www.liveinternet.ru - URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.liveinternet.ru and returned a unknown verdict (score 18), categorised as credential-harvest. The page resolved to 88.212.202.50 on EDINAYA SET LIMITED LIABILITY COMPANY in RU. 17 domains and 1 IP were contacted, over 13 HTTP requests. 28 malware samples communicate with this URL (Coinminer). The request followed 1 redirect before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 18) · Confidence 21%
- Scanned URL:
http://www.liveinternet.ru/click - Domain: www.liveinternet.ru · IP: 88.212.202.50 · AS39134 · RU
- Server: nginx/1.14.2
- Page title: LiveInternet @ Статистика и дневники, почта и поиск
- HTTP status: 200 · text/html; charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Nov 11 01: · subject CN=*.liveinternet.ru
- HTTP requests captured: 13
- Scan tier: fast · observed 2026-08-22 07:32:13 UTC
Redirect chain
http://www.liveinternet.ru/clickhttps://www.liveinternet.ru/
Malware communicating with this URL (28)
These samples were observed contacting or being served from www.liveinternet.ru. Each links to its full analysis.
- d32e399149cd5c50953a81903d9772e73ecf74c09f44926f2337bb08b79dc4fa - referenced ·
d32e399149cd5c50953a81903d9772e7· first seen 2026-08-22 - 3f7815dab64f229062df9b8db9618dd2686296fc2a4e94314adb99a44c9d6e12 - referenced ·
3f7815dab64f229062df9b8db9618dd2· first seen 2026-08-22 - 3f7496e7ad432ede46ff89ecd0af2fd8c17f92054ecf7d967dd65d46e54ffe86 - referenced ·
3f7496e7ad432ede46ff89ecd0af2fd8· first seen 2026-08-22 - 32321dbe7a75c95d82da4e38a99eba53b44e0312f4accd8a0b4b778963013c66 - referenced ·
32321dbe7a75c95d82da4e38a99eba53· first seen 2026-08-21 - df05fa75685ae17e99280fac72e2d048e9f4cecd55849cc1df27f2d65d78f90a - referenced ·
df05fa75685ae17e99280fac72e2d048· first seen 2026-08-21 - e0d99ad1ff74681cfde88b9eeb6abc04ed820167b38dae2fe238bf8484928def - referenced ·
e0d99ad1ff74681cfde88b9eeb6abc04· first seen 2026-08-21 - dcc87e5ea0588dadd78b9a2443ef3f96454cdc34406bb83bc77839b25043a3b8 - referenced ·
dcc87e5ea0588dadd78b9a2443ef3f96· first seen 2026-08-20 - bd55bb57e23e1ad7ae6648d024973b331170c8cc36a2526f780920faa37a835b - referenced ·
bd55bb57e23e1ad7ae6648d024973b33· first seen 2026-08-20 - bd5db1acfa5b74e347101f4dc6244ea77a4994b61fd892eed02da7c274a2dcf4 - referenced ·
bd5db1acfa5b74e347101f4dc6244ea7· first seen 2026-08-20 - bd543df16db7196ad97b913e8122959ee26af28c640d9610c70a5ff744926322 - referenced ·
bd543df16db7196ad97b913e8122959e· first seen 2026-08-20 - bd56c2c997dd61654f7b9979848f26b956291b435f927bba4c94cb3207605286 - referenced ·
bd56c2c997dd61654f7b9979848f26b9· first seen 2026-08-20 - 9905ac8e42c9f460b9ddb487205735e58f9ba959239c11cebbe52f75e1f26102 - referenced ·
9905ac8e42c9f460b9ddb487205735e5· first seen 2026-08-20 - Coinminer - referenced ·
257d36184d5745398fb026d060de4531· first seen 2026-08-19 - 6adfecbbfe26c19e68d5106b87acbb7e44db3132fed0956fe50f7520c8f97efa - referenced ·
6adfecbbfe26c19e68d5106b87acbb7e· first seen 2026-08-17 - 6ad8f9ffae51775c4046d5b7292619facb382c9c40e03e2e45d4ffe3f7d6f592 - referenced ·
6ad8f9ffae51775c4046d5b7292619fa· first seen 2026-08-17
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- Nginx
Contacted infrastructure
- 88.212.202.50 - AS39134 EDINAYA SET LIMITED LIABILITY COMPANY (Russian Federation)
Observed indicators
- www.liveinternet.ru
- pagead2.googlesyndication.com
- i.li.ru
- yandex.ru
- content.adriver.ru
- g.liveinternet.ru
- counter.yadro.ru
- cdn.viqeo.tv
- widget.adplay.ru
- mediametrics.ru
- smart-lab.ru
- www.03.ru
- www.3dnews.ru
- radio.mediametrics.ru
- doctor.ru
- mc.yandex.ru
- www.li.ru
- 88.212.202.50
- https://www.liveinternet.ru/
- https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js
Other scans of www.liveinternet.ru (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
https://stories-of-success.ru/ - 23 Aug 2026 - unknown ·
https://boilerservis.ru/uploads/files/timunilixive.pdf - 22 Aug 2026 - unknown ·
http://josefinacomparte.blogspot.com/search - 22 Aug 2026 - unknown ·
http://josefinacomparte.blogspot.com/ - 22 Aug 2026 - unknown ·
https://ssyssyss.narod.ru/ - 22 Aug 2026 - unknown ·
https://kinohorror.com/upload/file/tonabebeb.pdf - 22 Aug 2026 - unknown ·
https://kinohorror.com/upload/file/tonabebeb.pdf - 22 Aug 2026 - suspicious ·
https://www.semagro-msw.ru/pics/images/file/77012984907.pdf - 22 Aug 2026 - suspicious ·
https://www.semagro-msw.ru/pics/images/file/77012984907.pdf - 21 Aug 2026 - unknown ·
https://fastpic.org/view/67/2014/1114/7f7bb0e67b5597ad3637655a48fe5a80.jpg.html
Questions about www.liveinternet.ru
- Is www.liveinternet.ru safe?
- The scan of www.liveinternet.ru on 22 Aug 2026 reached no verdict either way (score 18). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.liveinternet.ru?
- 28 analysed samples communicate with this URL, including Coinminer.
- How was www.liveinternet.ru checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.liveinternet.ru
Scanned on MalwareAnalyzer by Cyble · Open interactive scan