www.marthatrotts.ca - URL scan, 15 Aug 2026
MalwareAnalyzer by Cyble scanned www.marthatrotts.ca and returned a unknown verdict (score 18), categorised as credential-harvest. The page resolved to 15.204.65.40 on OVH US LLC in US. The domain was registered 6273 days ago through eNom Canada Corp.. 13 domains and 1 IP were contacted, over 30 HTTP requests. 5 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 15 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 18) · Confidence 21%
- Scanned URL:
https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16071c81ab7629---57989920727.pdf - Domain: www.marthatrotts.ca · IP: 15.204.65.40 · AS16276 · US
- Server: Apache
- Page title: Page Not Found - Martha Trotts
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: eNom Canada Corp. · domain age 6273 days · created 2009-06-11
- Registrant country: CA
- Evidenced operator: Martha Trotts Company
- HTTP requests captured: 30
- Scan tier: fast · observed 2026-08-15 12:58:16 UTC
Malware communicating with this URL (5)
These samples were observed contacting or being served from www.marthatrotts.ca. Each links to its full analysis.
- Phishing - referenced ·
0fdd5eb6e9cb1cbb33b28d7e7f0635c6· first seen 2026-08-15 - Phishing - referenced ·
c0b0208f30ee8a2d628b439583a7a066· first seen 2026-08-15 - Phishing - referenced ·
67341d668e2876cba9bd9189041a3642· first seen 2026-08-14 - Phishing - referenced ·
4b495e52588161a890ba7b4de615b681· first seen 2026-08-14 - Phishing - referenced ·
045452de53cca3666d28190eb93a5452· first seen 2026-08-14
Antivirus & YARA (0 of 44 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
Detected technologies
- Apache
- PHP
- WordPress
- Google Analytics
- jQuery
Contacted infrastructure
- 15.204.65.40 - AS16276 OVH US LLC (United States)
Observed indicators
- www.marthatrotts.ca
- html5shiv.googlecode.com
- css3-mediaqueries-js.googlecode.com
- marthatrotts.ca
- themeforest.unitedthemes.com
- s7.addthis.com
- fonts.googleapis.com
- s.w.org
- www.facebook.com
- www.linkedin.com
- secure.gravatar.com
- www.muskokagraphics.com
- www.unitedthemes.com
- 15.204.65.40
- https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16071c81ab7629---57989920727.pdf
- https://www.marthatrotts.ca/wp-content/themes/nevada/css/ie8.css
- http://html5shiv.googlecode.com/svn/trunk/html5.js
- http://css3-mediaqueries-js.googlecode.com/svn/trunk/css3-mediaqueries.js
- http://marthatrotts.ca/wp-content/uploads/2013/09/favicon.ico
- http://themeforest.unitedthemes.com/wpversions/nevada/xml/wp-content/uploads/2012/09/apple-57.png
Other scans of www.marthatrotts.ca (6)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - unknown ·
https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1614d2616e - 19 Aug 2026 - unknown ·
https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16081c4693 - 16 Aug 2026 - unknown ·
https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160fefdc82 - 16 Aug 2026 - unknown ·
https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/160d85aa5c - 15 Aug 2026 - unknown ·
https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/16130ec861 - 14 Aug 2026 - unknown ·
https://www.marthatrotts.ca/wp-content/plugins/formcraft/file-upload/server/content/files/1609ec38e9
Questions about www.marthatrotts.ca
- Is www.marthatrotts.ca safe?
- The scan of www.marthatrotts.ca on 15 Aug 2026 reached no verdict either way (score 18). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.marthatrotts.ca?
- 5 analysed samples communicate with this URL, including Phishing.
- How was www.marthatrotts.ca checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.marthatrotts.ca
Scanned on MalwareAnalyzer by Cyble · Open interactive scan