www.wosign.com - URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.wosign.com and returned a unknown verdict (score -12). The page resolved to 101.91.111.102 on CHINANET SHANGHAI PROVINCE NETWORK in CN. The domain was registered 7082 days ago through Xiamen 35.com Information Co., Ltd.. 5 domains and 1 IP were contacted, over 9 HTTP requests. 1 malware sample communicates with this URL. The request followed 2 redirects before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: unknown (score -12) · Confidence 15%
- Scanned URL:
http://www.wosign.com/policy/0 - Domain: www.wosign.com · IP: 101.91.111.102 · AS4812 · CN
- Server: Apache
- Page title: WoSign Certification Practice Statement (CPS)-WoSign SSL Certificates!
- HTTP status: 200 · text/html; charset=UTF-8
- Registrar: Xiamen 35.com Information Co., Ltd. · domain age 7082 days · created 2007-03-31
- TLS issuer: C=CN, O=WoTrus CA Limited, CN=WoTrus RSA OV SSL CA 2 · valid to Apr 5 23: · subject C=CN, ST=广东省, O=沃通电子认证服务有限公司, CN=www.wosign.com
- Evidenced operator: 沃通电子认证服务有限公司
- HTTP requests captured: 9
- Scan tier: fast · observed 2026-08-21 04:32:16 UTC
Redirect chain
http://www.wosign.com/policy/0https://www.wosign.com/policy/0https://www.wosign.com/policy/
Malware communicating with this URL (1)
These samples were observed contacting or being served from www.wosign.com. Each links to its full analysis.
- ff1e0f7d9eb5a80d720d1747dbbd10445d372b14b2aa7a0510e0528aaa28068e - referenced ·
ff1e0f7d9eb5a80d720d1747dbbd1044· first seen 2026-08-21
Antivirus & YARA (0 of 47 engines)
No engine flagged this page's content.
Why this verdict
- Valid TLS, no impersonation or off-origin credential post
Detected technologies
- Apache
- jQuery
- Bootstrap
Contacted infrastructure
- 101.91.111.102 - AS4812 CHINANET SHANGHAI PROVINCE NETWORK (China)
Observed indicators
- www.wosign.com
- buy.wosign.com
- www.wosigndoc.com
- partner.wosign.com
- beian.miit.gov.cn
- 101.91.111.102
- https://www.wosign.com/policy/
- https://www.wosign.com/images/favicon.ico
- https://www.wosign.com/CSSEN/style-max-550.css
- https://www.wosign.com/CSSEN/style-max-1024.css
- https://www.wosign.com/CSSEN/style.css
- https://www.wosign.com/js_new/jquery-3.3.1.min.js
- https://www.wosign.com/js_new/bootstrap.min.js
- https://www.wosign.com/js_new/tabScript.js
- https://www.wosign.com/js_new/codehim.dropdown.js
- https://www.wosign.com/js_new/common.js
- https://www.wosign.com/CSS/style_ite_ie9.css
- https://www.wosign.com/English/index.htm
- https://www.wosign.com/images/web_style/wosign_logo_mobile_en.png
- https://www.wosign.com/
Other scans of www.wosign.com (1)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 21 Aug 2026 - unknown
Questions about www.wosign.com
- Is www.wosign.com safe?
- The scan of www.wosign.com on 21 Aug 2026 reached no verdict either way (score -12). Too little was captured to judge it, which is an unknown rather than a pass.
- What malware is associated with www.wosign.com?
- 1 analysed samples communicate with this URL.
- How was www.wosign.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.wosign.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan