https://demo3.milkmaid.it/http://demo3.milkmaid.it/http://demo3.milkmaid.it/login
Malware communicating with this URL (2)
These samples were observed contacting or being served from demo3.milkmaid.it. Each links to its full analysis.
- e8200b32898704891f1750672b81862bbe45394744917ba29a704178b1f23ed3 - referenced ·
e8200b32898704891f1750672b81862b· first seen 2026-08-24 - ede795ed0f1611cf450fbce6f976bf9dde848953fda1074fd712028b194bf426 - referenced ·
ede795ed0f1611cf450fbce6f976bf9d· first seen 2026-08-20
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- Nginx
- jQuery
- Bootstrap
Contacted infrastructure
- 51.89.21.114 - AS16276 OVH GmbH (Germany)
Observed indicators
- demo3.milkmaid.it
- www.google.com
- cdn.jsdelivr.net
- 51.89.21.114
- http://demo3.milkmaid.it/login
- http://demo3.milkmaid.it/templates/themes/social_report/css/bootstrap.min.css?fut=1763034465
- http://demo3.milkmaid.it/templates/themes/social_report/css/index.min.css?fut=1764343444
- http://demo3.milkmaid.it/templates/themes/social_report/css/mobile.min.css?fut=1763034528
- https://www.google.com/recaptcha/api.js?render=6LchRAssAAAAAMG7m3l0K-TjtvleFbIqnE6RhJ_R
- http://demo3.milkmaid.it/templates/themes/social_report/fontawesome-free-5.15.3-web/css/all.min.css?fut=1763031630
- https://cdn.jsdelivr.net/npm/bootstrap@5.3.8/dist/js/bootstrap.bundle.min.js
- http://demo3.milkmaid.it/templates/themes/social_report/js/jquery-3.6.0.min.js?fut=1758124595
- http://demo3.milkmaid.it/engines/framework/js/frontend-utils.min.js
- http://demo3.milkmaid.it/engines/framework/js/services.min.js
- http://demo3.milkmaid.it/templates/themes/social_report/js/index.min.js?fut=1764327255
- http://demo3.milkmaid.it/templates/themes/social_report/js/clamp.min.js?fut=1758124595
- http://demo3.milkmaid.it/applications/system/components/templates/LoginComponent.min.js?1763043710
Other scans of demo3.milkmaid.it (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - suspicious
Questions about demo3.milkmaid.it
- Is demo3.milkmaid.it safe?
- No. MalwareAnalyzer scanned demo3.milkmaid.it on 24 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with demo3.milkmaid.it?
- 2 analysed samples communicate with this URL.
- How was demo3.milkmaid.it checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of demo3.milkmaid.it
Scanned on MalwareAnalyzer by Cyble · Open interactive scan