Gridinsoft 在 All-z.co 上观察到的情况
Gridinsoft 威胁分析师直接检查了该网站,并记录了支持此决定的证据。
GMA-20260826234846-0304a6d1
- 检查时间
- 由 Gridinsoft 威胁分析师 完成
- 分析师结论
- 企业 URL 跳转服务 — 需要审查精确链接
- 证据依据
- 第一方网站分析 外部安全厂商情报: 仅作背景参考——未用于本次决定
当前独立审查未在 all-z.co 上复现 phishing 或 malware。最新 Gridinsoft scan 未指出有害对象;公开索引发现的六个短链接在普通浏览器中都只跳转到 www.allianz.co 的 PDF 路径。域名 blacklist 类别背后没有发现精确恶意 URL、凭据接收端、无关目的地、executable、payload 或 hash。因此,原有宽泛 Phishing 结果缺乏支持,已改为 Suspicious Website。由于完整短码空间无法枚举,而且已知链接会对 crawler、command-line、review 和部分 mobile profiles 隐藏目的地,不能对整个域名作 Safe 结论。今后的问题需要提供精确短链接并审查其目的地。
分析师结论
本次检查记录了 7 项观察
查看证据
已对 all-z.co 完成最新受支持的 Gridinsoft rescan。根路径返回 HTTP 404,结果没有正向有害行为信号,也未指出精确凭据接收端、无关 redirect、automatic download、malware 文件、payload、exploit、命令或 hash。原有 Phishing 结果依附于宽泛域名 signature,而不是可复现的有害对象。
- 公开证据 URL https://gridinsoft.com/online-virus-scanner/url/all_z-co
-
HTTP 状态
404 - 页面元素 The fresh result contained no positive behavior signal.
- 分析师观察 The fresh result did not name a concrete harmful all-z.co URL, destination, file, payload, receiver, command, exploit, or hash.
apex 解析到两个 AWS Global Accelerator IPv4,并通过 HTTPS 返回空的 HTTP 404;www 不解析。证书仅覆盖 all-z.co,有效期为 2026-02-02 至 2027-03-03。同长度的不存在短码返回 HTTP 404;robots.txt、sitemap.xml 和 favicon.ico 显示受限错误信息,而非公开目录或链接创建界面。
- DNS 信息 all-z.co resolved to 3.33.208.53 and 15.197.217.248; www.all-z.co did not resolve.
-
HTTP 状态
404 - 证书信息 Amazon RSA 2048 M01 certificate for all-z.co, valid 2026-02-02 through 2027-03-03.
- 分析师观察 The nonexistent short code /QQ00000 returned HTTP 404 and an explicit not-found response.
已直接检查公开 URL intelligence 或精确搜索发现的每个具体短码。六个代码在普通 desktop browser profiles 中都只跳转到官方 host www.allianz.co 的六个 PDF 路径。其中一个代码还出现在 Allianz Colombia 保险文件中,作为一般条款链接。没有对象跳转到无关 host、索取 credentials、触发 executable 或 archive download,或提供 malware payload。
-
重定向目标
https://www.allianz.co/content/dam/onemarketing/iberolatam/allianz-co/seguros/personas/salud/contratos/Salud-Gold-Plus-01072024-Version-01-1.pdf -
重定向目标
https://www.allianz.co/content/dam/onemarketing/iberolatam/allianz-co/seguros/empresas/documentos/2023/octubre/Negocio-Empresarial-Pyme-18102023-Version-07.pdf -
重定向目标
https://www.allianz.co/content/dam/onemarketing/iberolatam/allianz-co/seguros/empresas/documentos/Agricola-11102023-V2.pdf -
重定向目标
https://www.allianz.co/content/dam/onemarketing/iberolatam/allianz-co/seguros/personas/hogar/2021/Hogar-Individual-13122023-Version-24.pdf -
重定向目标
https://www.allianz.co/content/dam/onemarketing/iberolatam/allianz-co/seguros/empresas/documentos/Manejo-Global-Comercial-y-Estatal-10042024-V4.pdf -
重定向目标
https://www.allianz.co/content/dam/onemarketing/iberolatam/allianz-co/seguros/empresas/documentos/Multirriesgo-06112024-V8.pdf - 分析师观察 The checked codes were /QQACEhJ, /QQzxgNi, /QQzxgMw, /QQzxfZq, /QQzxgQm, and /QQbg5AN.
服务按 User-Agent 选择性披露目的地。Windows Chrome、Edge、Firefox、macOS Safari 和 iPhone Safari 收到相同 HTTP 302 目的地;Android Chrome、curl、Googlebot、Bingbot、Facebook preview 和 Gridinsoft review 收到 HTTP 200、两字节 body OK,且没有 Location。六个代码都复现了这一差异。虽然普通浏览器目的地是官方 Allianz 文件,这仍妨碍自动化对象审查。
-
HTTP 状态
302 -
重定向目标
https://www.allianz.co/content/dam/onemarketing/iberolatam/allianz-co/seguros/personas/salud/contratos/Salud-Gold-Plus-01072024-Version-01-1.pdf - 分析师观察 Windows and macOS desktop browsers plus iPhone Safari received HTTP 302; Android Chrome, curl, crawler, preview, and reviewer profiles received HTTP 200 with body OK and no Location header.
- 文件 SHA-256 565339bc4d33d72817b583024112eb7f5cdf3e5eef0252d6ec1b9c9a94e12bb3
精确 host 与可注册 parent-domain 是同一 apex。urlscan 没有精确公开 scan;OTX 返回 zero pulses 和七条 URL observations,即根路径加六个已检查代码。Wayback 没有 snapshot。当前完整 ThreatFox export、URLhaus 和 OpenPhish feeds 中没有精确匹配。公开 sandbox 搜索没有 sample。不可用或未索引来源被视为覆盖不完整,而非 clean。
- 公开证据 URL https://otx.alienvault.com/indicator/domain/all-z.co
- 公开证据 URL https://urlscan.io/domain/all-z.co
- 公开证据 URL https://web.archive.org/web/*/all-z.co/*
- 分析师观察 OTX returned zero pulses and seven URL observations; urlscan returned zero exact-host results; Wayback returned no record.
- 分析师观察 The current full ThreatFox export, URLhaus recent feed, and OpenPhish feed contained no exact all-z.co host or URL match.
- 分析师观察 No public result supplied an exact harmful URL, captured response, file, payload, credential receiver, hash, or sandbox behavior trace for all-z.co.
当前外部 snapshot 为 49 harmless、六个 malicious、一个 suspicious、34 undetected。负面项是 BitDefender、CyRadar、G-Data、Lionic、VIPRE、Webroot 和 ESET 的 blacklist 结果;Avira、Norton 和 Bitdefender 另有警告。可访问记录都没有指出导致类别的精确 URL 或 sample。这是信誉分歧,不是已复现的 phishing object。
- 页面元素 External snapshot: 49 harmless, 6 malicious, 1 suspicious, 34 undetected.
- 分析师观察 The adverse entries were blacklist-method domain results and did not name an exact all-z.co URL, response, file, payload, receiver, or hash.
all-z.co 是短链接 redirect namespace,不是普通网站。根路径不公开 directory、sitemap、创建界面或完整活动代码列表。已找到并审查六个公开对象,但无法独立枚举全部当前、已删除、私有和未来短码。有限 clean 样本不能认证每个目的地。
-
HTTP 状态
404 - 分析师观察 No public directory, sitemap, or link-creation interface was exposed by the reviewed root.
- 分析师观察 Six known codes were reviewed, but the complete short-code namespace was not publicly enumerable.
范围与限制
- 精确 host all-z.co 同时就是可注册 parent-domain;www 已单独检查且不解析。
- 审查覆盖最新 Gridinsoft report、根路径、错误路径、六个链接及目的地、多种 browser 和 crawler profiles、DNS、TLS、URL 和 threat intelligence、phishing feeds、sandbox indexes 和 archives。
- 全部当前、已删除、私有和未来短码无法公开枚举;已审查六个已知对象。
- Cloudflare 阻止自动获取最终 PDF bytes;审查了精确官方 www.allianz.co destinations 及独立索引的 Allianz 文件背景。
- 条件式、地域、account、language、referrer 或 time-based destinations 可能在已审查 profiles 和 locations 之外不同。
- 公开索引并不完整;没有匹配不能证明历史上从未存在未索引对象。
- URLhaus 和 ThreatFox 直接 APIs 要求 authorization;其公开 export 和 feed files 已另行检查。
- 外部 labels 仍是独立背景,不等同于可复现的恶意 URL 或 sample。
- 该结论不认证每个当前或未来链接为 safe,也不保证目的地不会变化。
帮助保护他人,快在社交媒体上分享此页面吧!知道all-z.co的人越多,骗子就越难得逞。 在社交媒体上分享此页面,帮助更多人评估all-z.co!