www.stefani.cz - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned www.stefani.cz and returned a suspicious verdict (score 20), categorised as credential-harvest, impersonating binance. The page resolved to 185.184.254.10 on Shoptet a.s. in CZ. 8 domains and 2 IPs were contacted, over 29 HTTP requests. The request followed 2 redirects before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 20) · Confidence 32%
- Scanned URL:
http://stefani.cz/fck/file/sifozopezetumojupaj.pdf - Domain: www.stefani.cz · IP: 185.184.254.10 · AS198627 · CZ
- Server: openresty
- Page title: Stránka neexistuje - Stefani
- HTTP status: 404 · text/html; charset=utf-8
- TLS issuer: C=AT, O=ZeroSSL GmbH, CN=ZeroSSL ECC DV SSL CA 2 · valid to Sep 29 23: · subject CN=www.stefani.cz
- HTTP requests captured: 29
- Scan tier: standard · observed 2026-08-23 14:30:13 UTC
Redirect chain
http://stefani.cz/fck/file/sifozopezetumojupaj.pdfhttp://www.stefani.cz/fck/file/sifozopezetumojupaj.pdfhttps://www.stefani.cz/fck/file/sifozopezetumojupaj.pdf
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Matches phishing-kit family "Binance / Crypto Exchange Kit"
- Cross-host redirect chain
Detected technologies
- Google Analytics
- jQuery
Contacted infrastructure
- 185.184.254.10 - AS198627 Shoptet a.s. (Czechia)
- 185.184.254.11 - AS198627 Shoptet a.s. (Czechia)
Observed indicators
- www.stefani.cz
- cdn.myshoptet.com
- use.typekit.net
- www.googletagmanager.com
- www.facebook.com
- connect.facebook.net
- www.elektrojanata.cz
- www.shoptet.cz
- 185.184.254.10
- 185.184.254.11
- https://www.stefani.cz/fck/file/sifozopezetumojupaj.pdf
- https://cdn.myshoptet.com/
- https://cdn.myshoptet.com/prj/dist/master/cms/libs/jquery/jquery-1.11.3-sec1.min.js
- https://cdn.myshoptet.com/prj/dist/master/cms/templates/frontend_templates/shared/css/font-face/open-sans.css
- https://cdn.myshoptet.com/prj/dist/master/cms/templates/frontend_templates/shared/css/font-face/noto-sans.css
- https://cdn.myshoptet.com/prj/dist/master/shop/dist/main-3g-header.js.27c4444ba5dd6be3416d.js
- https://use.typekit.net/nxv2roq.css
- https://cdn.myshoptet.com/prj/dist/master/shop/dist/font-shoptet-11.css.62c94c7785ff2cea73b2.css
- https://cdn.myshoptet.com/usr/paxio.myshoptet.com/user/documents/Venus/style.css?v771164
- https://cdn.myshoptet.com/usr/paxio.myshoptet.com/user/documents/blank/ikony.css?v23
Other scans of www.stefani.cz (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown
- 13 Aug 2026 - suspicious ·
https://www.stefani.cz/fck/file/97257939828.pdf
Questions about www.stefani.cz
- Is www.stefani.cz safe?
- No. MalwareAnalyzer scanned www.stefani.cz on 23 Aug 2026 and returned a suspicious verdict with a score of 20 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- Does www.stefani.cz belong to binance?
- No. This page claims the identity of binance but nothing establishes that binance operates it, which is what impersonation means here. Compare the certificate organisation and the registrant against the brand's real properties.
- How was www.stefani.cz checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.stefani.cz · Other binance phishing domains
Scanned on MalwareAnalyzer by Cyble · Open interactive scan