Gridinsoft 在 baikuder.com 上观察到的情况
Gridinsoft 威胁分析师直接检查了该网站,并记录了支持此决定的证据。
GMA-20260903173912-fa772fd5
- 检查时间
- 由 Gridinsoft 威胁分析师 完成
- 分析师结论
- 安全
- 证据依据
- 第一方网站分析 外部安全厂商情报: 存在矛盾的背景信息——未用于本次决定
当前独立审查支持将观察到的 baikuder.com 公开 deployment 判为安全。当前 51 个公开 pages 和 posts 均提供同一办公用品网站,未出现 phishing form、无关 redirect、executable 或 archive 交付、malware payload 或有害动作。urlscan 公共证据确认,/sima/index2.php 在 2022 年 10 月曾是一个带 Microsoft 品牌的具体密码提示页面,/sima.zip 则被记录为带 phishkit 标签的 archive。这些确切 paths 现在返回 HTTP 404,且不在当前 inventory 中。剩余 SOCRadar 与 OTX 指标是当前 domain-level blacklist 或 bulk-feed 背景,没有仍在线的确切对象。它们与当前 First-Party 结果矛盾,但不足以让 Gridinsoft 对当前受审查 deployment 保留宽泛警告。由于历史事件确实存在,继续加强并监控 WordPress 仍然合适。
分析师结论
本次检查记录了 8 项观察
查看证据
HTTPS root 提供 Baikuder 办公用品网站,HTTP root 与 www variants 均汇聚到同一 HTTPS apex。公开 WordPress API 列出 12 个 pages 和 39 个 product 或 news posts。当前 51 个唯一 public URLs 均在 baikuder.com 返回 HTTP 200,没有无关 final host。
-
HTTP 状态
200 -
最终 URL
https://baikuder.com/ - 页面元素 当前 public inventory 包含同一 host 的 51 个唯一 pages 和 posts;51 个均返回 HTTP 200。
- 页面元素 受审查 catalog 展示 desk organizers、filing and storage products、business supplies、writing supplies 以及各个 CLS product pages。
About、Contact、policy、catalog 与 product pages 一致将 Baikuder 标识为 CLS Industry Inc. 的办公用品品牌。联系方式与独立的 CLS 企业网站一致。当前 public inventory 中唯一的 form 是 same-origin contact form,要求普通的 name、email、subject 与 message 字段;没有 password、one-time code、payment-card field 或 unrelated-brand sign-in。未提交该 form。
- 页面元素 About 与 Contact pages 标识 CLS Industry Inc.、其 Taiwan 地址、[email protected] 与 +886-4-22352206。
- 公开证据 URL https://www.cls.com.tw/CLS_Story.php
- 页面元素 Contact form action 是 baikuder.com 上的 /contact/。
- 分析师观察 当前没有 public form 要求 password、one-time code、payment-card number、wallet secret 或 unrelated account credential。
Apex 与 www 通过 Cloudflare 解析并提供同一网站。当前 certificate 覆盖 baikuder.com 与 *.baikuder.com,有效期为 2026-07-10 至 2026-10-08。DNS 还发布 mail.cls.com.tw 作为 mail exchanger,并有 Google site-verification record。共享 Cloudflare addressing 只是 infrastructure context,其本身既不能证明有害,也不能证明安全。
- DNS 信息 审查期间 baikuder.com 与 www.baikuder.com 解析到 Cloudflare anycast addresses。
- DNS 信息 MX target 是 mail.cls.com.tw,apex 发布 Google site-verification TXT record。
- 证书信息 Let's Encrypt YE1 certificate 对 baikuder.com 与 *.baikuder.com 的有效期为 2026-07-10 至 2026-10-08。
- 分析师观察 共享 Cloudflare network placement 仅作为 infrastructure context,不作为 threat finding 或 clean-site guarantee。
完整的当前 public inventory 共 51 URLs,其 WordPress-rendered content 没有指向 executable、installer、mobile package、script package 或 archive 的链接。受审查 navigation 没有触发 automatic download 或 unrelated redirect,也没有识别出具体的 current malware file、payload URL、payload hash、credential receiver、exploit 或 harmful action。
- 分析师观察 当前 public page 与 post content 中没有 .exe、.msi、.apk、.dmg、.zip、.rar 或 .7z 链接。
- 分析师观察 未复现 automatic download、unrelated final host、current phishing form、malware payload 或 harmful execution。
urlscan 公共记录证明发生过具体历史事件,而不仅是 domain label。2022-10-11,来源为 OpenPhish 的 /sima/index2.php scan 返回 HTTP 200,标题为 'Sign in to your account';保留的 screenshot 显示在非 Microsoft host baikuder.com 上出现带 Microsoft 品牌的 password prompt。另一条 scan 将 /sima.zip 记录为 application/zip,并带有 miteru 与 phishkit 标签。检索到的 public record 没有提供 ZIP bytes 或 file hash,因此不对该 archive 声称具体 malware family 或 execution。
- 公开证据 URL https://urlscan.io/result/00cc286b-e90d-4d7a-b357-cc493892c708/
- 公开证据 URL https://urlscan.io/result/d98a3d83-428e-437e-b928-bd7fa9ae467b/
-
HTTP 状态
200 - MIME 类型 application/zip
- 分析师观察 历史页面在 baikuder.com 上以 Microsoft 品牌明确要求 password;检索到的证据未证明输入数据被发送到哪里。
- 分析师观察 历史 ZIP 已被记录并标记为 phishkit,但本次审查无法获得其 bytes、hash 与 sandbox execution trace。
历史 paths /sima、/sima/、/sima/index2.php、/sima/index2.php/ 与 /sima.zip 当前均以 text/html 返回 Baikuder HTTP 404 page。它们均未出现在当前 public page 或 post inventory 中。2022 至 2026 年后续 urlscan observations 显示,该 credential path 先后出现 403 或 500 responses,最终成为普通 404 pages。
-
HTTP 状态
404 - MIME 类型 text/html; charset=UTF-8
- 分析师观察 受测的 5 个 /sima variants 均返回 HTTP 404,且当前包含 51 URLs 的 public inventory 没有链接它们。
- 公开证据 URL https://urlscan.io/domain/baikuder.com
受申诉的 exact host 同时也是 registrable parent domain,因此 exact-host 与 parent-domain searches 指向同一 apex;www 已单独检查。urlscan 返回 25 条 public records,其中包括 2022 年的具体 phishing URL 与 ZIP,之后是后续 root pages 与 404 responses。OTX 返回 2026 年重复的 bulk-feed phishing pulses,其中 baikuder.com 是 domain indicator,并有 7 条 URL observations;最新 root observation 显示 HTTP 200,且没有 Google Safe Browsing match。当前 OpenPhish feed,以及在 Hybrid Analysis、Triage、ANY.RUN、URLhaus 和对确切历史 URLs 的精确 public searches,均未返回当前 sample-level match。仅凭认证或不可用的 APIs 未被视为 clean evidence。
- 公开证据 URL https://urlscan.io/domain/baikuder.com
- 公开证据 URL https://otx.alienvault.com/indicator/domain/baikuder.com
- 分析师观察 一个精确的历史 phishing page 可独立区别于当前 domain-blacklist 与 bulk-feed indicators。
- 分析师观察 在受审查的 public scanner、sandbox、threat-intelligence 或 feed indexes 中,未找到 current malware sample、payload hash 或仍在线的 harmful exact URL。
Internet Archive availability service 报告 2018-08-06 与 2019-08-15 存在成功 apex snapshots。它没有报告 /sima/index2.php 的 stored snapshot,也没有报告 /sima.zip. Direct replay 与 CDX listing 在审查期间不可用,因此没有用 archived apex content 声称这些页面当时展示了什么。当前网站与 public registration data 分别显示较长的 domain 与 business continuity。
- 公开证据 URL https://web.archive.org/web/20180806074937/http://baikuder.com/
- 公开证据 URL https://web.archive.org/web/20190815203022/http://baikuder.com/
- 分析师观察 Archive availability 找到两条成功 apex captures,但没有找到 /sima 下任何确切历史 object 的 capture。
- 分析师观察 不可用的 archive replay 被记录为 limitation,没有被解释为 clean content。
范围与限制
- 受申诉的 exact host 同时也是 registrable parent domain,因此 exact-host 与 parent-domain OSINT 都指向同一 baikuder.com apex。www variant 已单独检查。
- 审查覆盖 current Gridinsoft report、HTTP 与 www redirects、当前全部 51 个 public WordPress pages 与 posts、navigation、forms、linked downloads、确切 historical /sima paths、DNS、TLS、public URL scanners、threat-intelligence indexes、sandbox-index searches、current phishing feed 以及可用 archive metadata。
- 未提交 form,未创建 account,未输入 credential 或 personal information,也未运行 executable 或 archive。
- 审查未检查 private server files、logs、administrator accounts、mailboxes、unpublished endpoints、WordPress administration 或 2022 年 phishing publication 的内部原因。
- 历史 /sima.zip 记录暴露了其 URL、MIME type 与 phishkit tag,但没有 retrievable bytes、file hash 或 sandbox execution trace。没有将具体 malware family 或 payload behavior 归因于该 archive。
- Internet Archive replay 与 CDX listing 不可用;其 availability API 报告 apex snapshots,但没有找到 /sima 下任何确切 object 的 snapshot。Unavailable 或 authentication-only sources 被记录为 unverified,而不是 clean。
- Public search、URL-scanner、threat-intelligence、sandbox、feed 与 archive indexes 并不完整;未出现在某个 index 中不能证明 unindexed event 从未发生。
- 安全描述记录时间所观察到的 public deployment 与 exact paths。它不保证 future content、private server state、WordPress plugin security、account security,也不保证已修复的 compromise 不会再次发生。
帮助保护他人,快在社交媒体上分享此页面吧!知道baikuder.com的人越多,骗子就越难得逞。 在社交媒体上分享此页面,帮助更多人评估baikuder.com!