xn--h1agcmh.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned xn--h1agcmh.com and returned a suspicious verdict (score 30), categorised as phishing. The page resolved to 176.57.66.232 on Tilda Publishing JSC in RU. The domain was registered 170 days ago through Registrar of Domain Names REG.RU LLC. 12 domains and 1 IP were contacted, over 23 HTTP requests. 2 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 30) · Confidence 33%
- Scanned URL:
http://xn--h1agcmh.com/ckfinder/userfiles/files/93746902162.pdf - Domain: xn--h1agcmh.com · IP: 176.57.66.232 · RU
- Server: ddos-guard
- Page title: 404 page
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: Registrar of Domain Names REG.RU LLC · domain age 170 days · created 2026-03-03
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Sep 13 20: · subject CN=xn--h1agcmh.com
- HTTP requests captured: 23
- Scan tier: standard · observed 2026-08-21 11:00:36 UTC
Redirect chain
http://xn--h1agcmh.com/ckfinder/userfiles/files/93746902162.pdfhttps://xn--h1agcmh.com/ckfinder/userfiles/files/93746902162.pdf
Malware communicating with this URL (2)
These samples were observed contacting or being served from xn--h1agcmh.com. Each links to its full analysis.
- Phishing - referenced ·
95413e68cf4722c75dad5c34887947b0· first seen 2026-08-15 - Phishing - referenced ·
70b7785ee1d99320ea41bddcf3b10a41· first seen 2026-08-14
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- phishing
Why this verdict
- Homograph / mixed-script domain (IDN spoofing)
Detected technologies
- jQuery
Contacted infrastructure
- 176.57.66.232 Tilda Publishing JSC (Russian Federation)
Observed indicators
- xn--h1agcmh.com
- ws.tildacdn.com
- static.tildacdn.com
- neo.tildacdn.com
- fonts.gstatic.com
- fonts.googleapis.com
- cdnjs.cloudflare.com
- t.me
- max.ru
- webdesign-an.ru
- matilda-design.ru
- mc.yandex.ru
- 176.57.66.232
- https://xn--h1agcmh.com/ckfinder/userfiles/files/93746902162.pdf
- https://xn--h1agcmh.com/page
- https://ws.tildacdn.com/
- https://static.tildacdn.com/
- https://static.tildacdn.com/tild3433-6266-4139-a135-316530663964/photo.svg
- https://static.tildacdn.com/tild3538-6364-4537-b562-346334663034/photo.svg
- https://static.tildacdn.com/tild3637-3062-4561-b166-623737383265/photo.svg
Other scans of xn--h1agcmh.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://xn--h1agcmh.com/ckfinder/userfiles/files/64611558962.pdf - 23 Aug 2026 - suspicious ·
https://xn--h1agcmh.com/ckfinder/userfiles/files/64611558962.pdf
Questions about xn--h1agcmh.com
- Is xn--h1agcmh.com safe?
- No. MalwareAnalyzer scanned xn--h1agcmh.com on 21 Aug 2026 and returned a suspicious verdict with a score of 30 out of 100, categorised as phishing. Treat it as hostile until it is re-checked.
- What malware is associated with xn--h1agcmh.com?
- 2 analysed samples communicate with this URL, including Phishing.
- How was xn--h1agcmh.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of xn--h1agcmh.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan