Gridinsoft 在 Api.intellect.studio 上观察到的情况
Gridinsoft 威胁分析师直接检查了该网站,并记录了支持此决定的证据。
GMA-20260901182111-94e693f1
- 检查时间
- 由 Gridinsoft 威胁分析师 完成
- 分析师结论
- 安全
- 证据依据
- 第一方网站分析 外部安全厂商情报: 存在矛盾的背景信息——未用于本次决定
当前独立第一方审查支持 api.intellect.studio 为安全。该精确主机表现为受限应用 API:根路径始终返回 403,HTTP 仅升级到同一 HTTPS 主机,/health 返回预期 JSON。抽样公开路径未显示冒充、凭据收集、无关重定向、自动下载、可执行文件、压缩包、恶意软件 URL、文件、载荷或哈希。先前 Suspicious Website 结果源于宽泛的父域签名,没有当前 Gridinsoft 自有的有害行为信号。CRDF、Seclookup、Avira 和 Norton 外部类别仍作为相互矛盾的背景,而非对象级证据,且未决定本次结论。
分析师结论
本次检查记录了 5 项观察
查看证据
桌面、移动和爬虫对 API 根路径的请求始终返回 HTTP 403,且未重定向到其他位置。HTTP 仅升级一次到同一 HTTPS 主机。公开健康 endpoint 返回 HTTP 200 和 JSON result true,符合受限应用 API 而非常规公开主页的行为。
-
HTTP 状态
403 -
最终 URL
https://api.intellect.studio/ -
HTTP 状态
200 - 公开证据 URL https://api.intellect.studio/health
- 分析师观察 The /health response was application/json with the body {"result":true}.
被审查的标准公开状态、文档和安全文本路径要么返回同站正常 HTTP 404,要么返回预期健康 JSON。没有路径跳转到站外、展示冒充登录、请求凭据或付款,也没有自动下载可执行文件或压缩包。
- 分析师观察 /health returned 200 JSON; /healthz, /status, /.well-known/security.txt, /openapi.json, /swagger, and /docs returned same-site 404 responses.
- 分析师观察 No reviewed public path exposed a password form, file-upload form, payment request, unrelated redirect, automatic download, executable, or archive.
精确主机通过与父域相同的 Cloudflare 部署解析,并提供匹配的 wildcard 证书。这些事实符合其所述的公司控制 API,但未被单独视为安全证明。
- DNS 信息 A records: 104.21.90.30 and 172.67.193.197
- 证书信息 Certificate SANs: intellect.studio and *.intellect.studio; valid 2026-07-29 through 2026-10-27
- 分析师观察 The exact API host and the parent used the same Cloudflare addresses and certificate scope during the review.
最新受支持的 Gridinsoft 复扫到达精确 HTTPS 主机,并因 2026 年 7 月 6 日的宽泛 intellect.studio 签名而保留 Suspicious Website。当前第一方报告没有有害行为正向信号,也未指出具体恶意路径、响应、重定向目的地、文件、载荷或哈希。聚合快照包含 53 项无害、两项恶意黑名单类别和 35 项未检测结果。
-
HTTP 状态
403 -
最终 URL
https://api.intellect.studio/ - 分析师观察 The retained signature named intellect.studio and was dated 2026-07-06; no current positive harmful-behavior signal accompanied it.
- 分析师观察 Fresh aggregate snapshot: 53 harmless, 2 malicious, 0 suspicious, and 35 undetected.
- 分析师观察 The two adverse aggregate entries were CRDF and Seclookup hostname blacklist labels.
精确主机的公开 OSINT 返回零条 URLScan 记录、零个 OTX 威胁脉冲和 URL 观察、零条成功 Wayback 记录。精确公开网页搜索和 OpenPhish 未发现有害 API URL 或样本。证书历史印证了父域控制的 wildcard 部署。URLhaus 和 ThreatFox 需要授权,Common Crawl 不可用;这些缺口按未知处理。
- 公开证据 URL https://urlscan.io/domain/api.intellect.studio
- 公开证据 URL https://otx.alienvault.com/indicator/hostname/api.intellect.studio
- 公开证据 URL https://web.archive.org/web/*/api.intellect.studio/*
- 分析师观察 URLScan, OTX, and Wayback returned no exact-host record exposing a malicious object.
- 分析师观察 No accessible exact-host search supplied a malicious URL, response, file, payload, hash, credential receiver, or execution trace.
范围与限制
- 审查范围包括记录时刻的精确 API 主机、根响应、公开健康 endpoint、标准公开状态与文档路径、重定向、DNS、TLS 和可访问公开 OSINT。
- 未测试经过身份验证的应用请求、私有 API 方法、客户账户、移动应用会话、服务器代码、日志、数据库、管理员访问或未公开路由。
- 受限根路径和缺少公开 API 文档限制了功能覆盖。安全描述的是被审查公开行为,并不认证私有数据处理或每个经身份验证的 endpoint。
- URLhaus 和 ThreatFox 需要授权,Common Crawl 不可用。缺失覆盖按未知记录,而非干净结果。
- 外部提供商管理各自的主机或域名评级,在 Gridinsoft 作出决定后仍可能显示不利结果。
帮助保护他人,快在社交媒体上分享此页面吧!知道api.intellect.studio的人越多,骗子就越难得逞。 在社交媒体上分享此页面,帮助更多人评估api.intellect.studio!