dn.com - suspicious URL scan, 17 Aug 2026
MalwareAnalyzer by Cyble scanned dn.com and returned a suspicious verdict (score 28). The page resolved to 3.175.115.33 on Amazon.com, Inc. in US. 9 domains and 2 IPs were contacted, over 8 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 17 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
http://syuncyoku.jp/upload/file/9321168466.pdf - Domain: dn.com · IP: 3.175.115.33 · AS16509 · US
- Server: nginx
- Page title: syuncyoku.jp Premium domain name trading - syuncyoku.jp Buy and sell domain names at a fixed price- Dn.com domain name trading platform
- HTTP status: 200 · text/html;charset=UTF-8
- TLS issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M01 · valid to Dec 31 23: · subject CN=dn.com
- HTTP requests captured: 8
- Scan tier: standard · observed 2026-08-17 11:14:34 UTC
Redirect chain
http://syuncyoku.jp/upload/file/9321168466.pdfhttps://dn.com/sale/syuncyoku.jp
Malware communicating with this URL (1)
These samples were observed contacting or being served from dn.com. Each links to its full analysis.
- Phishing - referenced ·
36eff878a801b3ab5f3a4b3d720ca83a· first seen 2026-08-17
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- Amazon CloudFront
- Google Analytics
- jQuery
- Bootstrap
Contacted infrastructure
- 3.175.115.33 - AS16509 Amazon.com, Inc. (United States)
- 35.173.228.115 - AS14618 Amazon Technologies Inc. (United States)
Observed indicators
- dn.com
- top.dn.com
- global.domains
- user.dn.com
- twitter.com
- www.facebook.com
- www.linkedin.com
- hm.baidu.com
- www.googletagmanager.com
- 3.175.115.33
- 35.173.228.115
- https://dn.com/sale/syuncyoku.jp
- https://dn.com/rs/plugins/bootstrap/css/bootstrap.min.css
- https://dn.com/rs/plugins/layui/css/layui.css
- https://dn.com/rs/styles/base.css?v=20251110
- https://dn.com/rs/styles/main.css?v=20260602
- https://dn.com/rs/styles/domain-detail.css?v=2026011501
- https://dn.com/favicon.ico
- https://dn.com/en-us/
- https://dn.com/en-us/sale/syuncyoku.jp
Other scans of dn.com (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 19 Aug 2026 - unknown ·
https://dn.com/sale/n.io - 17 Aug 2026 - suspicious
Questions about dn.com
- Is dn.com safe?
- No. MalwareAnalyzer scanned dn.com on 17 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with dn.com?
- 1 analysed samples communicate with this URL, including Phishing.
- How was dn.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of dn.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan