wpa.qq.com - suspicious URL scan, 23 Aug 2026
MalwareAnalyzer by Cyble scanned wpa.qq.com and returned a suspicious verdict (score 28). The page resolved to 43.129.2.11 on Asia Pacific Network Information Center, Pty. Ltd. in HK. The domain was registered 11434 days ago through MarkMonitor Information Technology (Shanghai) Co., Ltd.. 3 domains and 2 IPs were contacted, over 1 HTTP request. 8 malware samples communicate with this URL (AntiVM, Ramnit). The request followed 1 redirect before landing. This is a point-in-time observation from 23 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
http://wpa.qq.com/msgrd?V=1& - Domain: wpa.qq.com · IP: 43.129.2.11 · AS132203 · HK
- Server: tws
- Page title: 服务异常
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: MarkMonitor Information Technology (Shanghai) Co., Ltd. · domain age 11434 days · created 1995-05-04
- TLS issuer: C=US, O=DigiCert, Inc., CN=DigiCert Secure Site OV G2 TLS CN RSA4096 SHA256 2022 CA1 · valid to Jan 29 23: · subject C=CN, ST=Guangdong Province, L=Shenzhen, O=Tencent Technology (Shenzhen) Company Limited, CN=wpa.qq.com
- Evidenced operator: Tencent Technology (Shenzhen) Company Limited
- HTTP requests captured: 1
- Scan tier: fast · observed 2026-08-23 18:32:22 UTC
Redirect chain
http://wpa.qq.com/msgrd?V=1&https://wpa.qq.com/msgrd?V=1&
Malware communicating with this URL (8)
These samples were observed contacting or being served from wpa.qq.com. Each links to its full analysis.
- 3e940b6a9517f68141ae3944dd7c3f1cd1ba1e642730ec7f0ca6b0888a6ebffe - referenced ·
3e940b6a9517f68141ae3944dd7c3f1c· first seen 2026-08-23 - 381592ba0fd2c605628118c02e0a6225f6552390b8f8f985c60eeacbe4b89b89 - referenced ·
381592ba0fd2c605628118c02e0a6225· first seen 2026-08-23 - AntiVM - referenced ·
257d968d7d78362779f32e3223545e96· first seen 2026-08-18 - 2551fe1bbdcb47e25739e51eae73a0635de36e106022b465cdf02e937f0e5129 - referenced ·
2551fe1bbdcb47e25739e51eae73a063· first seen 2026-08-17 - 2bfc6be17729a750757653c37ad7d18ebfaf68c39e30066bb0f86b0a894891bc - referenced ·
2bfc6be17729a750757653c37ad7d18e· first seen 2026-08-15 - f55c3048fbc1bb5cad750ebf0e886507413e13083cb308b0397866b9f17d5ade - referenced ·
f55c3048fbc1bb5cad750ebf0e886507· first seen 2026-08-15 - 3addb573b14949015db80afcc67b3286a370a6352c2fcdb37cd9e869fa3ebd83 - referenced ·
3addb573b14949015db80afcc67b3286· first seen 2026-08-13 - Ramnit - referenced ·
6265b3472c3deb2fc22f455d4fe83ba4· first seen 2026-08-11
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 43.129.2.11 - AS132203 Asia Pacific Network Information Center, Pty. Ltd. (Hong Kong)
- 43.159.234.172 - AS132203 Asia Pacific Network Information Center, Pty. Ltd. (Hong Kong)
Observed indicators
- wpa.qq.com
- bqq.gtimg.com
- tam.cdn-go.cn
- 43.129.2.11
- 43.159.234.172
- https://wpa.qq.com/msgrd?V=1&
- https://bqq.gtimg.com/CDN/source/images/wpa/wpa-error.png
- https://tam.cdn-go.cn/aegis-sdk/latest/aegis.min.js
Other scans of wpa.qq.com (6)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - unknown ·
https://www.4tuku.com/ - 16 Aug 2026 - suspicious ·
https://www.njchemland.com/upload/files/begabemifajotexumepe.pdf - 15 Aug 2026 - unknown ·
http://longruiglass.com/ - 14 Aug 2026 - unknown ·
http://glotecgh.com/ - 14 Aug 2026 - unknown ·
http://glotecgh.com/ - 14 Aug 2026 - unknown ·
http://glotecgh.com/
Questions about wpa.qq.com
- Is wpa.qq.com safe?
- No. MalwareAnalyzer scanned wpa.qq.com on 23 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with wpa.qq.com?
- 8 analysed samples communicate with this URL, including AntiVM, Ramnit.
- How was wpa.qq.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of wpa.qq.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan