www.tencent.com - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.tencent.com and returned a suspicious verdict (score 28). The page resolved to 43.168.224.84 on ACEVILLE PTE.LTD. in SG. The domain was registered 10203 days ago through MarkMonitor Information Technology (Shanghai) Co., Ltd.. 9 domains and 1 IP were contacted, over 6 HTTP requests. 1 malware sample communicates with this URL (HUILoader). This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://www.tencent.com/ - Domain: www.tencent.com · IP: 43.168.224.84 · SG
- Server: nginx
- Page title: Home - Tencent
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: MarkMonitor Information Technology (Shanghai) Co., Ltd. · domain age 10203 days · created 1998-09-14
- TLS issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign Atlas R3 OV TLS CA 2026 Q2 · valid to Dec 25 06: · subject C=CN, ST=Guangdong, L=Shenzhen, O=Shenzhen Tencent Computer Systems Company Limited, CN=www.tencent.com
- Evidenced operator: Shenzhen Tencent Computer Systems Company Limited
- HTTP requests captured: 6
- Scan tier: fast · observed 2026-08-22 02:46:42 UTC
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.tencent.com. Each links to its full analysis.
- HUILoader - referenced ·
6d37f504aa2c470dce0cc40eaee12a6f· first seen 2026-08-22
Antivirus & YARA (1 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Nginx
- WordPress
- jQuery
Contacted infrastructure
- 43.168.224.84 ACEVILLE PTE.LTD. (Singapore)
Observed indicators
- www.tencent.com
- careers.tencent.com
- www.linkedin.com
- twitter.com
- ipr.tencent.com
- www.qq.com
- beian.miit.gov.cn
- www.beian.gov.cn
- h5.news.qq.com
- 43.168.224.84
- https://www.tencent.com/
- https://www.tencent.com/wp-content/plugins/visual-link-preview/dist/public.css?ver=2.4.2
- https://www.tencent.com/wp-content/themes/tencent-web/style.css?ver=3.2.5-20260330
- https://www.tencent.com/wp-content/themes/tencent-web/assets/dist/main.css?ver=3.2.5-20260330
- https://www.tencent.com/wp-content/plugins/ubermenu/pro/assets/css/ubermenu.min.css?ver=3.8.4
- https://www.tencent.com/wp-content/plugins/ubermenu/assets/css/skins/minimal.css?ver=7.0.4
- https://www.tencent.com/wp-content/plugins/sitepress-multilingual-cms/res/js/cookies/language-cookie.js?ver=495000
- https://www.tencent.com/wp-content/plugins/sitepress-multilingual-cms/dist/js/browser-redirect/app.js?ver=495000
- https://www.tencent.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
- https://www.tencent.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
Other scans of www.tencent.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - suspicious ·
https://www.qq.com/ - 23 Aug 2026 - unknown ·
https://qzone.qq.com/ - 23 Aug 2026 - unknown ·
https://qzs.qq.com/ - 23 Aug 2026 - suspicious ·
https://www.qq.com/ - 23 Aug 2026 - suspicious ·
https://www.qq.com/ - 22 Aug 2026 - suspicious ·
https://www.qq.com/ - 21 Aug 2026 - suspicious ·
https://www.qq.com/ - 19 Aug 2026 - suspicious ·
https://www.qq.com/ - 17 Aug 2026 - suspicious ·
https://www.qq.com/ - 17 Aug 2026 - unknown ·
https://accounts.qq.com/
Questions about www.tencent.com
- Is www.tencent.com safe?
- No. MalwareAnalyzer scanned www.tencent.com on 22 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.tencent.com?
- 1 analysed samples communicate with this URL, including HUILoader.
- How was www.tencent.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.tencent.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan