Security Scan Report: lab.wangdun.cn

Redirected to:
https://lab.wangdun.cn:60000/#/main
Site favicon
Submitted: Sep 14, 2026, 1:47:59 AMCompleted: Sep 14, 2026, 1:50:38 AMpubliccompleted

This website contacted 1 IP in 1 country across 1 domain to perform 13 HTTP transactions. The main domain is lab.wangdun.cn.

Submitted URL: https://lab.wangdun.cn:60000

Effective URL:

https://lab.wangdun.cn:60000/#/main
Redirected

AI Security Verdict

High Risk

Confidence: 85%

8
Risk Score

ThreatFox reports the scanned IP:port as 'viper' malware with 2 independent feeds; page title matches. Despite no forms or JS malware, the primary-infrastructure malware indicator makes this HIGH_RISK.

Risk Factors (3)
Primary IP:Port 111.170.148.134:60000 flagged as 'viper' malware by ThreatFox (2 independent feeds).
Page title 'VIPER' aligns with the reported threat name.
Service exposed on non-standard port 60000.
Domain age information unavailable

Details

Page Title

VIPERsecondary capture

Scan Type

public

Domain Name Analysis

Domain 'lab.wangdun.cn:60000' uses the Chinese country-code top-level domain (.cn); it also runs on subdomain 'lab'. Count 7 characters in 'wangdun' holding 2 vowels versus five consonants. Word splitting yields 2 words: wang, dun. Median word length comes out to 3.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://lab.wangdun.cn:60000

Page Load Overview

75.33s
Total Load Time
473 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:35 chars
Detector Agreement:100%

Website Classification

Primary Category

unknown0% confidence
Type: dynamic
Method: structural

All Detected Categories

No categories detected

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
13111.170.148.134China
AS151185China Telecom
131--

Detected Technologies5

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1A0F0ABC288F1540E229087251DE5F2288FC9056B5F099C1078E8952E4FA9F8BCDE396C

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

6:h4hqIY7Y03RfAbpliLDe1jLnpAP8U6eLB3Q56MJLrMYsLKT6jJ9nFAiiQduB9d:hRJOyLSLpAPG56MFwZziKG

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:1:0:dc5cdb75b0ea3f6dde5bbe81da769de0

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:0000000000000000
Perceptual Hash:8888888888222222
Difference Hash:1010000000000000
Wavelet Hash:3838000000000000
Color Hash:#1f4e93

Other Hashes

Crop Resistant:1010000000000000

Scan History

Scan history not available

Unable to load historical scan data