www.itbaloch.com - URL scan, 16 Aug 2026
MalwareAnalyzer by Cyble scanned www.itbaloch.com and returned a unknown verdict (score -12). The page resolved to 2.59.170.19 on WorldStream B.V. in NL. The domain was registered 243 days ago through NameCheap, Inc.. 1 domain and 2 IPs were contacted. 13 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 16 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
http://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a4c8239841---74212458627.pdf - Domain: www.itbaloch.com · IP: 2.59.170.19 · AS49981 · NL
- Server: nginx/1.28.3 (Ubuntu)
- Page title: 404 Not Found
- HTTP status: 404 · text/html
- Registrar: NameCheap, Inc. · domain age 243 days · created 2025-12-16
- TLS issuer: C=US, O=Let's Encrypt, CN=YE2 · valid to Nov 7 22: · subject CN=www.itbaloch.com
- Scan tier: fast · observed 2026-08-16 14:52:37 UTC
Redirect chain
http://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a4c8239841---74212458627.pdfhttps://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a4c8239841---74212458627.pdf
Malware communicating with this URL (13)
These samples were observed contacting or being served from www.itbaloch.com. Each links to its full analysis.
- Phishing - referenced ·
95d084930e5861c50d469d91acefcc08· first seen 2026-08-16 - Phishing - referenced ·
29a4b16566abad1515da1167ba45dc36· first seen 2026-08-16 - Phishing - referenced ·
abfac46a2e546301491bff0c3979589c· first seen 2026-08-16 - Phishing - referenced ·
61f47cab4910816bbf0405fd542b4d06· first seen 2026-08-15 - Phishing - referenced ·
c927369342973435b7ef4090c22b8786· first seen 2026-08-15 - Phishing - referenced ·
42a221014e0caed78f86ecce580b0ae9· first seen 2026-08-15 - Phishing - referenced ·
5508ada9d937ba1368a294562b015726· first seen 2026-08-14 - Phishing - referenced ·
b32cae7217da43ac3bf0429106816301· first seen 2026-08-14 - Phishing - referenced ·
13a6cdd097684605dcd259ad9d7fd045· first seen 2026-08-13 - Phishing - referenced ·
dcb8a88644cc5da560343ef9233c4d9d· first seen 2026-08-13 - Phishing - referenced ·
8d6c25150474bd9085974bdad243e193· first seen 2026-08-13 - Phishing - referenced ·
e3f6fc9c389612f0d16ff4ad03dfe753· first seen 2026-08-12 - Phishing - referenced ·
3293c17073de9272df363cc9f68414a1· first seen 2026-08-11
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
Contacted infrastructure
- 2.59.170.19 - AS49981 WorldStream B.V. (Netherlands)
- 104.219.250.36 - AS22612 Namecheap, Inc. (US)
Observed indicators
- www.itbaloch.com
- 2.59.170.19
- 104.219.250.36
- https://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/1607a4c8239841---74212458627.pdf
Other scans of www.itbaloch.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - unknown ·
https://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/160b829cdaca4 - 16 Aug 2026 - unknown ·
https://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/160960b5e6982 - 13 Aug 2026 - unknown ·
https://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/1612f0f98af62 - 13 Aug 2026 - unknown ·
https://www.itbaloch.com/wp-content/plugins/formcraft/file-upload/server/content/files/16072ce9b5973
Questions about www.itbaloch.com
- Is www.itbaloch.com safe?
- The scan of www.itbaloch.com on 16 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.itbaloch.com?
- 13 analysed samples communicate with this URL, including Phishing.
- How was www.itbaloch.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.itbaloch.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan