Gridinsoft 在 Chosei-kai.com 上观察到的情况
Gridinsoft 威胁分析师直接检查了该网站,并记录了支持此决定的证据。
GMA-20260903174836-87eabac2
- 检查时间
- 由 Gridinsoft 威胁分析师 完成
- 分析师结论
- 安全
- 证据依据
- 第一方网站分析 外部安全厂商情报: 存在矛盾的背景信息——未用于本次决定
当前独立审查确认,chosei-kai.com 在 2026 年 5 月初的两个确切隐藏路径上曾托管真实的 Shaw 仿冒 phishing 页面。这些路径数日内即被阻断,现在对多种请求配置均返回 HTTP 404。当前 apex、www 别名、79 个公开页面样本、同源咨询表单、跳转、DNS 和 TLS 均与其所述日本医疗机构一致;未复现当前 phishing 页面、外部凭据接收端、有害下载、malware payload 或 exploit。因此,当前外部警告属于相互矛盾的宽泛信誉背景,不能作为继续保留当前全域 Phishing 分类的依据。
分析师结论
本次检查记录了 9 项观察
查看证据
可注册父域的 HTTP 一次跳转到 HTTPS apex,HTTPS www 一次跳转到同一 apex。最终页面返回 HTTP 200,显示日本 Chosei-kai 医疗机构网站。desktop、mobile、Googlebot、Gridinsoft 和 Google-referrer 配置产生相同的规范化可见内容;审查的 root 页面未启动无关跳转或自动下载。
-
HTTP 状态
200 -
最终 URL
https://chosei-kai.com/ -
重定向目标
https://chosei-kai.com/ - MIME 类型 text/html; charset=UTF-8
- 文件 SHA-256 151897c29aed79b96bef5b9a0a4e9e1541433b1135635dabe6410f6ba2852140
- 页面元素 The page title was 長生会 and the visible content described the Chosei-kai medical corporation and its hospitals.
- 分析师观察 All five profiles had normalized visible-text SHA-256 51064254d30bcd24c10a1e96cbde25b29d3adc92e13c6e958a2f754129998c57.
有限的两层审查请求了从实时导航发现的 79 个同站页面。78 个返回 HTTP 200,一个旧图片路径返回 HTTP 404。没有页面最终落到无关 host,没有链接 executable 或 archive 下载,没有嵌入外部凭据表单,也没有提供文件上传界面。外部导航仅限 Google 与 Google Maps hosts。
- 分析师观察 79 same-site pages were requested: 78 returned HTTP 200 and one obsolete GIF path returned HTTP 404.
- 分析师观察 No executable, installer, script payload, or archive download link was identified in the reviewed navigation.
- 分析师观察 The only external hosts found in page navigation or resources were google.com, google.co.jp, maps.google.co.jp, and goo.gl.
两个公开表单均为同源 Contact Form 7 咨询和招聘表单。它们要求普通联系、地址、招聘与消息字段,并提交回 chosei-kai.com 上各自路径。它们不要求密码、支付卡、一次性代码或钱包秘密。没有提交任何表单。
- 公开证据 URL https://chosei-kai.com/inquiry
- 公开证据 URL https://chosei-kai.com/inquiry_recruit
- 页面元素 The general enquiry form requests name, phonetic name, telephone, address, email confirmation, and a message.
- 页面元素 The recruitment form adds recruitment categories and otherwise uses ordinary contact and message fields.
- 分析师观察 Both form actions remained on chosei-kai.com; no password or external credential receiver was present.
2026 年 5 月 6 日至 8 日的公共 urlscan 记录保留了两个确切路径上的真实对象级事件。这些页面返回 HTTP 200,标题为 Sign in - Shaw,并显示 Shaw Webmail 界面,以双因素认证消息要求 Shaw 邮箱和密码。保存的扫描将其标记为针对 Shaw 的 phishing。该记录证明的是历史 phishing 页面,而非单纯域名 blacklist 类别;未输入凭据,也未记录 malware 文件或 executable payload。
-
HTTP 状态
200 - 页面元素 Shaw Webmail branding, Confirm your 2 Factor Authentication, Shaw email, Password, and Sign in.
- 文件 SHA-256 a8759ded511e4bf2b202f0727c798a4bac14268ab3fea0d1d21f88cb2ac7aee1
- 截图 SHA-256 fff6111d8d372917d079d7ac0449abbf398370e6921607b1fac7ae56ce4f48f0
- 公开证据 URL https://urlscan.io/result/019e0538-c6dd-7368-906b-b43a62bf2b18/
- 公开证据 URL https://urlscan.io/result/019dfd5a-d461-771d-adf4-9b2acc34446e/
- 分析师观察 The urlscan page identified the saved response as phishing against Shaw and recorded response SHA-256 a8759ded511e4bf2b202f0727c798a4bac14268ab3fea0d1d21f88cb2ac7aee1.
两个确切 Shaw 路径现在对 desktop、Googlebot 和 Gridinsoft 配置均返回网站正常的 HTTP 404 页面。随后报告的 /00d1/ 与 /0000/ 目录也返回 HTTP 404,而直接列出 /wp-content/uploads/ 返回 HTTP 403。在这些路径上均未复现历史 phishing 内容或凭据界面。
-
HTTP 状态
404 -
最终 URL
https://chosei-kai.com/Arress/shaw/index.html -
最终 URL
https://chosei-kai.com/Arres/shaw/index.html -
最终 URL
https://chosei-kai.com/00d1/ -
最终 URL
https://chosei-kai.com/0000/ - 分析师观察 Each historical or later reported path returned the same unavailable result for desktop, crawler, and Gridinsoft request profiles.
- 分析师观察 The upload-directory root returned HTTP 403 rather than exposing a browsable file index.
apex 与 www 在 Xserver 基础设施上解析到 183.90.240.43。当前证书覆盖两个名称,有效期为 2026 年 8 月 22 日至 11 月 20 日。Verisign RDAP 将该域名记录为活跃且自 2012 年 12 月 24 日起注册;DNS 显示相同的五个 Xserver nameservers。
- DNS 信息 chosei-kai.com and www.chosei-kai.com resolved to 183.90.240.43; authoritative nameservers were ns1.xserver.jp through ns5.xserver.jp.
- 证书信息 The current TLS certificate covered chosei-kai.com and www.chosei-kai.com and was valid from 2026-08-22 through 2026-11-20.
- 公开证据 URL https://rdap.verisign.com/com/v1/domain/chosei-kai.com
- 分析师观察 The exact host and registrable parent are the same apex; www was reviewed as a separate alias.
urlscan 返回 25 条记录:确切 Shaw 页面在 5 月初在线,5 月 8 日至 11 日被阻断,并在 6 月和 7 月返回普通 404 页面;随后对 /00d1/ 与 /0000/ 的 scans 被阻断或不可用。OTX 包含一个 5 月 9 日 phishing 列表批量 pulse,其中只有域名级指标及 68 条 URL observations,包括到 5 月 13 日已移除的 Shaw 路径。Wayback 索引了 2013 至 2026 年成功的 root 与医疗网站内容,但本次审查期间无法检索确切路径的 archive。
- 公开证据 URL https://urlscan.io/domain/chosei-kai.com
- 公开证据 URL https://otx.alienvault.com/indicator/domain/chosei-kai.com
- 公开证据 URL https://web.archive.org/web/*/chosei-kai.com/
- 分析师观察 The exact urlscan records establish the former phishing page and its subsequent removal; the OTX pulse is only a domain indicator without an exact sample or behavior record.
- 分析师观察 Wayback CDX exposed successful root and medical-site records beginning in 2013 and continuing through 2026; archive coverage is incomplete.
当前外部聚合在 Gridinsoft 之外仍有 7 个恶意及 1 个可疑的域名 blacklist 标签,另有 Avira 和 Norton 的不利结果。这些标签未指出当前 URL、凭据接收端、文件、payload、hash 或 execution trace。公共 Triage 搜索没有报告;Hybrid Analysis、ANY.RUN、Joe Sandbox、URLQuery、URLhaus API 与 ThreatFox API 的详情不可用或受认证限制,均按未知处理。最近的公共 OpenPhish、URLhaus 与 ThreatFox feeds 没有精确匹配。
- 分析师观察 The current aggregate matrix retained alphaMountain.ai, Chong Lua Dao, CyRadar, Fortinet, Lionic, SOCRadar, VIPRE, and Forcepoint ThreatSeeker domain-level results; direct Avira and Norton results were also adverse.
- 分析师观察 Bitdefender categorized the site as health and did not return a malicious result.
- 分析师观察 No accessible external record beyond the historical Shaw pages supplied a current exact harmful object or behavioral sandbox trace.
- 分析师观察 Unavailable or authentication-restricted sources were treated as unknown rather than clean.
当前审查未复现历史 Shaw 仿冒、外部凭据接收端、无关跳转、自动投递 executable 或 archive、malware 文件、payload、hash、exploit 或有害 execution trace。当前 Gridinsoft 报告也没有支持活动 Phishing 类别的第一方正面行为信号。历史确切路径 phishing 页面仍是已确认的过去事件,而当前域名 blacklist 类别只是更宽泛的信誉背景。
- 分析师观察 No current phishing page, credential receiver, malware file, payload, hash, exploit, or harmful execution trace was reproduced.
- 分析师观察 The fresh Gridinsoft report contained no positive first-party behavior signal supporting the active Phishing classification.
- 分析师观察 A concrete historical object and a current domain-wide blacklist category are distinct evidence classes; only the former was directly demonstrated, and it is no longer served.
范围与限制
- 结论适用于当前公开 apex、www 别名、已审查页面样本、公开表单以及已识别历史路径。未评估认证内容、私有文件、服务器端源代码、数据库、logs、邮箱、管理员状态或未来变更。
- 未提交联系或招聘表单,也未输入凭据、个人数据、支付数据或一次性代码。历史 phishing 界面仅通过公共扫描器保存的元数据和图像进行审查,没有与其交互。
- 保存的历史响应与截图证明存在 Shaw 品牌邮箱和密码界面,但不证明已提交凭据、受害者损失、malware 文件、payload 执行、运营者身份或犯罪归因;本报告不作这些更强断言。
- 当前 WordPress sitemap endpoint 返回 HTTP 404,因此公开页面审查从实时导航进行有限的两层遍历。共请求 79 个同站页面:78 个返回 HTTP 200,一个过时图片路径返回 HTTP 404。
- 公共搜索、URL 扫描、sandbox、threat-intelligence、feed 与 archive 索引并不完整。受认证限制或不可用的来源按未知而非安全处理。
- 当前安全结论不会抹去已确认的历史 phishing 事件,也不认证未来内容;它表示在审查范围内,活动的宽泛 Phishing 分类没有可复现的当前第一方证据支持。
帮助保护他人,快在社交媒体上分享此页面吧!知道chosei-kai.com的人越多,骗子就越难得逞。 在社交媒体上分享此页面,帮助更多人评估chosei-kai.com!