55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn - URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn and returned a unknown verdict (score -12). The page resolved to 172.67.71.3 on Cloudflare, Inc. in US. 10 domains and 2 IPs were contacted, over 7 HTTP requests. 1 malware sample communicates with this URL (Zusy). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
https://th.cn/ - Domain: 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn · IP: 172.67.71.3 · AS13335 · US
- Server: cloudflare
- Page title: 美果123 - 今日推荐
- HTTP status: 200 · text/html
- TLS issuer: C=US, O=Google Trust Services, CN=WE1 · valid to Nov 3 11: · subject CN=meiguo123.cn
- HTTP requests captured: 7
- Scan tier: fast · observed 2026-08-20 23:57:28 UTC
Redirect chain
https://th.cn/https://55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn/?site=dGguY24=&acct=930
Malware communicating with this URL (1)
These samples were observed contacting or being served from 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn. Each links to its full analysis.
- Zusy - referenced ·
cc9c6389784a71ac105e479a8b7298f9· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Cloudflare
- jQuery
- Cloudflare Insights
Contacted infrastructure
- 172.67.71.3 - AS13335 Cloudflare, Inc. (United States)
- 146.235.218.82 - AS31898 Oracle Corporation (United States)
Observed indicators
- 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn
- dragonstatic.com
- cdnjs.cloudflare.com
- dpstatic.meiguo123.cn
- meiguo.com
- www.aliyun.com
- mingqu.com
- beian.miit.gov.cn
- hm.baidu.com
- static.cloudflareinsights.com
- 172.67.71.3
- 146.235.218.82
- https://55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn/?site=dGguY24=&acct=930
- https://dragonstatic.com/ico-p/dp.ico
- https://cdnjs.cloudflare.com/ajax/libs/jquery/3.7.1/jquery.min.js
- https://dpstatic.meiguo123.cn/parking-render/js/index.js?ts=1787252711011
- https://55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn/js/index.js?ts=1787252711011
- https://dpstatic.meiguo123.cn/domain.e3a9c4f1b7d28a0c6f5e9b4d1a8c2f7e.js
- https://dpstatic.meiguo123.cn/style.1f9c3a7e5b2d4a8c6e0f7b9d1c4a2e8f.css
- https://dpstatic.meiguo123.cn/parking/js/track.9b4e2d8f6c1a5e0d3f7b9c2a4e8d1a6b.js
Questions about 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn
- Is 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn safe?
- The scan of 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn on 20 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn?
- 1 analysed samples communicate with this URL, including Zusy.
- How was 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of 55824579028ad157afeac83a1dfc41ed.dp2024.meiguo123.cn
Scanned on MalwareAnalyzer by Cyble · Open interactive scan