www.vrtaspol.cz - suspicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned www.vrtaspol.cz and returned a suspicious verdict (score 28). The page resolved to 62.109.154.76 on IGNUM-AS - Webglobe, s.r.o., CZ in CZ. 7 domains and 1 IP were contacted, over 5 HTTP requests. The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
http://vrtaspol.cz/klienti/devel/sneznerolby.cz/ckfinder/userfiles/files/19496984430.pdf - Domain: www.vrtaspol.cz · IP: 62.109.154.76 · AS29134 · CZ
- Server: nginx
- Page title: Takovou stránku tady nemáme :( - Vrtaspol s.r.o.
- HTTP status: 404 · text/html
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Sep 16 09: · subject CN=www.vrtaspol.cz
- HTTP requests captured: 5
- Scan tier: standard · observed 2026-08-19 18:06:21 UTC
Redirect chain
http://vrtaspol.cz/klienti/devel/sneznerolby.cz/ckfinder/userfiles/files/19496984430.pdfhttps://www.vrtaspol.cz/klienti/devel/sneznerolby.cz/ckfinder/userfiles/files/19496984430.pdf
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- Google Analytics
- jQuery
Contacted infrastructure
- 62.109.154.76 - AS29134 IGNUM-AS - Webglobe, s.r.o., CZ (CZ)
Observed indicators
- www.vrtaspol.cz
- ajax.googleapis.com
- www.freeprivacypolicy.com
- www.googletagmanager.com
- www.google.com
- tvorbawebstranek.cz
- www.webseo-optimalizace.cz
- 62.109.154.76
- https://www.vrtaspol.cz/klienti/devel/sneznerolby.cz/ckfinder/userfiles/files/19496984430.pdf
- https://www.vrtaspol.cz/files/images/favicon/apple-touch-icon.png
- https://www.vrtaspol.cz/files/images/favicon/favicon-32x32.png
- https://www.vrtaspol.cz/files/images/favicon/favicon-16x16.png
- https://www.vrtaspol.cz/files/images/favicon/site.webmanifest
- https://www.vrtaspol.cz/files/css/styles.css?t=1787162784
- https://www.vrtaspol.cz/files/js/functions.js?v=1
- https://ajax.googleapis.com/ajax/libs/jquery/2.2.0/jquery.min.js
- https://www.freeprivacypolicy.com/public/cookie-consent/4.1.0/cookie-consent.js
- https://www.googletagmanager.com/gtag/js?id=G-C5S2JTPG3J
- https://www.vrtaspol.cz/files/simplelightbox/simplelightbox.min.css
- https://www.vrtaspol.cz/files/simplelightbox/simple-lightbox.js
Other scans of www.vrtaspol.cz (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - suspicious
Questions about www.vrtaspol.cz
- Is www.vrtaspol.cz safe?
- No. MalwareAnalyzer scanned www.vrtaspol.cz on 19 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- How was www.vrtaspol.cz checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.vrtaspol.cz
Scanned on MalwareAnalyzer by Cyble · Open interactive scan