duba.net - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned duba.net and returned a suspicious verdict (score 28). The page resolved to 218.12.76.169 on China Unicom Hebei province network in CN. The domain was registered 8919 days ago through eName Technology Co., Ltd.. 14 domains and 1 IP were contacted, over 7 HTTP requests. 2 malware samples communicate with this URL (Generickdz, Mikey). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://duba.net/ - Domain: duba.net · IP: 218.12.76.169 · AS4837 · CN
- Server: openresty
- Page title: 【金山毒霸官网】免费杀毒软件|电脑杀毒|全面扫描|垃圾清理|电脑加速|软件管家
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: eName Technology Co., Ltd. · domain age 8919 days · created 2002-03-20
- TLS issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 · valid to Feb 6 03: · subject C=CN, ST=北京, L=北京, O=北京灵豹智能科技有限公司, CN=*.duba.net
- Evidenced operator: 北京灵豹智能科技有限公司
- HTTP requests captured: 7
- Scan tier: fast · observed 2026-08-20 19:23:29 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from duba.net. Each links to its full analysis.
- Generickdz - referenced ·
b02318fd36dbb66df4b9144042d21627· first seen 2026-08-20 - Mikey - referenced ·
2392069cf8f070176f271e16d96fe8ac· first seen 2026-08-13
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nuxt.js
Contacted infrastructure
- 218.12.76.169 - AS4837 China Unicom Hebei province network (China)
Observed indicators
- duba.net
- www.ijinshan.com
- hm.baidu.com
- fe-res.zhhainiao.com
- new.duba.net
- www.duba.com
- team.duba.net
- dh1.cmcmcdn.com
- ti.duba.net
- young.duba.net
- cd001.www.duba.net
- www.duba.net
- beian.miit.gov.cn
- weibo.com
- 218.12.76.169
- https://duba.net/
- https://www.ijinshan.com/favicon.ico
- https://hm.baidu.com/hm.js?7b344617dc861558bc02241018ca7977
- https://fe-res.zhhainiao.com/ccweb/duba-ccweb-prod-0.1.6.iife.js
- https://new.duba.net/_nuxt/0acb26e.js
Questions about duba.net
- Is duba.net safe?
- No. MalwareAnalyzer scanned duba.net on 20 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with duba.net?
- 2 analysed samples communicate with this URL, including Generickdz, Mikey.
- How was duba.net checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of duba.net
Scanned on MalwareAnalyzer by Cyble · Open interactive scan