wemqmewkqewq.work.gd
ADS / TRACKER Informational label, not part of the risk score
Checking live DNS resolution...
100/100
CRITICAL RISK
32
Malware URLs
1
Resolved IPs
732
Abuse Reports
31
Active URLs

Threat Intelligence Summary: wemqmewkqewq.work.gd

Risk Level: CRITICAL — Threat Score: 100/100

Assessment: wemqmewkqewq.work.gd is actively hosting 31 malware URLs across 1 resolved IP address. The number of active endpoints suggests ongoing, organized malware distribution. This domain should be blocked at the DNS or firewall level. Malware families associated with this domain include botnetdomain, elf, ua-wget.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 32 — Active: 31 — Resolved IPs: 1 — Abuse Reports: 732

First Seen: 2026-09-27T06:34:10 — Last Online: 2026-10-04T00:33:36

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

wemqmewkqewq.work.gd has been associated with 32 malware URLs , of which 31 are currently active . The primary threat types are malware_download.

Active threat. This domain is currently serving malicious content. Multiple malware URLs have been identified on this domain. Network administrators should consider blocking this domain or monitoring traffic to it closely.

Associated malware families include: botnetdomain, elf, mirai.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2026-09-27T06:34:10
Last Seen Online
2026-10-04T00:33:36
Data Last Updated
2026-10-04T05:00:25.680017
Status Activity Timeline (32 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

ONLINE
http://wemqmewkqewq.work.gd/b_lt
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_t8
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_nl
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_sr
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/b_kt
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_dbg
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_ns
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_new
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_v2
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_fin
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_clean
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_nsr
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/b_wt
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86_64_nowd
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/b_persist
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/x86
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/powerpc-440fp
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/m68k
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/i586
First detected as online
ONLINE
http://wemqmewkqewq.work.gd/arc
First detected as online
Showing 20 most recent changes of 32 total
Associated IP Addresses (1)

All IP addresses this domain has resolved to (current and historical). These IPs may host or have hosted malware URLs.

217.60.195.187
732 abuse reports Severity: medium
Malware Classification
botnetdomain
Generic botnet command-and-control infrastructure. Domain used to coordinate infected devices, issue commands, and exfiltrate stolen data. Part of distributed botnet network infrastructure.
elf
Malware family "elf" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
ua-wget
Automated malware download campaign using wget user-agent strings. Indicates command-line driven infection attempts, typically part of shell script malware loaders targeting servers and IoT devices.
sh
Malicious shell script campaign. Bash/sh scripts used for initial access, downloading additional malware, establishing persistence, or cryptocurrency mining. Common in Linux server compromises.
wemqmewkqewq-work-gd
Malware family "wemqmewkqewq-work-gd" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
mirai
Infamous IoT botnet source code released in 2016, spawning thousands of variants. Responsible for record-breaking DDoS attacks exceeding 1 Tbps. Spreads by scanning for devices with default credentials. Target routers, cameras, DVRs globally.
Malware URLs (32)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

http://wemqmewkqewq.work.gd/x86_64_sr
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/b_kt
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_dbg
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_ns
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_new
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_v2
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_fin
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_clean
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_nsr
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/b_wt
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_nowd
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/b_persist
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/b_lt
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_t8
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/x86_64_nl
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-10-03
botnetdomain elf mirai
http://wemqmewkqewq.work.gd/armv4l
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-09-27
botnetdomain elf mirai ua-wget wemqmewkqewq-work-gd
http://wemqmewkqewq.work.gd/powerpc-440fp
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-09-27
botnetdomain elf mirai ua-wget wemqmewkqewq-work-gd
http://wemqmewkqewq.work.gd/m68k
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-09-27
botnetdomain elf mirai ua-wget wemqmewkqewq-work-gd
http://wemqmewkqewq.work.gd/i586
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-09-27
botnetdomain elf mirai ua-wget wemqmewkqewq-work-gd
http://wemqmewkqewq.work.gd/arc
Active Threat
IP: 217.60.195.187
Type: malware_download
First Seen: 2026-09-27
botnetdomain elf mirai ua-wget wemqmewkqewq-work-gd
Showing 20 of 32 URLs