106.53.123.17 - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned 106.53.123.17 and returned a unknown verdict (score 6). The page resolved to 106.53.123.17 on Tencent cloud computing (Beijing) Co., Ltd. in CN. 2 domains and 2 IPs were contacted. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 9%
- Scanned URL:
http://chinasoftcore.com/userfiles/file/%5C/sugalukatikikokapat.pdf - Domain: 106.53.123.17 · IP: 106.53.123.17 · AS45090 · CN
- Page title: IIS 10.0 Detailed Error - 404.0 - Not Found
- HTTP status: 404 · text/html; charset=utf-8
- Scan tier: fast · observed 2026-08-21 10:57:08 UTC
Redirect chain
http://chinasoftcore.com/userfiles/file/%5C/sugalukatikikokapat.pdfhttp://106.53.123.17:3389/userfiles/file///sugalukatikikokapat.pdf?cdnhost=chinasoftcore__com__cdn6108&
Malware communicating with this URL (1)
These samples were observed contacting or being served from 106.53.123.17. Each links to its full analysis.
- Phishing - referenced ·
7d0f738b094d710bbb1442e860ed094f· first seen 2026-08-21
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Served over plaintext HTTP
Contacted infrastructure
- 106.53.123.17 - AS45090 Tencent cloud computing (Beijing) Co., Ltd. (China)
- 43.161.228.103 - AS132203 ACEVILLE PTE.LTD. (Hong Kong)
Observed indicators
- 106.53.123.17
- go.microsoft.com
- 106.53.123.17
- 43.161.228.103
- http://106.53.123.17:3389/userfiles/file///sugalukatikikokapat.pdf?cdnhost=chinasoftcore__com__cdn6108&
- http://go.microsoft.com/fwlink/?LinkID=66439
- http://go.microsoft.com/fwlink/?LinkID=62293&IIS70Error=404,0,0x80070002,14393
Questions about 106.53.123.17
- Is 106.53.123.17 safe?
- The scan of 106.53.123.17 on 21 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with 106.53.123.17?
- 1 analysed samples communicate with this URL, including Phishing.
- How was 106.53.123.17 checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of 106.53.123.17
Scanned on MalwareAnalyzer by Cyble · Open interactive scan