bige.vn - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned bige.vn and returned a suspicious verdict (score 28), categorised as credential-harvest. The page resolved to 160.22.122.110 on IONSITE SOFTWARE ONE MEMBER COMPANY LIMITED in VN. 7 domains and 1 IP were contacted, over 3 HTTP requests. 2 malware samples communicate with this URL (Phishing). The request followed 1 redirect before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 37%
- Scanned URL:
http://bige.vn/uploads/userfiles/file/judaline.pdf - Domain: bige.vn · IP: 160.22.122.110 · AS135918 · VN
- Server: Apache/2
- Page title: Không tìm thấy trang này – Trung tâm thương mại BIGE
- HTTP status: 404 · text/html; charset=UTF-8
- TLS issuer: C=US, O=Let's Encrypt, CN=YE1 · valid to Oct 7 08: · subject CN=bige.vn
- HTTP requests captured: 3
- Scan tier: standard · observed 2026-08-20 05:14:52 UTC
Redirect chain
http://bige.vn/uploads/userfiles/file/judaline.pdfhttps://bige.vn/uploads/userfiles/file/judaline.pdf
Malware communicating with this URL (2)
These samples were observed contacting or being served from bige.vn. Each links to its full analysis.
- Phishing - referenced ·
eb10c5ac3ce9a3ff5dca299016135561· first seen 2026-08-15 - Phishing - referenced ·
ec2b91899334f5f6665cd8879d6b3f60· first seen 2026-08-14
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Categories
- credential-harvest
Why this verdict
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
- Matches phishing-kit family "Meta / Facebook Login Kit"
Detected technologies
- Apache
- WordPress
Contacted infrastructure
- 160.22.122.110 - AS135918 IONSITE SOFTWARE ONE MEMBER COMPANY LIMITED (Viet Nam)
Observed indicators
- bige.vn
- gmpg.org
- rehubdocs.wpsoul.com
- recompare.wpsoul.net
- themeforest.net
- recart.wpsoul.com
- fleek.us10.list-manage.com
- 160.22.122.110
- https://bige.vn/uploads/userfiles/file/judaline.pdf
- http://gmpg.org/xfn/11
- https://bige.vn/xmlrpc.php
- https://bige.vn/feed/
- https://bige.vn/comments/feed/
- https://bige.vn/wp-content/cache/wpo-minify/1783645743/assets/wpo-minify-header-fd36503f.min.css
- https://bige.vn/wp-content/cache/wpo-minify/1783645743/assets/wpo-minify-header-7baf0e53.min.js
- https://bige.vn/wp-content/cache/wpo-minify/1783645743/assets/wpo-minify-header-319546ec.min.js
- https://bige.vn/wp-json/
- https://bige.vn/xmlrpc.php?rsd
- https://bige.vn/wp-content/themes/rehub-theme/fonts/rhicons.woff2?3oibrk
- http://rehubdocs.wpsoul.com/docs/rehub-theme/basic-settings/how-to-add-top-line-on-site/
Other scans of bige.vn (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - suspicious
Questions about bige.vn
- Is bige.vn safe?
- No. MalwareAnalyzer scanned bige.vn on 20 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with bige.vn?
- 2 analysed samples communicate with this URL, including Phishing.
- How was bige.vn checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of bige.vn
Scanned on MalwareAnalyzer by Cyble · Open interactive scan