Is acquilarssb.top safe?
http://acquilarssb.top/
Malware page masquerading as a PDF viewer update on a 27-day-old domain.
This is a malware distribution page. Four antivirus engines flagged it as malicious and the page uses a fake PDF viewer update prompt to trick visitors into downloading harmful software. Do not click the download button or install anything from this site.
Read the full analysis01 · Investigation Brief
Investigation Brief
The domain was registered only 27 days ago through NameSilo with privacy protection. Four of 92 antivirus engines flagged the URL as malicious, including CRDF and Forcepoint ThreatSeeker. The page displays a fake document download prompt claiming the user's PDF viewer is outdated. The SSL certificate is invalid with no issuer listed. The page loads external domains including nestlemills31. screenconnect. com, a known remote-access tool domain. These signals together indicate active malware distribution rather than a legitimate service.
Page Content
The captured page shows a modal titled "Secure Document Loading" with text claiming the visitor's PDF viewer is outdated. A prominent download button urges the user to install an update. No legitimate branding, company name, or contact details appear anywhere on the page.
Infrastructure
The site sits on IP 104.21.26.179 behind Cloudflare. The SSL certificate is invalid with zero days to expiry and no issuer. External scripts load from nestlemills31.screenconnect.com, a domain associated with remote-access software often abused in malware campaigns. No redirects occur; the malicious content is served directly.
Domain History
The domain acquilarssb.top was registered 27 days ago on 2026-06-30 through NameSilo, LLC. Owner information is hidden behind privacy protection. The domain has no established history or traffic ranking.
Web Reputation
Four antivirus engines returned malicious verdicts: CRDF, Forcepoint ThreatSeeker, LevelBlue, and SOCRadar. Two additional engines flagged the site as suspicious. Google Safe Browsing lists no block, but the engine detections alone are sufficient to classify the URL as harmful.
What this means for you
Visiting this page risks downloading malware disguised as a PDF viewer update. Do not click any download links or install software from this domain.
Why the score is 21
The score combines saved deterministic evidence with the grounded analysis available for this report. Coverage remains separate so missing sources cannot be mistaken for clean results.
02 · Security Evidence
Security evidence
Antivirus Engines
Fresh result
6 engines flagged this URL
Every saved adverse engine is listed below. The full provider matrix remains available for audit.
- Malicious
- 4
- Suspicious
- 2
- Total
- 92
| Engine | Finding |
|---|---|
| CRDFMalicious | malicious |
| Forcepoint ThreatSeekerMalicious | malicious |
| LevelBlueMalicious | phishing |
| SOCRadarMalicious | phishing |
| alphaMountain.aiSuspicious | suspicious |
| GridinsoftSuspicious | suspicious |
All 92 engine results
- CRDF - malicious - Malicious
- Forcepoint ThreatSeeker - malicious - Malicious
- LevelBlue - phishing - Malicious
- SOCRadar - phishing - Malicious
- alphaMountain.ai - suspicious - Suspicious
- Gridinsoft - suspicious - Suspicious
- 0xSI_f33d - unrated - Clean
- Abusix - clean - Clean
- Acronis - clean - Clean
- ADMINUSLabs - clean - Clean
- AILabs (MONITORAPP) - clean - Clean
- AlienVault - clean - Clean
- AlphaSOC - unrated - Clean
- Antiy-AVL - clean - Clean
- ArcSight Threat Intelligence - unrated - Clean
- AutoShun - unrated - Clean
- Bfore.Ai PreCrime - unrated - Clean
- BitDefender - clean - Clean
- Bkav - unrated - Clean
- BlockList - clean - Clean
- Blueliv - clean - Clean
- Certego - clean - Clean
- ChainPatrol - unrated - Clean
- Chong Lua Dao - clean - Clean
- CINS Army - clean - Clean
- Cluster25 - unrated - Clean
- Criminal IP - unrated - Clean
- CSIS Security Group - unrated - Clean
- CTX AI - clean - Clean
- Cyan - unrated - Clean
- Cyble - clean - Clean
- CyRadar - clean - Clean
- desenmascara.me - clean - Clean
- DNS8 - unrated - Clean
- Dr.Web - clean - Clean
- EmergingThreats - clean - Clean
- Emsisoft - clean - Clean
- Ermes - unrated - Clean
- ESET - clean - Clean
- ESTsecurity - clean - Clean
- Fortinet - clean - Clean
- Fortra - unrated - Clean
- G-Data - clean - Clean
- GCP Abuse Intelligence - unrated - Clean
- Google Safe Browsing - clean - Clean
- GreenSnow - clean - Clean
- GreyNoise - unrated - Clean
- Guardpot - unrated - Clean
- Heimdal Security - clean - Clean
- Hunt.io Intelligence - unrated - Clean
- IPsum - clean - Clean
- Juniper Networks - clean - Clean
- K7AntiVirus - unrated - Clean
- Kaspersky - clean - Clean
- Lionic - clean - Clean
- Lumu - unrated - Clean
- Malwared - clean - Clean
- MalwarePatrol - clean - Clean
- MalwareURL - unrated - Clean
- Mimecast - unrated - Clean
- Netcraft - unrated - Clean
- OpenPhish - clean - Clean
- PhishFort - unrated - Clean
- Phishing Database - clean - Clean
- Phishtank - clean - Clean
- PREBYTES - clean - Clean
- PrecisionSec - unrated - Clean
- Quick Heal - clean - Clean
- Quttera - clean - Clean
- Rising - clean - Clean
- SafeToOpen - unrated - Clean
- Sangfor - clean - Clean
- Sansec eComscan - unrated - Clean
- Scantitan - clean - Clean
- SCUMWARE.org - clean - Clean
- Seclookup - clean - Clean
- Snort IP sample list - unrated - Clean
- Sophos - clean - Clean
- StopForumSpam - clean - Clean
- Sucuri SiteCheck - clean - Clean
- ThreatHive - clean - Clean
- URLhaus - clean - Clean
- URLQuery - unrated - Clean
- Viettel Threat Intelligence - clean - Clean
- VIPRE - unrated - Clean
- ViriBack - clean - Clean
- VX Vault - clean - Clean
- Webroot - clean - Clean
- Xcitium Verdict Cloud - unrated - Clean
- Yandex Safebrowsing - clean - Clean
- ZeroCERT - clean - Clean
- ZeroFox - unrated - Clean
Security Scans
Checked against the browser threat feeds available to this scan — no hit.
What we observed
Visual warning signs were identified
The page displays a classic social engineering pattern that attempts to coerce users into downloading malicious software by masquerading as a necessary PDF viewer update.
What the captured page showed
4 observations- 01
Deceptive 'Downloading Secure Document' modal designed to trick users into downloading unwanted software
- 02
False urgency alert claiming the user's PDF viewer is outdated
- 03
Call-to-action button prompting a download under the guise of fixing a software issue
- 04
Lack of legitimate branding or context for the document being downloaded
03 · Investigation Story
Investigation story
- 1
What the site claims
Secure Document Loading
- 2
What we observed
The page content was captured and checked alongside 92 antivirus results.
- 3
What independent research found
No complete independent-research result was available in this saved report.
- 4
What remains unverified
1 of the five core capabilities did not complete, so those gaps remain visible in the coverage ledger.
Scam-Type Likelihood
1 of 21 categories showed signals
Each card names a specific harm pattern and the concrete facts that support it. The category score is supporting context; the report verdict above remains the final severity decision.
- Tagged as scareware, abusive ads, or deceptive notification behavior.
20Show remaining categoriesHide checked categories
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
04 · Domain & Infrastructure
Domain & infrastructure
The plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Infrastructure map
How the saved page connected to the wider web.
Domain Timeline
- Jun 30, 2026Domain registered
First appeared in WHOIS records — 27 days old today.
- Jul 28, 2026Saved security review — Flagged as suspicious
The completed checks from this saved scan are detailed above.
acquilarssb.top was registered very recently and is already flagged. Freshly-registered domains are disproportionately used for scams, and a young domain with active threat signals warrants extra caution.
Contact Verification
Saved contact details can help identify the operator. Their presence supports traceability; it does not prove the business is trustworthy.
- No direct contact email found on the captured page.
Domain & Encryption
Server Reputation
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
05 · Evidence Ledger
Evidence ledger
The conclusion is supported by the evidence saved with this report.
Technical threat
Malware, phishing, credential theft and hostile infrastructure.
Multiple antivirus warnings
Operator / customer risk
Complaints, withdrawals, business conduct and commercial traps.
No confirmed evidence in this dimension.
Source coverage and freshness
Status shows whether usable evidence was saved; finding shows what that evidence observed.
| Source | Result | Completion | Finding | Freshness |
|---|---|---|---|---|
| Antivirus | 6 of 92 engines flagged | Completed | Adverse | fresh · Jul 28, 2026 |
| Browser protection | No browser threat-list match | Completed | No adverse finding | Not available |
| Page content | Page fetched · HTTP 200 | Completed | No adverse finding | Not available |
| Visual evidence | 4 visible observations saved with the page capture | Limited | Adverse | Not available |
| Independent research | Independent research was not available for this report | Unavailable | No saved finding | Not available |
- Page content
- Result: Page fetched · HTTP 200
- Completed
- No adverse finding
- Visual evidence
- Result: 4 visible observations saved with the page capture
- Limited
- Adverse
- Independent research
- Result: Independent research was not available for this report
- Unavailable
- No saved finding
07 · Community
Community
08 · Safety FAQ
Safety FAQ
Common questions, answered directly from the scan data above — so the answers reflect the saved verdict and evidence in this report.
0 community contributions
Share what happened, what the site requested, and what others should watch for.
Community reviews never change the scanner verdict.