www.yankey.com - suspicious URL scan, 22 Aug 2026
MalwareAnalyzer by Cyble scanned www.yankey.com and returned a suspicious verdict (score 49). The page resolved to 43.254.17.11 on Yuan-Jhen Info., Co., Ltd in TW. 9 domains and 2 IPs were contacted, over 21 HTTP requests. The request followed 3 redirects before landing. This is a point-in-time observation from 22 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 49) · Confidence 58%
- Scanned URL:
http://www.yankey.com.tw/demo/public/editor/ckfinder/upload/user_upload/files/66804149111.pdf - Domain: www.yankey.com · IP: 43.254.17.11 · AS131149 · TW
- Server: Apache
- Page title: 404 找不到網頁了! - 洋基工程股份有限公司|高科技廠房機電/無塵室統包工程
- HTTP status: 404 · text/html; charset=utf-8
- TLS issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA EV R36 · valid to Sep 23 23: · subject serialNumber=30921756, jurisdictionC=TW, businessCategory=Private Organization, C=TW, ST=New Taipei, O=YANKEY ENGINEERING CO., LTD., CN=yankey.com
- Evidenced operator: YANKEY ENGINEERING CO., LTD.
- HTTP requests captured: 21
- Scan tier: standard · observed 2026-08-22 07:01:03 UTC
Redirect chain
http://www.yankey.com.tw/demo/public/editor/ckfinder/upload/user_upload/files/66804149111.pdfhttps://www.yankey.com.tw/demo/public/editor/ckfinder/upload/user_upload/files/66804149111.pdfhttps://www.yankey.com/chinese/demo/public/editor/ckfinder/upload/user_upload/files/66804149111.pdfhttps://www.yankey.com/403.shtml/
Antivirus & YARA (2 of 48 engines)
- YARA: delivr.to detections [yara]: DLV_HTML_Smuggling (page content)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- 2 antivirus/YARA engines flagged the page content: DLV_HTML_Smuggling, SOPHOS_Gootloader_JS
- Valid TLS, no impersonation or off-origin credential post
- Cross-host redirect chain
Detected technologies
- Apache
- Google Analytics
- jQuery
Contacted infrastructure
- 43.254.17.11 - AS131149 Yuan-Jhen Info., Co., Ltd (Taiwan)
- 108.160.157.3 - AS63410 PrivateSystems Networks WA (United States)
Observed indicators
- www.yankey.com
- www.googletagmanager.com
- maps.google.com.tw
- www.facebook.com
- youtube.com
- www.ibest.com.tw
- www.ibest.tw
- cse.google.com
- connect.facebook.net
- 43.254.17.11
- 108.160.157.3
- https://www.yankey.com/403.shtml/
- https://www.yankey.com/chinese/css/master.css?v=260529
- https://www.yankey.com/chinese/images/touch-icon/apple-icon-60x60.png
- https://www.yankey.com/chinese/images/touch-icon/apple-icon-76x76.png
- https://www.yankey.com/chinese/images/touch-icon/apple-icon-120x120.png
- https://www.yankey.com/chinese/images/touch-icon/apple-icon-152x152.png
- https://www.yankey.com/public/js/jquery-3.6.0.min.js
- https://www.yankey.com/public/js/jquery-ui-1.13.2/jquery-ui.min.js
- https://www.yankey.com/public/js/jquery.blockUI.min.js
Questions about www.yankey.com
- Is www.yankey.com safe?
- No. MalwareAnalyzer scanned www.yankey.com on 22 Aug 2026 and returned a suspicious verdict with a score of 49 out of 100. Treat it as hostile until it is re-checked.
- How was www.yankey.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the standard tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the standard tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.yankey.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan