www.lerucherdesanges.fr - suspicious URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned www.lerucherdesanges.fr and returned a suspicious verdict (score 34). The page resolved to 52.59.120.70 on A100 ROW GmbH in DE. The domain was registered 5613 days ago through GANDI. 8 domains and 3 IPs were contacted, over 5 HTTP requests. The request followed 2 redirects before landing. This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 34) · Confidence 43%
- Scanned URL:
http://lerucherdesanges.fr/userfiles/file/93790432534.pdf - Domain: www.lerucherdesanges.fr · IP: 52.59.120.70 · AS16509 · DE
- Server: nginx
- HTTP status: 404 · text/html;charset=utf-8
- Registrar: GANDI · domain age 5613 days · created 2011-04-04
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Oct 29 11: · subject CN=www.lerucherdesanges.fr
- Evidenced operator: Ano Nymous
- HTTP requests captured: 5
- Scan tier: standard · observed 2026-08-17 06:03:06 UTC
Redirect chain
http://lerucherdesanges.fr/userfiles/file/93790432534.pdfhttp://www.lerucherdesanges.fr/userfiles/file/93790432534.pdfhttps://www.lerucherdesanges.fr/userfiles/file/93790432534.pdf
Antivirus & YARA (1 of 47 engines)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: JPCERT_LODEINFO
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Detected technologies
- Nginx
- jQuery
Contacted infrastructure
- 52.59.120.70 - AS16509 A100 ROW GmbH (Germany)
- 217.70.184.38 - AS29169 GANDI FRANCE L/B SERVICES (France)
- 18.197.248.23 - AS16509 A100 ROW GmbH (Germany)
Observed indicators
- www.lerucherdesanges.fr
- cdn.appconsent.io
- de.cdn-website.com
- le-de.cdn-website.com
- static.cdn-website.com
- app.multiscreenstore.com
- www.google.com
- sitessoftfactprdpublic.blob.core.windows.net
- 52.59.120.70
- 217.70.184.38
- 18.197.248.23
- https://www.lerucherdesanges.fr/userfiles/file/93790432534.pdf
- https://cdn.appconsent.io/solocal/solocal-cmp-sfbx.js
- https://www.lerucherdesanges.fr/dmPageNotFound
- https://de.cdn-website.com/33a3879aedd74388a422aa6e08ced8c2/dms3rep/multi/noun-honey-1294426.png
- https://de.cdn-website.com/33a3879aedd74388a422aa6e08ced8c2/site_favicon_16_1647518856391.ico
- https://le-de.cdn-website.com/
- https://de.cdn-website.com/
- https://static.cdn-website.com/
- https://app.multiscreenstore.com/script.js?70595507&lang=fr
Other scans of www.lerucherdesanges.fr (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://www.lerucherdesanges.fr/userfiles/file/6629834961.pdf - 17 Aug 2026 - suspicious
- 17 Aug 2026 - suspicious
Questions about www.lerucherdesanges.fr
- Is www.lerucherdesanges.fr safe?
- No. MalwareAnalyzer scanned www.lerucherdesanges.fr on 17 Aug 2026 and returned a suspicious verdict with a score of 34 out of 100. Treat it as hostile until it is re-checked.
- How was www.lerucherdesanges.fr checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.lerucherdesanges.fr
Scanned on MalwareAnalyzer by Cyble · Open interactive scan