www.gz-chengeng.com - suspicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.gz-chengeng.com and returned a suspicious verdict (score 48), categorised as suspicious-infrastructure. The page resolved to 18.65.244.116 on Amazon.com, Inc. in AU. 10 domains and 3 IPs were contacted, over 6 HTTP requests. The request followed 2 redirects before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 48) · Confidence 60%
- Scanned URL:
http://gz-chengeng.com/uploadfile/files/kobixerasopo.pdf - Domain: www.gz-chengeng.com · IP: 18.65.244.116 · AS16509 · AU
- Page title: 广州辰庚医药科技发展有限公司-医疗设备-自动痔疮套扎吻合器
- HTTP status: 200 · text/html; charset=UTF-8
- TLS issuer: C=CN, O=Xin Net Technology Corp., CN=XinNet RSA DV · valid to Dec 3 23: · subject CN=www.gz-chengeng.com
- HTTP requests captured: 6
- Scan tier: standard · observed 2026-08-20 20:05:04 UTC
Redirect chain
http://gz-chengeng.com/uploadfile/files/kobixerasopo.pdfhttp://www.gz-chengeng.com/https://www.gz-chengeng.com/
Antivirus & YARA (1 of 47 engines)
- YARA: ESET research [yara]: IIS_Group10 (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Categories
- suspicious-infrastructure
Why this verdict
- Antivirus/YARA detection in page content: IIS_Group10
- Algorithmically-generated (DGA-like) hostname
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Detected technologies
- Amazon CloudFront
- jQuery
- Bootstrap
Contacted infrastructure
- 18.65.244.116 - AS16509 Amazon.com, Inc. (Australia)
- 16.163.201.39 - AS16509 Amazon Data Services Hong Kong (Hong Kong)
- 18.65.244.102 - AS16509 Amazon.com, Inc. (Australia)
Observed indicators
- www.gz-chengeng.com
- omo-oss-image.thefastimg.com
- dcloud-static01.faststatics.com
- www.nmpa.gov.cn
- mpa.gd.gov.cn
- www.miit.gov.cn
- www.mofcom.gov.cn
- beian.miit.gov.cn
- www.300.cn
- guangzhuo.300.cn
- 18.65.244.116
- 16.163.201.39
- 18.65.244.102
- https://www.gz-chengeng.com/
- https://omo-oss-image.thefastimg.com/
- https://dcloud-static01.faststatics.com/
- https://www.gz-chengeng.com/favicon.ico
- https://www.gz-chengeng.com/npublic/libs/css/ceccbootstrap.min.css,global.css?instance=new2023081615265933767&viewType=p&v=1702454679000&siteType=oper
- https://www.gz-chengeng.com/css/site.css?instance=new2023081615265933767&viewType=p&v=1702454679000&siteType=oper
- https://www.gz-chengeng.com/css/home_e4613fc4f400c32d97236ea19e3de15f.min.css?instance=new2023081615265933767&viewType=p&v=1702454679000&siteType=oper
Other scans of www.gz-chengeng.com (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - malicious
- 22 Aug 2026 - suspicious
- 20 Aug 2026 - malicious
Questions about www.gz-chengeng.com
- Is www.gz-chengeng.com safe?
- No. MalwareAnalyzer scanned www.gz-chengeng.com on 20 Aug 2026 and returned a suspicious verdict with a score of 48 out of 100, categorised as suspicious-infrastructure. Treat it as hostile until it is re-checked.
- How was www.gz-chengeng.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.gz-chengeng.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan