www.northamericatalk.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.northamericatalk.com and returned a suspicious verdict (score 54). The page resolved to 209.59.130.137 on Liquid Web, L.L.C in US. The domain was registered 5492 days ago through GoDaddy.com, LLC. 1 domain and 1 IP were contacted. 13 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 54) · Confidence 60%
- Scanned URL:
https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614137b89b340---16208121026.pdf - Domain: www.northamericatalk.com · IP: 209.59.130.137 · AS32244 · US
- Server: Apache
- HTTP status: 200 · application/pdf
- Registrar: GoDaddy.com, LLC · domain age 5492 days · created 2011-08-08
- Scan tier: fast · observed 2026-08-21 22:36:48 UTC
Malware communicating with this URL (13)
These samples were observed contacting or being served from www.northamericatalk.com. Each links to its full analysis.
- Phishing - referenced ·
66815d9431396e2e27fcfaa6ebee5e6b· first seen 2026-08-21 - Phishing - referenced ·
a9d13c03c511144b00b7e0d6a1f0e115· first seen 2026-08-20 - Phishing - referenced ·
4d9b662cb5abb3d88055a7ad94f8ac21· first seen 2026-08-19 - Phishing - referenced ·
d9a8a89893e43501b5b849db4e903bb2· first seen 2026-08-19 - Phishing - referenced ·
787604cc5680cdb439d5cb335b234a19· first seen 2026-08-18 - Phishing - referenced ·
9689681cb332c5c809501d6303b03216· first seen 2026-08-17 - Phishing - referenced ·
ab5d421bb1a69a51722ac03c94e44cf5· first seen 2026-08-17 - Phishing - referenced ·
b2b28ae7ac762628f74258ed02c3a6ec· first seen 2026-08-16 - Phishing - referenced ·
ff32a47cb6af9bba7bf0e514fad72e08· first seen 2026-08-16 - Phishing - referenced ·
cd4887f3ae58bc778dd0b2068cbcdbe3· first seen 2026-08-14 - Phishing - referenced ·
16e8e8f8e1529abe20225b55529517f2· first seen 2026-08-13 - Phishing - referenced ·
aaf8cc9dce5c4ab8d99209ee3fb671ac· first seen 2026-08-13 - Phishing - referenced ·
453a0c00629dfa6381710d47daa8464c· first seen 2026-08-12
Antivirus & YARA (1 of 48 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2528dad23a95d95-d2528dad23a95d95-10044376-0
- File download routed to the malware sandbox (1614137b89b340---16208121026.pdf)
Detected technologies
- Apache
Contacted infrastructure
- 209.59.130.137 - AS32244 Liquid Web, L.L.C (United States)
Files served by this page
- 1614137b89b340---16208121026.pdf ·
3a16bc7eddd20ab7beb0c397aae38a3f
Observed indicators
- www.northamericatalk.com
- 209.59.130.137
- https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614137b89b340---16208121026.pdf
Other scans of www.northamericatalk.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/160ac - 23 Aug 2026 - suspicious ·
https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/16146 - 19 Aug 2026 - suspicious ·
https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/1614e - 14 Aug 2026 - unknown ·
https://www.northamericatalk.com/wp-content/plugins/formcraft/file-upload/server/content/files/16089
Questions about www.northamericatalk.com
- Is www.northamericatalk.com safe?
- No. MalwareAnalyzer scanned www.northamericatalk.com on 21 Aug 2026 and returned a suspicious verdict with a score of 54 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.northamericatalk.com?
- 13 analysed samples communicate with this URL, including Phishing.
- How was www.northamericatalk.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.northamericatalk.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan