www.gunyagder.org.tr - URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned www.gunyagder.org.tr and returned a unknown verdict (score -12). The page resolved to 141.98.204.235 on AEROTEK-AS - CIZGI TELEKOMUNIKASYON ANONIM SIRKETI, TR in TR. 6 domains and 1 IP were contacted, over 4 HTTP requests. 5 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
http://www.gunyagder.org.tr/wp-content/plugins/super-forms/uploads/php/files/p3j3vcpj0t55fuikmnf255c694/fekavile.pdf - Domain: www.gunyagder.org.tr · IP: 141.98.204.235 · AS42807 · TR
- Page title: Sayfa bulunamadı – GÜNYAĞDER
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR2 · valid to Nov 13 05: · subject CN=gunyagder.sunargrup.com.tr
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-19 19:37:53 UTC
Redirect chain
http://www.gunyagder.org.tr/wp-content/plugins/super-forms/uploads/php/files/p3j3vcpj0t55fuikmnf255c694/fekavile.pdfhttps://www.gunyagder.org.tr/wp-content/plugins/super-forms/uploads/php/files/p3j3vcpj0t55fuikmnf255c694/fekavile.pdf
Malware communicating with this URL (5)
These samples were observed contacting or being served from www.gunyagder.org.tr. Each links to its full analysis.
- Phishing - referenced ·
25725e39457b684740138df15194d554· first seen 2026-08-19 - Phishing - referenced ·
1ab2cae428ab09443caa0532671a3680· first seen 2026-08-19 - Phishing - referenced ·
572cd3d6f120b038598a9a81d33665be· first seen 2026-08-15 - Phishing - referenced ·
00f375d88381d0e8e73e91d2c0b0d445· first seen 2026-08-14 - Phishing - referenced ·
72d4efe50ff23fb44e33aab68fa9f426· first seen 2026-08-12
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- PHP
- WordPress
Contacted infrastructure
- 141.98.204.235 - AS42807 AEROTEK-AS - CIZGI TELEKOMUNIKASYON ANONIM SIRKETI, TR (TR)
Observed indicators
- www.gunyagder.org.tr
- gmpg.org
- fonts.googleapis.com
- cdnjs.cloudflare.com
- www.tarimorman.gov.tr
- www.bysd.org.tr
- 141.98.204.235
- https://www.gunyagder.org.tr/wp-content/plugins/super-forms/uploads/php/files/p3j3vcpj0t55fuikmnf255c694/fekavile.pdf
- http://gmpg.org/xfn/11
- https://fonts.googleapis.com/
- https://www.gunyagder.org.tr/feed/
- https://www.gunyagder.org.tr/comments/feed/
- https://fonts.googleapis.com/css?family=Georgia,Times,"Times+New+Roman",serif:regular,700,regular|Lato:regular,700|Dancing+Script:regular,400&display=swap&ver=3.9
- https://www.gunyagder.org.tr/wp-content/cache/wpo-minify/1786733555/assets/wpo-minify-header-b34a311e.min.css
- https://www.gunyagder.org.tr/wp-content/cache/wpo-minify/1786733555/assets/wpo-minify-header-7c160e4d.min.js
- https://www.gunyagder.org.tr/xmlrpc.php?rsd
- https://www.gunyagder.org.tr/wp-content/themes/flatsome/assets/css/ie-fallback.css
- https://cdnjs.cloudflare.com/ajax/libs/html5shiv/3.6.1/html5shiv.js
- https://www.gunyagder.org.tr/wp-content/themes/flatsome/assets/libs/ie-flexibility.js
- https://www.gunyagder.org.tr/wp-content/uploads/2019/11/cropped-logo-32x32.gif
Other scans of www.gunyagder.org.tr (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://www.gunyagder.org.tr/wp-content/plugins/super-forms/uploads/php/files/n8j1lgk3aced3ajkfgrqjl
Questions about www.gunyagder.org.tr
- Is www.gunyagder.org.tr safe?
- The scan of www.gunyagder.org.tr on 19 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.gunyagder.org.tr?
- 5 analysed samples communicate with this URL, including Phishing.
- How was www.gunyagder.org.tr checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.gunyagder.org.tr
Scanned on MalwareAnalyzer by Cyble · Open interactive scan