aia1.wosign.com - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned aia1.wosign.com and returned a unknown verdict (score 6). The page resolved to 101.91.111.113 on CHINANET SHANGHAI PROVINCE NETWORK in CN. 1 domain and 1 IP were contacted. 3 malware samples communicate with this URL (Generickdz). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score 6) · Confidence 9%
- Scanned URL:
http://aia1.wosign.com/class3.code.ca1.cer07 - Domain: aia1.wosign.com · IP: 101.91.111.113 · AS4812 · CN
- Server: nginx/1.28.0
- Page title: 404 Not Found
- HTTP status: 404 · text/html
- Scan tier: fast · observed 2026-08-21 11:27:21 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from aia1.wosign.com. Each links to its full analysis.
- 56a64aaa6886701aebe4fca7a4fd84d39d542dd68b927aa31eab9e6e34f50f4b - referenced ·
56a64aaa6886701aebe4fca7a4fd84d3· first seen 2026-08-21 - ff1e0f7d9eb5a80d720d1747dbbd10445d372b14b2aa7a0510e0528aaa28068e - referenced ·
ff1e0f7d9eb5a80d720d1747dbbd1044· first seen 2026-08-21 - Generickdz - referenced ·
b02318fd36dbb66df4b9144042d21627· first seen 2026-08-20
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Served over plaintext HTTP
Detected technologies
- Nginx
Contacted infrastructure
- 101.91.111.113 - AS4812 CHINANET SHANGHAI PROVINCE NETWORK (China)
Observed indicators
- aia1.wosign.com
- 101.91.111.113
- http://aia1.wosign.com/class3.code.ca1.cer07
Other scans of aia1.wosign.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - unknown
Questions about aia1.wosign.com
- Is aia1.wosign.com safe?
- The scan of aia1.wosign.com on 21 Aug 2026 reached no verdict either way (score 6). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with aia1.wosign.com?
- 3 analysed samples communicate with this URL, including Generickdz.
- How was aia1.wosign.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of aia1.wosign.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan