dayuntang.com - suspicious URL scan, 14 Aug 2026
MalwareAnalyzer by Cyble scanned dayuntang.com and returned a suspicious verdict (score 28). The page resolved to 23.225.94.66. 2 domains and 2 IPs were contacted, over 7 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 14 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
http://dayuntang.com/assets/uploads/ckedit/files/20210912200615.pdf - Domain: dayuntang.com · IP: 23.225.94.66
- Server: nginx
- Page title: 给我个黄网站2020国语在线观看 - 策驰影院
- HTTP status: 200 · text/html;charset=utf-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YR1 · valid to Aug 26 16: · subject CN=dayuntang.com
- HTTP requests captured: 7
- Scan tier: standard · observed 2026-08-14 13:19:03 UTC
Redirect chain
http://dayuntang.com/assets/uploads/ckedit/files/20210912200615.pdfhttps://dayuntang.com/assets/uploads/ckedit/files/20210912200615.pdf
Malware communicating with this URL (1)
These samples were observed contacting or being served from dayuntang.com. Each links to its full analysis.
- Phishing - referenced ·
6b69b49982bbeed4605a371c629fe71e· first seen 2026-08-12
Antivirus & YARA (1 of 44 engines)
- YARA: JPCERT/CC [yara]: JPCERT_LODEINFO (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: JPCERT_LODEINFO
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- jQuery
Contacted infrastructure
- 23.225.94.66 - AS40065 CloudRadium L.L.C (United States)
- 23.225.94.75 - AS40065 CloudRadium L.L.C (United States)
Observed indicators
- dayuntang.com
- s9.cnzz.com
- 23.225.94.66
- 23.225.94.75
- https://dayuntang.com/assets/uploads/ckedit/files/20210912200615.pdf
- https://dayuntang.com/template/default18/template/mb13/statics/img/favicon.ico
- https://dayuntang.com/template/default18/template/mb13/statics/font/iconfont.css
- https://dayuntang.com/template/default18/template/mb13/statics/css/stui_block.css
- https://dayuntang.com/template/default18/template/mb13/statics/css/stui_block_color.css
- https://dayuntang.com/template/default18/template/mb13/statics/css/stui_default.css
- https://dayuntang.com/template/default18/template/mb13/statics/js/jquery.min.js
- https://dayuntang.com/template/default18/template/mb13/statics/js/stui_default.js
- https://dayuntang.com/template/default18/template/mb13/statics/js/stui_block.js
- https://dayuntang.com/template/default18/template/mb13/statics/js/home.js
- https://dayuntang.com/
- https://dayuntang.com/template/default18/template/mb13/statics/js/jquery.autocomplete.js
- https://dayuntang.com/search/-------------.html
- https://dayuntang.com/type/dianying.html
- https://dayuntang.com/type/dianshiju.html
- https://dayuntang.com/type/zongyi.html
Other scans of dayuntang.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - suspicious ·
https://dayuntang.com/assets/uploads/ckedit/files/20210904000702.pdf - 22 Aug 2026 - suspicious ·
https://dayuntang.com/assets/uploads/ckedit/files/20210904000702.pdf - 9 Aug 2026 - unknown ·
https://dayuntang.com/assets/uploads/ckedit/files/20210920212834.pdf - 8 Aug 2026 - unknown ·
https://dayuntang.com/assets/uploads/ckedit/files/20210909233316.pdf
Questions about dayuntang.com
- Is dayuntang.com safe?
- No. MalwareAnalyzer scanned dayuntang.com on 14 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with dayuntang.com?
- 1 analysed samples communicate with this URL, including Phishing.
- How was dayuntang.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of dayuntang.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan