www.velapower.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.velapower.com and returned a suspicious verdict (score 40). The page resolved to 38.60.148.100 on Kaopu Cloud HK Limited in SG. The domain was registered 2781 days ago through Chengdu West Dimension Digital Technology Co., Ltd.. 5 domains and 2 IPs were contacted, over 3 HTTP requests. 1 malware sample communicates with this URL (Phishing). The request followed 3 redirects before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 40) · Confidence 43%
- Scanned URL:
http://velapower.com/glwh/UploadFile/file/2021090414163873499.pdf - Domain: www.velapower.com · IP: 38.60.148.100 · AS138915 · SG
- Server: Byte-nginx
- HTTP status: 404 · text/html; charset=utf-8
- Registrar: Chengdu West Dimension Digital Technology Co., Ltd. · domain age 2781 days · created 2019-01-09
- HTTP requests captured: 3
- Scan tier: fast · observed 2026-08-21 13:11:47 UTC
Redirect chain
http://velapower.com/glwh/UploadFile/file/2021090414163873499.pdfhttps://velapower.com/glwh/UploadFile/file/2021090414163873499.pdfhttps://velapower.com/glwh/uploadfile/file/2021090414163873499.pdfhttps://www.velapower.com/glwh/uploadfile/file/2021090414163873499.pdf
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.velapower.com. Each links to its full analysis.
- Phishing - referenced ·
52080e2b56d84697e1643c91dd06f128· first seen 2026-08-21
Antivirus & YARA (1 of 47 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: DLV_HTML_Smuggling
Detected technologies
- Nginx
- Google Analytics
Contacted infrastructure
- 38.60.148.100 - AS138915 Kaopu Cloud HK Limited (Singapore)
- 156.227.14.33 - AS63139 Bedge Co Limited (Singapore)
Observed indicators
- www.velapower.com
- img.yfisher.com
- www.googletagmanager.com
- www.google-analytics.com
- api-qqt.weyescloud.com
- 38.60.148.100
- 156.227.14.33
- https://www.velapower.com/glwh/uploadfile/file/2021090414163873499.pdf
- https://www.velapower.com/v1.5.11/font/icon/icon.woff2
- https://img.yfisher.com/m6110/1730176223h3bu/png100-t3-scale100.webp
- https://www.velapower.com/glwh/uploadfile/file/2021090414163873499.pdf.html
- https://www.googletagmanager.com/
- https://img.yfisher.com/
- https://www.google-analytics.com/
- https://api-qqt.weyescloud.com/
- https://www.velapower.com/v1.5.11/dist/css/entire.css
- https://www.velapower.com/assets/plugins/swiper.simple.css
- https://www.velapower.com/assets/plugins/iconfont.css
- https://www.velapower.com/assets/css/interactive.css
- https://www.googletagmanager.com/gtm.js?id=
Other scans of www.velapower.com (4)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - suspicious
- 13 Aug 2026 - suspicious ·
https://www.velapower.com/glwh/uploadfile/file/2021091823471573499.pdf - 13 Aug 2026 - unknown ·
https://www.velapower.com/glwh/uploadfile/file/2021091823471573499.pdf - 13 Aug 2026 - suspicious ·
https://www.velapower.com/glwh/uploadfile/file/2021091823471573499.pdf
Questions about www.velapower.com
- Is www.velapower.com safe?
- No. MalwareAnalyzer scanned www.velapower.com on 21 Aug 2026 and returned a suspicious verdict with a score of 40 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.velapower.com?
- 1 analysed samples communicate with this URL, including Phishing.
- How was www.velapower.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.velapower.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan