www.pcmreps.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.pcmreps.com and returned a suspicious verdict (score 28), categorised as suspicious-infrastructure, credential-harvest. The page resolved to 104.21.66.149 on Cloudflare, Inc. in US. The domain was registered 6039 days ago through GoDaddy.com, LLC. 8 domains and 2 IPs were contacted, over 20 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://toscanafantastica.com/userfiles/file/vujozejodakagekipax.pdf - Domain: www.pcmreps.com · IP: 104.21.66.149 · AS13335 · US
- Server: cloudflare
- Page title: Italia Plus 1: “Venecia, Florencia, Roma” :: PCM REPS Agencia mayorista de viajes
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: GoDaddy.com, LLC · domain age 6039 days · created 2010-02-05
- HTTP requests captured: 20
- Scan tier: fast · observed 2026-08-20 13:26:09 UTC
Redirect chain
https://toscanafantastica.com/userfiles/file/vujozejodakagekipax.pdfhttps://www.pcmreps.com/travel/tour/237/italia-plus-1-venecia-florencia-roma
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.pcmreps.com. Each links to its full analysis.
- Phishing - referenced ·
18b6e89af980cc211b5bf4ae550241ab· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- suspicious-infrastructure
- credential-harvest
Why this verdict
- Algorithmically-generated (DGA-like) hostname
- Credential-harvesting form
Detected technologies
- Cloudflare
- Google Analytics
- jQuery
- Bootstrap
- Cloudflare Insights
Contacted infrastructure
- 104.21.66.149 - AS13335 Cloudflare, Inc. (United States)
- 104.21.83.212 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- www.pcmreps.com
- fonts.googleapis.com
- cdnjs.cloudflare.com
- cdn.jsdelivr.net
- www.facebook.com
- dash.callbell.eu
- www.googleadservices.com
- static.cloudflareinsights.com
- 104.21.66.149
- 104.21.83.212
- https://www.pcmreps.com/travel/tour/237/italia-plus-1-venecia-florencia-roma
- https://www.pcmreps.com/assets/css/spinners/air.svg
- https://www.pcmreps.com/apple-icon-57x57.png
- https://www.pcmreps.com/apple-icon-60x60.png
- https://www.pcmreps.com/apple-icon-72x72.png
- https://www.pcmreps.com/apple-icon-76x76.png
- https://www.pcmreps.com/apple-icon-114x114.png
- https://www.pcmreps.com/apple-icon-120x120.png
- https://www.pcmreps.com/apple-icon-144x144.png
- https://www.pcmreps.com/apple-icon-152x152.png
Questions about www.pcmreps.com
- Is www.pcmreps.com safe?
- No. MalwareAnalyzer scanned www.pcmreps.com on 20 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100, categorised as suspicious-infrastructure and credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with www.pcmreps.com?
- 1 analysed samples communicate with this URL, including Phishing.
- How was www.pcmreps.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.pcmreps.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan