www.grupoapex.es - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned www.grupoapex.es and returned a unknown verdict (score 6). The page resolved to 5.35.200.156 on AIRE NETWORKS DEL MEDITERRANEO SL UNIPERSONAL in ES. 5 domains and 1 IP were contacted, over 3 HTTP requests. 1 malware sample communicates with this URL (Docusign112101). The request followed 2 redirects before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 15%
- Scanned URL:
https://santoreino.es/ - Domain: www.grupoapex.es · IP: 5.35.200.156 · AS31577 · ES
- Server: Apache
- Page title: Grupo Apex - Patatas Fritas, Aperitivos y Frutos Secos
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 11 17: · subject CN=santoreino.es
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-19 15:02:34 UTC
Redirect chain
https://santoreino.es/https://grupoapex.es/https://www.grupoapex.es/
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.grupoapex.es. Each links to its full analysis.
- Docusign112101 - referenced ·
9ff816f6eaf14f22b2d3663957de22bf· first seen 2026-08-19
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
- A signature matched text in the page (DLV_HTML_Smuggling) — pages that discuss malware can match, so this alone is not a malicious verdict
- Cross-host redirect chain
Detected technologies
- Apache
- WordPress
- jQuery
Contacted infrastructure
- 5.35.200.156 - AS31577 AIRE NETWORKS DEL MEDITERRANEO SL UNIPERSONAL (Spain)
Observed indicators
- www.grupoapex.es
- fonts.gstatic.com
- centinela.lefebvre.es
- cookiedatabase.org
- www.google.com
- 5.35.200.156
- https://www.grupoapex.es/
- https://www.grupoapex.es/xmlrpc.php
- https://fonts.gstatic.com/
- https://www.grupoapex.es/feed/
- https://www.grupoapex.es/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fwww.grupoapex.es%2F
- https://www.grupoapex.es/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fwww.grupoapex.es%2F&format=xml
- https://www.grupoapex.es/wp-content/litespeed/css/78d8a5e3e662ddd01160af7e68781f09.css?ver=59c77
- https://www.grupoapex.es/wp-content/et-cache/101/et-divi-dynamic-tb-178-tb-188-101-late.css
- https://www.grupoapex.es/wp-content/et-cache/101/et-divi-dynamic-tb-178-tb-188-101.css
- https://www.grupoapex.es/wp-includes/js/jquery/jquery.min.js
- https://www.grupoapex.es/wp-json/
- https://www.grupoapex.es/wp-json/wp/v2/pages/101
- https://www.grupoapex.es/xmlrpc.php?rsd
- https://www.grupoapex.es/wp-content/uploads/2020/11/cropped-favicon-GrupoApex-32x32.png
Questions about www.grupoapex.es
- Is www.grupoapex.es safe?
- The scan of www.grupoapex.es on 19 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.grupoapex.es?
- 1 analysed samples communicate with this URL, including Docusign112101.
- How was www.grupoapex.es checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.grupoapex.es
Scanned on MalwareAnalyzer by Cyble · Open interactive scan