www.ip138.com - malicious URL scan, 20 Aug 2026
MalwareAnalyzer by Cyble scanned www.ip138.com and returned a malicious verdict (score 60), categorised as credential-harvest. The page resolved to 138.113.102.14 on Meteverse Limited. in US. The domain was registered 8158 days ago through eName Technology Co., Ltd.. 43 domains and 1 IP were contacted, over 2 HTTP requests. 2 malware samples communicate with this URL (Delf). This is a point-in-time observation from 20 Aug 2026; the page may have changed since.
Scan result
- Verdict: malicious (score 60) · Confidence 69%
- Scanned URL:
https://www.ip138.com/ - Domain: www.ip138.com · IP: 138.113.102.14 · AS54994 · US
- Server: Microsoft-IIS/6.0
- Page title: iP地址查询--手机号码查询归属地 | 邮政编码查询 | iP地址归属地查询 | 身份证号码验证在线查询网
- HTTP status: 200 · text/html
- Registrar: eName Technology Co., Ltd. · domain age 8158 days · created 2004-04-19
- TLS issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign GCC R6 AlphaSSL CA 2025 · valid to Nov 9 10: · subject CN=*.ip138.com
- HTTP requests captured: 2
- Scan tier: fast · observed 2026-08-20 19:57:20 UTC
Malware communicating with this URL (2)
These samples were observed contacting or being served from www.ip138.com. Each links to its full analysis.
- Delf - contacted ·
6c6f2411d6fb9477847fbd3518950334· first seen 2026-08-20 - Delf - contacted ·
e31303162c644d3b1dd4fb18d2384b6c· first seen 2026-08-20
Antivirus & YARA (1 of 47 engines)
- YARA: ESET research [yara]: IIS_Group10 (page content)
Categories
- credential-harvest
Why this verdict
- Antivirus/YARA detection in page content: IIS_Group10
- Credential-harvesting form
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Microsoft IIS
- ASP.NET
Contacted infrastructure
- 138.113.102.14 - AS54994 Meteverse Limited. (United States)
Observed indicators
- www.ip138.com
- m.ip138.com
- cache.ip138.com
- qq.ip138.com
- www.liantu.com
- caipiao.ip138.com
- bifen.ip138.com
- www.yitaifang.com
- 10.ip138.com
- 2026.ip138.com
- idc.ip138.com
- tool.ip138.com
- dnsdaquan.com
- ipjisuanqi.com
- user.ip138.com
- jx.ip138.com
- icplishi.com
- chaziyu.com
- chapangzhan.com
- chayoulian.com
Other scans of www.ip138.com (3)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 20 Aug 2026 - malicious
- 20 Aug 2026 - malicious
- 20 Aug 2026 - malicious
Questions about www.ip138.com
- Is www.ip138.com safe?
- No. MalwareAnalyzer scanned www.ip138.com on 20 Aug 2026 and returned a malicious verdict with a score of 60 out of 100, categorised as credential-harvest. Treat it as hostile until it is re-checked.
- What malware is associated with www.ip138.com?
- 2 analysed samples communicate with this URL, including Delf.
- How was www.ip138.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.ip138.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan