tunhuaduytan.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned tunhuaduytan.com and returned a suspicious verdict (score 28). The page resolved to 112.213.89.79 on SUPER ONLINE DATA JOINT STOCK COMPANY in VN. The domain was registered 3725 days ago through P.A. Viet Nam Company Limited. 3 domains and 1 IP were contacted, over 7 HTTP requests. 1 malware sample communicates with this URL (Phishing). This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://tunhuaduytan.com/upload/userfiles/files/23971274503.pdf - Domain: tunhuaduytan.com · IP: 112.213.89.79 · AS45544 · VN
- Server: LiteSpeed
- Page title: Tu Nhua Duy Tan - Page not found
- HTTP status: 404 · text/html; charset=UTF-8
- Registrar: P.A. Viet Nam Company Limited · domain age 3725 days · created 2016-06-09
- TLS issuer: C=AT, O=ZeroSSL GmbH, CN=ZeroSSL RSA DV SSL CA 2 · valid to Sep 8 23: · subject CN=tunhuaduytan.com.vn
- HTTP requests captured: 7
- Scan tier: standard · observed 2026-08-21 08:10:42 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from tunhuaduytan.com. Each links to its full analysis.
- Phishing - referenced ·
bda6e7b8255961f7752de057b38f6526· first seen 2026-08-15
Antivirus & YARA (1 of 47 engines)
- YARA: Stratosphere IPS [yara]: STRATO_Tor_Onion_C2 (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: STRATO_Tor_Onion_C2
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- LiteSpeed
- jQuery
Contacted infrastructure
- 112.213.89.79 - AS45544 SUPER ONLINE DATA JOINT STOCK COMPANY (Viet Nam)
Observed indicators
- tunhuaduytan.com
- connect.facebook.net
- sp.zalo.me
- 112.213.89.79
- https://tunhuaduytan.com/upload/userfiles/files/23971274503.pdf
- https://tunhuaduytan.com/favicon.ico
- https://tunhuaduytan.com/css/main.css
- https://tunhuaduytan.com/css/form.css
- https://tunhuaduytan.com/css/page.css
- https://tunhuaduytan.com/css/menu.css
- https://tunhuaduytan.com/css/jquery-ui.css
- https://tunhuaduytan.com/js/jquery-1.8.3.min.js
- https://tunhuaduytan.com/js/jquery.carouFredSel-6.1.0-packed.js
- https://tunhuaduytan.com/css/Kendo/kendo.metro.min.css
- https://tunhuaduytan.com/css/Kendo/kendo.common.min.css
- https://tunhuaduytan.com/js/Kendo/kendo.web.min.js
- https://tunhuaduytan.com/js/jquery-ui.js
- https://tunhuaduytan.com/js/page/content.page.js
- https://connect.facebook.net/vi_VN/sdk.js#xfbml=1&version=v2.3&appId=1576343885962915
- https://tunhuaduytan.com/
Other scans of tunhuaduytan.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - suspicious
Questions about tunhuaduytan.com
- Is tunhuaduytan.com safe?
- No. MalwareAnalyzer scanned tunhuaduytan.com on 21 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with tunhuaduytan.com?
- 1 analysed samples communicate with this URL, including Phishing.
- How was tunhuaduytan.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of tunhuaduytan.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan