xn--42cfa4ewb0a0b3fwh.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned xn--42cfa4ewb0a0b3fwh.com and returned a suspicious verdict (score 38), categorised as phishing. The page resolved to 27.254.96.235 on CSLOXINFO-IDC in TH. The domain was registered 4381 days ago through PDR Ltd. d/b/a PublicDomainRegistry.com. 3 domains and 1 IP were contacted, over 1 HTTP request. 2 malware samples communicate with this URL (Phishing). The request followed 3 redirects before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 38) · Confidence 44%
- Scanned URL:
http://xn--42cfa4ewb0a0b3fwh.com/imageupload/files/soxitixive.pdf - Domain: xn--42cfa4ewb0a0b3fwh.com · IP: 27.254.96.235 · AS9891 · TH
- Server: Apache/2
- Page title: หนึ่งมงคลศาลพระภูมิ – ศาลพระพรหม ศาลพระภูมิ ศาลเจ้าที่ คุณภาพสูง
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com · domain age 4381 days · created 2014-08-22
- TLS issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA DV R36 · valid to Feb 10 23: · subject CN=xn--42cfa4ewb0a0b3fwh.com
- HTTP requests captured: 1
- Scan tier: standard · observed 2026-08-21 02:00:28 UTC
Redirect chain
http://xn--42cfa4ewb0a0b3fwh.com/imageupload/files/soxitixive.pdfhttps://xn--42cfa4ewb0a0b3fwh.com/imageupload/files/soxitixive.pdfhttps://xn--42cfa4ewb0a0b3fwh.com/N003https://xn--42cfa4ewb0a0b3fwh.com/N003/
Malware communicating with this URL (2)
These samples were observed contacting or being served from xn--42cfa4ewb0a0b3fwh.com. Each links to its full analysis.
- Phishing - referenced ·
c6fdcfaf0d0537d0fd30e6482f9abbc6· first seen 2026-08-15 - Phishing - referenced ·
75d5a3d814e433a09da7a0d20aae2e93· first seen 2026-08-14
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Homograph / mixed-script domain (IDN spoofing)
- Untrusted certificate (UNABLE_TO_VERIFY_LEAF_SIGNATURE)
Detected technologies
- Apache
Contacted infrastructure
- 27.254.96.235 - AS9891 CSLOXINFO-IDC (Thailand)
Observed indicators
- xn--42cfa4ewb0a0b3fwh.com
- www.w3schools.com
- fonts.googleapis.com
- 27.254.96.235
- https://xn--42cfa4ewb0a0b3fwh.com/N003/
- https://www.w3schools.com/w3css/5/w3.css
- https://www.w3schools.com/lib/w3-theme-green.css
- https://fonts.googleapis.com/css2?family=Thasadith:wght@700&display=swap
- https://fonts.googleapis.com/css?family=Kanit
- https://fonts.googleapis.com/css?family=Thasadith
- https://www.w3schools.com/lib/w3.js
- https://xn--42cfa4ewb0a0b3fwh.com/images/T001-3.jpg
- https://xn--42cfa4ewb0a0b3fwh.com/N003/images/Promotion02-1.png
- https://xn--42cfa4ewb0a0b3fwh.com/N003/images/line_4423628.png
- https://xn--42cfa4ewb0a0b3fwh.com/index.php#table
- https://xn--42cfa4ewb0a0b3fwh.com/N003/?search=%E0%B8%A8%E0%B8%B2%E0%B8%A5%E0%B8%9E%E0%B8%A3%E0%B8%B0%E0%B8%9E%E0%B8%A3%E0%B8%AB%E0%B8%A1%E0%B9%82%E0%B8%A1%E0%B9%80%E0%B8%94%E0%B8%B4%E0%B8%A3%E0%B9%8C%E0%B8%99&page=1#table
- https://xn--42cfa4ewb0a0b3fwh.com/N003/?search=%E0%B8%A8%E0%B8%B2%E0%B8%A5%E0%B8%9E%E0%B8%A3%E0%B8%B0%E0%B8%A0%E0%B8%B9%E0%B8%A1%E0%B8%B4%E0%B9%82%E0%B8%A1%E0%B9%80%E0%B8%94%E0%B8%B4%E0%B8%A3%E0%B9%8C%E0%B8%99&page=1#table
- https://xn--42cfa4ewb0a0b3fwh.com/N003/?search=%E0%B8%A8%E0%B8%B2%E0%B8%A5%E0%B9%80%E0%B8%88%E0%B9%89%E0%B8%B2%E0%B8%97%E0%B8%B5%E0%B9%88%E0%B9%82%E0%B8%A1%E0%B9%80%E0%B8%94%E0%B8%B4%E0%B8%A3%E0%B9%8C%E0%B8%99&page=1#table
- https://xn--42cfa4ewb0a0b3fwh.com/N003/?search=%E0%B8%A8%E0%B8%B2%E0%B8%A5%E0%B9%82%E0%B8%94%E0%B8%A1%E0%B9%81%E0%B8%A5%E0%B8%B0%E0%B9%80%E0%B8%97%E0%B8%A7%E0%B8%B2%E0%B8%A5%E0%B8%B1%E0%B8%A2&page=1#table
- https://xn--42cfa4ewb0a0b3fwh.com/N003/?search=%E0%B8%A8%E0%B8%B2%E0%B8%A5%E0%B8%9E%E0%B8%A3%E0%B8%B0%E0%B8%9E%E0%B8%A3%E0%B8%AB%E0%B8%A1%E0%B9%84%E0%B8%97%E0%B8%A2&page=1#table
Questions about xn--42cfa4ewb0a0b3fwh.com
- Is xn--42cfa4ewb0a0b3fwh.com safe?
- No. MalwareAnalyzer scanned xn--42cfa4ewb0a0b3fwh.com on 21 Aug 2026 and returned a suspicious verdict with a score of 38 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with xn--42cfa4ewb0a0b3fwh.com?
- 2 analysed samples communicate with this URL, including Phishing.
- How was xn--42cfa4ewb0a0b3fwh.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of xn--42cfa4ewb0a0b3fwh.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan