christophercheung.com
Checking live DNS resolution...
100/100
CRITICAL RISK
20
Malware URLs
1
Resolved IPs
75
Abuse Reports
20
Active URLs

Threat Intelligence Summary: christophercheung.com

Risk Level: CRITICALThreat Score: 100/100

Assessment: christophercheung.com is actively hosting 20 malware URLs across 1 resolved IP address. The number of active endpoints suggests ongoing, organized malware distribution. This domain should be blocked at the DNS or firewall level. Malware families associated with this domain include mirai, gafgyt, botnetdomain.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 20 — Active: 20 — Resolved IPs: 1 — Abuse Reports: 75

First Seen: 2026-06-16T11:33:07 — Last Online: 2026-07-16T01:32:42

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

christophercheung.com has been associated with 20 malware URLs , of which 20 are currently active . The primary threat types are malware_download, malware.

Active threat. This domain is currently serving malicious content. Multiple malware URLs have been identified on this domain. Network administrators should consider blocking this domain or monitoring traffic to it closely.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2026-06-16T11:33:07
Last Seen Online
2026-07-16T01:32:42
Data Last Updated
2026-07-16T05:00:44.699240
Status Activity Timeline (22 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

OFFLINE ONLINE
http://christophercheung.com/powerpc
Status changed from offline to online
OFFLINE ONLINE
http://christophercheung.com/m68k
Status changed from offline to online
OFFLINE ONLINE
http://christophercheung.com/x86_64
Status changed from offline to online
ONLINE OFFLINE
http://christophercheung.com/powerpc
Status changed from online to offline
ONLINE OFFLINE
http://christophercheung.com/m68k
Status changed from online to offline
ONLINE OFFLINE
http://christophercheung.com/x86_64
Status changed from online to offline
ONLINE
http://christophercheung.com/painbins.sh
First detected as online
ONLINE
http://christophercheung.com/i686
First detected as online
ONLINE
http://christophercheung.com/mips
First detected as online
ONLINE
http://christophercheung.com/i586
First detected as online
ONLINE
http://christophercheung.com/sparc
First detected as online
ONLINE
http://christophercheung.com/m68k
First detected as online
ONLINE
http://christophercheung.com/armv4l
First detected as online
ONLINE
http://christophercheung.com/powerpc-440fp
First detected as online
ONLINE
http://christophercheung.com/armv5l
First detected as online
ONLINE
http://christophercheung.com/i486
First detected as online
ONLINE
http://christophercheung.com/x86_64
First detected as online
ONLINE
http://christophercheung.com/armv7l
First detected as online
ONLINE
http://christophercheung.com/sh4
First detected as online
ONLINE
http://christophercheung.com/powerpc
First detected as online
Showing 20 most recent changes of 22 total
Associated IP Addresses (1)

All IP addresses this domain has resolved to (current and historical). These IPs may host or have hosted malware URLs.

89.33.192.131
75 abuse reports Severity: high
Malware Classification
mirai
Infamous IoT botnet source code released in 2016, spawning thousands of variants. Responsible for record-breaking DDoS attacks exceeding 1 Tbps. Spreads by scanning for devices with default credentials. Target routers, cameras, DVRs globally.
gafgyt
IoT botnet malware also known as BASHLITE or Lizkebab. Targets Linux-based IoT devices through default credentials and known exploits. Used for launching large-scale DDoS attacks. Competes with Mirai for control of vulnerable devices.
botnetdomain
Generic botnet command-and-control infrastructure. Domain used to coordinate infected devices, issue commands, and exfiltrate stolen data. Part of distributed botnet network infrastructure.
Malware URLs (20)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

https://christophercheung.com/
Active Threat
Type: malware
https://christophercheung.com/
Active Threat
Type: malware
https://christophercheung.com/
Active Threat
Type: malware
http://christophercheung.com/painbins.sh
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain gafgyt mirai
http://christophercheung.com/sparc
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/i486
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/armv4l
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain gafgyt mirai
http://christophercheung.com/powerpc-440fp
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/i586
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/mips
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/x86_64
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/m68k
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/armv7l
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/sh4
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/powerpc
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/mipsel
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/armv6l
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/i686
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain mirai
http://christophercheung.com/armv5l
Active Threat
IP: 89.33.192.131
Type: malware_download
First Seen: 2026-06-16
botnetdomain gafgyt mirai
https://christophercheung.com/
Active Threat
Type: malware