bandarabbasi.rozfa.ir - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned bandarabbasi.rozfa.ir and returned a suspicious verdict (score 24), categorised as credential-harvest. The page resolved to 79.127.127.68 on Asiatech Data Transmission company in IR. 4 domains and 1 IP were contacted, over 4 HTTP requests. 1 malware sample communicates with this URL. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 24) · Confidence 30%
- Scanned URL:
http://bandarabbasi.rozfa.ir/tag/%D8%AF%D8%A7%D9%86%D9%84%D9%88%D8%AF+%D8%A2%D9%87%D9%86%DA%AF%D9%87%D8%A7%DB%8C+%D9%82%D8%AF%DB%8C%D9%85%DB%8C+%D8%A7%D8%B2+%DA%A9%D8%A7%D9%85%D8%B1%D8%A7%D9%86+%D9%88+%D9%87%D9%88%D9%85%D9%86 - Domain: bandarabbasi.rozfa.ir · IP: 79.127.127.68 · AS43754 · IR
- Server: LiteSpeed
- Page title: دانلود آهنگهای قدیمی از کامران و هومن
- HTTP status: 200 · text/html; charset=utf-8
- HTTP requests captured: 4
- Scan tier: fast · observed 2026-08-21 18:52:25 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from bandarabbasi.rozfa.ir. Each links to its full analysis.
- 3f7207c0fa5781776880058c9f0182c26bbbfc2d7a7d255f4b8c8b0b36d4bea0 - referenced ·
3f7207c0fa5781776880058c9f0182c2· first seen 2026-08-21
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Served over plaintext HTTP
Detected technologies
- LiteSpeed
Contacted infrastructure
- 79.127.127.68 - AS43754 Asiatech Data Transmission company (Iran, Islamic Republic of)
Observed indicators
- bandarabbasi.rozfa.ir
- rozblog.com
- www.tak3da-download.tk
- www.rozblog.com
- 79.127.127.68
- http://bandarabbasi.rozfa.ir/tag/%D8%AF%D8%A7%D9%86%D9%84%D9%88%D8%AF+%D8%A2%D9%87%D9%86%DA%AF%D9%87%D8%A7%DB%8C+%D9%82%D8%AF%DB%8C%D9%85%DB%8C+%D8%A7%D8%B2+%DA%A9%D8%A7%D9%85%D8%B1%D8%A7%D9%86+%D9%88+%D9%87%D9%88%D9%85%D9%86
- https://rozblog.com/include/rozblog_ads_js.php?6
- https://rozblog.com/temp/site.css?38.8
- https://bandarabbasi.rozfa.ir/
- https://bandarabbasi.rozfa.ir/tag/%D8%AF%D8%A7%D9%86%D9%84%D9%88%D8%AF+%D8%A2%D9%87%D9%86%DA%AF%D9%87%D8%A7%DB%8C+%D9%82%D8%AF%DB%8C%D9%85%DB%8C+%D8%A7%D8%B2+%DA%A9%D8%A7%D9%85%D8%B1%D8%A7%D9%86+%D9%88+%D9%87%D9%88%D9%85%D9%86
- http://bandarabbasi.rozfa.ir/theme/rozblog_v4/favi1.ico
- http://bandarabbasi.rozfa.ir/temp/tarahi/styles.css
- http://bandarabbasi.rozfa.ir/temp/default/script.js
- https://bandarabbasi.rozfa.ir/code/popup
- http://bandarabbasi.rozfa.ir/weblog/file/loading/88.gif
- http://bandarabbasi.rozfa.ir/
- http://bandarabbasi.rozfa.ir/forum
- http://bandarabbasi.rozfa.ir/register
- http://bandarabbasi.rozfa.ir/login
- http://bandarabbasi.rozfa.ir/archive
Questions about bandarabbasi.rozfa.ir
- Is bandarabbasi.rozfa.ir safe?
- No. MalwareAnalyzer scanned bandarabbasi.rozfa.ir on 21 Aug 2026 and returned a suspicious verdict with a score of 24 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with bandarabbasi.rozfa.ir?
- 1 analysed samples communicate with this URL.
- How was bandarabbasi.rozfa.ir checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of bandarabbasi.rozfa.ir
Scanned on MalwareAnalyzer by Cyble · Open interactive scan