wcdt.co.th - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned wcdt.co.th and returned a suspicious verdict (score 54). The page resolved to 104.248.153.28 on DigitalOcean, LLC in SG. 1 domain and 1 IP were contacted. 13 malware samples communicate with this URL (Phishing). This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 54) · Confidence 60%
- Scanned URL:
https://wcdt.co.th/wp-content/plugins/super-forms/uploads/php/files/pi9qubvcfdg8h65055l8qcn3l0/49274469339.pdf - Domain: wcdt.co.th · IP: 104.248.153.28 · AS14061 · SG
- Server: nginx/1.15.5 (Ubuntu)
- HTTP status: 200 · application/pdf
- Scan tier: fast · observed 2026-08-23 10:47:13 UTC
Malware communicating with this URL (13)
These samples were observed contacting or being served from wcdt.co.th. Each links to its full analysis.
- Phishing - referenced ·
ee770149a49523424fcb31fbecfa2a58· first seen 2026-08-23 - Phishing - referenced ·
3d441cdc8d642d93f776a31c2634b0d6· first seen 2026-08-22 - Phishing - referenced ·
dcdfad2c349449ccee9ea2fd394d5c03· first seen 2026-08-21 - Phishing - referenced ·
519b46dfab0d81e09be02169d76961ac· first seen 2026-08-19 - Phishing - referenced ·
6939b6afb85eed3b91b5439b83d905d0· first seen 2026-08-16 - Phishing - referenced ·
7bb52ca630f34749f9e3b4bc53793719· first seen 2026-08-15 - Phishing - referenced ·
7da465ba8292124551f3150a4cf02f5f· first seen 2026-08-15 - Phishing - referenced ·
414f436aaafc02882d06e7b200a97d1e· first seen 2026-08-15 - Phishing - referenced ·
0b17a729133e1e5a54cd7b7dc7b85f05· first seen 2026-08-15 - 160e64b6b21438---42528492592.pdf - referenced ·
3f108fd062d7e7999b4c39fa348875f1· first seen 2026-08-14 - Phishing - referenced ·
e1c64540b34f4ad078b13bcde6451482· first seen 2026-08-14 - Phishing - referenced ·
df433e9a602669d758c5a26dde519aa5· first seen 2026-08-13 - Phishing - referenced ·
9e86ff0c37c175456e269115718df57f· first seen 2026-08-11
Antivirus & YARA (1 of 48 engines)
- ClamAV (daily) [av]: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (served file)
Why this verdict
- Antivirus/YARA detection in page content: Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- File download routed to the malware sandbox (49274469339.pdf)
Detected technologies
- Nginx
Contacted infrastructure
- 104.248.153.28 - AS14061 DigitalOcean, LLC (Singapore)
Files served by this page
- 49274469339.pdf ·
f90234bee7c5462e39a50d44057a806e
Observed indicators
- wcdt.co.th
- 104.248.153.28
- https://wcdt.co.th/wp-content/plugins/super-forms/uploads/php/files/pi9qubvcfdg8h65055l8qcn3l0/49274469339.pdf
Other scans of wcdt.co.th (2)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 14 Aug 2026 - suspicious ·
https://wcdt.co.th/wp-content/plugins/super-forms/uploads/php/files/db7dq7ib0rdtlt5o8nm2k7lkuj/gijar - 14 Aug 2026 - suspicious ·
https://wcdt.co.th/wp-content/plugins/super-forms/uploads/php/files/db7dq7ib0rdtlt5o8nm2k7lkuj/gijar
Questions about wcdt.co.th
- Is wcdt.co.th safe?
- No. MalwareAnalyzer scanned wcdt.co.th on 23 Aug 2026 and returned a suspicious verdict with a score of 54 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with wcdt.co.th?
- 13 analysed samples communicate with this URL, including Phishing.
- How was wcdt.co.th checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of wcdt.co.th
Scanned on MalwareAnalyzer by Cyble · Open interactive scan