www.gz-chengeng.com - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.gz-chengeng.com and returned a malicious verdict (score 60), categorised as suspicious-infrastructure. The page resolved to 18.65.244.102 on Amazon.com, Inc. in AU. The domain was registered 5894 days ago through Bizcn.com, Inc.. 10 domains and 3 IPs were contacted, over 6 HTTP requests. The request followed 2 redirects before landing. This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 60) · Confidence 69%
- Scanned URL:
http://gz-chengeng.com/uploadfile/files/kobixerasopo.pdf - Domain: www.gz-chengeng.com · IP: 18.65.244.102 · AS16509 · AU
- Page title: 广州辰庚医药科技发展有限公司-医疗设备-自动痔疮套扎吻合器
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Bizcn.com, Inc. · domain age 5894 days · created 2010-07-01
- HTTP requests captured: 6
- Scan tier: fast · observed 2026-08-20 20:06:03 UTC
Redirect chain
http://gz-chengeng.com/uploadfile/files/kobixerasopo.pdfhttp://www.gz-chengeng.com/https://www.gz-chengeng.com/
Antivirus & YARA (1 of 47 engines)
- YARA: ESET research [yara]: IIS_Group10 (page content)
Categories
- suspicious-infrastructure
Why this verdict
- Antivirus/YARA detection in page content: IIS_Group10
- Algorithmically-generated (DGA-like) hostname
- Cross-host redirect chain
Detected technologies
- Amazon CloudFront
- jQuery
- Bootstrap
Contacted infrastructure
- 18.65.244.102 - AS16509 Amazon.com, Inc. (Australia)
- 16.163.201.39 - AS16509 Amazon Data Services Hong Kong (Hong Kong)
- 18.65.244.116 - AS16509 Amazon.com, Inc. (Australia)
Observed indicators
- www.gz-chengeng.com
- omo-oss-image.thefastimg.com
- dcloud-static01.faststatics.com
- www.nmpa.gov.cn
- mpa.gd.gov.cn
- www.miit.gov.cn
- www.mofcom.gov.cn
- beian.miit.gov.cn
- www.300.cn
- guangzhuo.300.cn
- 18.65.244.102
- 16.163.201.39
- 18.65.244.116
- https://www.gz-chengeng.com/
- https://omo-oss-image.thefastimg.com/
- https://dcloud-static01.faststatics.com/
- https://www.gz-chengeng.com/favicon.ico
- https://www.gz-chengeng.com/npublic/libs/css/ceccbootstrap.min.css,global.css?instance=new2023081615265933767&viewType=p&v=1702454679000&siteType=oper
- https://www.gz-chengeng.com/css/site.css?instance=new2023081615265933767&viewType=p&v=1702454679000&siteType=oper
- https://www.gz-chengeng.com/css/home_e4613fc4f400c32d97236ea19e3de15f.min.css?instance=new2023081615265933767&viewType=p&v=1702454679000&siteType=oper
Other scans of www.gz-chengeng.com (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 22 Aug 2026 - malicious
- 22 Aug 2026 - suspicious
- 20 Aug 2026 - suspicious
Questions about www.gz-chengeng.com
- Is www.gz-chengeng.com safe?
- No. MalwareAnalyzer scanned www.gz-chengeng.com on 20 Aug 2026 and returned a malicious verdict with a score of 60 out of 100, categorised as suspicious-infrastructure. Treat it as hostile until it is re-checked.
- How was www.gz-chengeng.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.gz-chengeng.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan