sieuthi-go.vn - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned sieuthi-go.vn and returned a suspicious verdict (score 43). The page resolved to 42.96.50.46 on CMC Telecom Infrastructure Company in VN. 1 domain and 2 IPs were contacted, over 32 HTTP requests. The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 43) · Confidence 49%
- Scanned URL:
https://sieuthigo.vn/upload/ck/files/nawiwusat.pdf - Domain: sieuthi-go.vn · IP: 42.96.50.46 · AS45903 · VN
- Server: 2.0.0
- HTTP status: 404 · text/html; charset=utf-8
- TLS issuer: C=US, O=DigiCert Inc, OU=www.digicert.com, CN=GeoTrust TLS RSA CA G1 · valid to Jan 31 23: · subject C=VN, ST=Ho Chi Minh City, O=EB SERVICES COMPANY LIMITED, CN=*.sieuthi-go.vn
- Evidenced operator: EB SERVICES COMPANY LIMITED
- HTTP requests captured: 32
- Scan tier: standard · observed 2026-08-20 17:16:37 UTC
Redirect chain
https://sieuthigo.vn/upload/ck/files/nawiwusat.pdfhttps://sieuthi-go.vn/upload/ck/files/nawiwusat.pdf
Antivirus & YARA (2 of 47 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
- YARA: MalwareAnalyser community pack [yara]: TL_Ransomware_Note_Markers (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- 2 antivirus/YARA engines flagged the page content: SOPHOS_Gootloader_JS, TL_Ransomware_Note_Markers
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Next.js
Contacted infrastructure
- 42.96.50.46 - AS45903 CMC Telecom Infrastructure Company (Viet Nam)
- 160.187.59.94 - AS152994 EB Services LLC (Viet Nam)
Observed indicators
- sieuthi-go.vn
- 42.96.50.46
- 160.187.59.94
- https://sieuthi-go.vn/upload/ck/files/nawiwusat.pdf
- https://sieuthi-go.vn/_next/static/css/6ea8bbd1ac6c842a.css
- https://sieuthi-go.vn/_next/static/css/2aa199ae6265e4c0.css
- https://sieuthi-go.vn/_next/static/chunks/polyfills-c67a75d1b6f99dc8.js
- https://sieuthi-go.vn/_next/static/chunks/webpack-f5509922eec5e91d.js
- https://sieuthi-go.vn/_next/static/chunks/framework-fee8a7e75612eda8.js
- https://sieuthi-go.vn/_next/static/chunks/main-629b483661a6a7b5.js
- https://sieuthi-go.vn/_next/static/chunks/pages/_app-7fd8e99f1b602b66.js
- https://sieuthi-go.vn/_next/static/chunks/5675-86013b480fbbd7c2.js
- https://sieuthi-go.vn/_next/static/chunks/4477-8c83b2891888ce84.js
- https://sieuthi-go.vn/_next/static/chunks/9571-6334862bcb43fed0.js
- https://sieuthi-go.vn/_next/static/chunks/6360-792c0bc3ac5e314c.js
- https://sieuthi-go.vn/_next/static/chunks/3385-6bc75dee878f8482.js
- https://sieuthi-go.vn/_next/static/chunks/8226-6a4cb7b83162bdd3.js
- https://sieuthi-go.vn/_next/static/chunks/8086-3f26d3676eba5884.js
- https://sieuthi-go.vn/_next/static/chunks/1664-984ff4b7948f7ae8.js
- https://sieuthi-go.vn/_next/static/chunks/4484-0699bb96bc2fc02a.js
Other scans of sieuthi-go.vn (8)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - malicious
- 15 Aug 2026 - unknown ·
https://sieuthi-go.vn/upload/ck/files/54159525187.pdf - 15 Aug 2026 - unknown ·
https://sieuthi-go.vn/upload/ck/files/54159525187.pdf - 15 Aug 2026 - unknown ·
https://sieuthi-go.vn/upload/ck/files/54159525187.pdf - 15 Aug 2026 - unknown ·
https://sieuthi-go.vn/upload/ck/files/54159525187.pdf - 15 Aug 2026 - unknown ·
https://sieuthi-go.vn/upload/ck/files/54159525187.pdf - 15 Aug 2026 - unknown ·
https://sieuthi-go.vn/upload/ck/files/54159525187.pdf - 15 Aug 2026 - unknown ·
https://sieuthi-go.vn/upload/ck/files/54159525187.pdf
Questions about sieuthi-go.vn
- Is sieuthi-go.vn safe?
- No. MalwareAnalyzer scanned sieuthi-go.vn on 20 Aug 2026 and returned a suspicious verdict with a score of 43 out of 100. Treat it as hostile until it is re-checked.
- How was sieuthi-go.vn checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of sieuthi-go.vn
Scanned on MalwareAnalyzer by Cyble · Open interactive scan