www.holderit.com - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.holderit.com and returned a unknown verdict (score 0). The page resolved to 34.149.87.45 on Google LLC in US. The domain was registered 8121 days ago through 123-Reg Limited. 2 domains and 1 IP were contacted, over 6 HTTP requests. 14 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 0) · Confidence 0%
- Scanned URL:
http://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/16095a36e779cb---poxepewesarobisuz.pdf - Domain: www.holderit.com · IP: 34.149.87.45 · AS396982 · US
- Server: Pepyaka
- Page title: 404 Error: Page Not Found
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: 123-Reg Limited · domain age 8121 days · created 2004-05-28
- HTTP requests captured: 6
- Scan tier: fast · observed 2026-08-22 09:11:46 UTC
Redirect chain
http://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/16095a36e779cb---poxepewesarobisuz.pdfhttps://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/16095a36e779cb---poxepewesarobisuz.pdf
Malware communicating with this URL (14)
These samples were observed contacting or being served from www.holderit.com. Each links to its full analysis.
- Phishing - referenced ·
08d091f16669fe1b1ca128bd21cdd0e9· first seen 2026-08-22 - Phishing - referenced ·
71a7c6e837dc3bbcb8ba813a32da7c63· first seen 2026-08-22 - Phishing - referenced ·
d9302f50194a23cc44a6b99ba72be279· first seen 2026-08-20 - Phishing - referenced ·
5d0d4ca1c83b0d0efc48758c89e8c471· first seen 2026-08-19 - Phishing - referenced ·
984543f7f500bc88626667daf57e400e· first seen 2026-08-19 - Phishing - referenced ·
6e89b7482d53e95d66398cc7fddb0d62· first seen 2026-08-17 - Phishing - referenced ·
0127a47816f111b2b6f8ea9a0e85b1b3· first seen 2026-08-17 - Phishing - referenced ·
8c5c1d4fdd83501d4466ace0af67330a· first seen 2026-08-16 - Phishing - referenced ·
b73f300fba6b822568b0c82eb2aa4344· first seen 2026-08-16 - Phishing - referenced ·
5b2b2028cfdf478f3b117eec9eb4eca5· first seen 2026-08-16 - Phishing - referenced ·
5bb6a08db21bb20a5fb1262419200dc0· first seen 2026-08-15 - Phishing - referenced ·
d27887daa64b50d2795920383ab79533· first seen 2026-08-14 - Phishing - referenced ·
8e4843c5e421367d0331eaf17c884514· first seen 2026-08-14 - Phishing - referenced ·
feb2c1f5f81a6b707c7349bb2c392ee9· first seen 2026-08-13
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Detected technologies
- Fastly
- React
Contacted infrastructure
- 34.149.87.45 - AS396982 Google LLC (United States)
Observed indicators
- www.holderit.com
- static.parastorage.com
- 34.149.87.45
- https://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/16095a36e779cb---poxepewesarobisuz.pdf
- https://static.parastorage.com/polyfill/v2/polyfill.min.js?features=default,es6,es7,es2017&flags=gated&unknown=polyfill&rum=0
- https://static.parastorage.com/unpkg-semver/fedops-logger@5/fedops-logger.bundle.min.js
- https://static.parastorage.com/unpkg-semver/header-footer-provider/app.bundle.min.js
- https://static.parastorage.com/unpkg/react@18.2.0/umd/react.production.min.js
- https://static.parastorage.com/unpkg/react-dom@18.2.0/umd/react-dom.production.min.js
- https://static.parastorage.com/services/classic-error-pages-statics/1.98.0/app.min.css
- https://static.parastorage.com/unpkg/@wix/wix-fonts@1.14.0/media/WixMadeforTextVF_W_Wght.8022447a.woff2
- https://static.parastorage.com/unpkg/@wix/wix-fonts@1.14.0/media/WixMadeforDisplayVF_W_Wght.ab35e4df.woff2
- https://static.parastorage.com/unpkg/@wix/wix-fonts@1.14.0/madefor.min.css
- https://static.parastorage.com/unpkg/@wix/wix-fonts@1.14.0/madeforDisplay.min.css
- https://static.parastorage.com/services/classic-error-pages-statics/1.98.0/app.bundle.min.js
Other scans of www.holderit.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown ·
https://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/1609c8ca7bee0 - 16 Aug 2026 - unknown ·
https://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ab5f32d84e - 13 Aug 2026 - unknown ·
https://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/16099c89b0e80 - 13 Aug 2026 - unknown ·
https://www.holderit.com/wp-content/plugins/formcraft/file-upload/server/content/files/16099c89b0e80
Questions about www.holderit.com
- Is www.holderit.com safe?
- The scan of www.holderit.com on 22 Aug 2026 reached no verdict either way (score 0). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.holderit.com?
- 14 analysed samples communicate with this URL, including Phishing.
- How was www.holderit.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.holderit.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan