xoxoceylon.com - malicious URL scan, 19 Aug 2026
MalwareAnalyzer by Cyble scanned xoxoceylon.com and returned a malicious verdict (score 68), categorised as credential-harvest. The page resolved to 104.21.71.55 on Cloudflare, Inc. in US. The domain was registered 2 days ago through NameCheap, Inc.. 18 domains and 2 IPs were contacted, over 25 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 19 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 68) · Confidence 80%
- Scanned URL:
http://bulongvungtau.com/media/ftp/file/99419842994.pdf - Domain: xoxoceylon.com · IP: 104.21.71.55 · AS13335 · US
- Server: cloudflare
- Page title: ELLOSLOT || Daftar Akun Slot Gratis Pragmatic Play Demo No 1 Di Indonesia Paling Gacor
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: NameCheap, Inc. · domain age 2 days · created 2026-08-17
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 15 06: · subject CN=xoxoceylon.com
- HTTP requests captured: 25
- Scan tier: standard · observed 2026-08-19 15:02:52 UTC
Redirect chain
http://bulongvungtau.com/media/ftp/file/99419842994.pdfhttps://xoxoceylon.com/product-category/maxi/
Malware communicating with this URL (1)
These samples were observed contacting or being served from xoxoceylon.com. Each links to its full analysis.
- Phishing - referenced ·
d9a8a89893e43501b5b849db4e903bb2· first seen 2026-08-19
Antivirus & YARA (1 of 47 engines)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Antivirus/YARA detection in page content: JPCERT_LODEINFO
- Domain registered 2 day(s) ago
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
Contacted infrastructure
- 104.21.71.55 - AS13335 Cloudflare, Inc. (United States)
- 104.21.57.70 - AS13335 Cloudflare, Inc. (United States)
Observed indicators
- xoxoceylon.com
- elloslot.xoxoceylon.com
- ik.imagekit.io
- www.samsung.com
- assets.adobedtm.com
- in2.ecom-qa.samsung.com
- account.samsung.com
- shop.samsung.com
- images.samsung.com
- r1.community.samsung.com
- via.placeholder.com
- cdnjs.cloudflare.com
- www.google.com
- play.google.com
- apps.apple.com
- links.s-gift.app
- maps.googleapis.com
- static.cloudflareinsights.com
- 104.21.71.55
- 104.21.57.70
Other scans of xoxoceylon.com (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - malicious
- 19 Aug 2026 - malicious
- 19 Aug 2026 - malicious
Questions about xoxoceylon.com
- Is xoxoceylon.com safe?
- No. MalwareAnalyzer scanned xoxoceylon.com on 19 Aug 2026 and returned a malicious verdict with a score of 68 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with xoxoceylon.com?
- 1 analysed samples communicate with this URL, including Phishing.
- How was xoxoceylon.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of xoxoceylon.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan