Gridinsoft 在 Southfloridademolition.com 上观察到的情况
Gridinsoft 威胁分析师直接检查了该网站,并记录了支持此决定的证据。
GMA-20260902154540-6121e143
- 检查时间
- 由 Gridinsoft 威胁分析师 完成
- 分析师结论
- 安全
- 证据依据
- 第一方网站分析 外部安全厂商情报: 存在矛盾的背景信息——未用于本次决定
已审查的当前公开部署为安全。根域名与 www 在五种请求配置下均提供预期的 South Florida Demolition 网站,sitemap 中 53 个 URLs 全部返回 HTTP 200,公开 WordPress endpoints 返回 HTTP 404。未复现伪验证流程、PowerShell 指令、凭据仿冒、恶意重定向、自动下载、executable、archive、malware 文件、payload 或 hash。此前 Suspicious Website 分类与当前自有证据冲突,现已移除。Menlo Security 与 OTX 支持旧 WordPress 阶段可信的域名级 ClickFix 历史关联,但未保留该域名的确切恶意 URL 或样本。其余标签是外部域名信誉背景,不能代替当前可观察行为。
分析师结论
本次检查记录了 7 项观察
查看证据
更正前,Gridinsoft 记录将该域名标为 Suspicious Website,但当前报告显示 HTTP 200、无正面行为信号、预期企业标题,且没有确切恶意 URL、文件、payload 或 hash。更正并重新读取后,公开报告显示安全。外部不利域名标签没有取代当前可复现的自有依据。
- 公开证据 URL https://gridinsoft.com/online-virus-scanner/url/southfloridademolition-com
-
HTTP 状态
200 - 页面元素 The post-correction report readback showed Safe with no positive behavior signal.
- 分析师观察 The fresh external-engine aggregate contained 3 malicious, 1 suspicious, 55 harmless, and 31 undetected results; it was recorded as contradictory context rather than verdict evidence.
Windows、macOS、Android、Googlebot 与 Gridinsoft 配置收到同一个 40,645 字节 HTTPS 根文档和相同 SHA-256。页面是预期的 South Florida Demolition 企业网站;www 一次重定向到根域名并返回相同内容。未观察到伪 CAPTCHA、终端指令、clipboard 替换、无关重定向、自动下载、executable 或 archive 链接、凭据仿冒或当前 malware 对象。
-
HTTP 状态
200 -
最终 URL
https://southfloridademolition.com/ -
重定向目标
https://southfloridademolition.com/ - 文件 SHA-256 7de8069f3ce1e5bd7d384f5a6b59c795130360fb1ee961afbdffd56cd6940b1c
- 页面元素 The title was Fort Lauderdale's Trusted Demolition Contractor Since 1992 | South Florida Demolition Services.
- 分析师观察 All five request profiles received the same 40,645-byte root response and SHA-256.
- 分析师观察 No fake CAPTCHA, terminal instruction, clipboard replacement, unrelated redirect, automatic download, executable or archive link, credential imitation, or current malware object was observed.
sitemap 暴露 53 个同源公开 URLs,全部返回 HTTP 200。页面使用 Astro 样式表和预期分析或表单服务。静态检查未发现 ClickFix 或 PowerShell 指令、伪验证流程、executable 或 archive 引用、无关导航目标或自动下载。联系表单是普通业务咨询,未提交。
-
HTTP 状态
200 -
最终 URL
https://southfloridademolition.com/sitemap-0.xml - 分析师观察 All 53 same-origin sitemap URLs returned HTTP 200.
- 页面元素 The root used an Astro stylesheet and expected analytics scripts; the contact page used ordinary business inquiry fields.
- 分析师观察 No ClickFix or PowerShell instruction, fake verification flow, executable or archive reference, unrelated navigation target, or automatic download was found in the reviewed public surface.
公开路径 /wp-login.php、/wp-admin/、/wp-json/、/xmlrpc.php 和 /wp-content/ 在所有审查配置下均返回 HTTP 404。结合 Astro 资源和稳定页面集合,这支持此前公开 WordPress 表面已被移除并替换。它不能证明所有私有服务端组件或外部账户都不存在。
-
HTTP 状态
404 - 分析师观察 /wp-login.php, /wp-admin/, /wp-json/, /xmlrpc.php, and /wp-content/ returned HTTP 404 across the reviewed request profiles.
- 分析师观察 The current public pages referenced an Astro build asset rather than WordPress page assets.
Menlo Security 在 2026 年 5 月将 southfloridademolition.com 列入域名级 ClickFix 清单;四个 OTX pulses 重复该报告,而确切 www 主机没有 pulse。这支持可信历史关联,但没有提供确切路径、捕获响应、文件、payload 或 hash,也不能单独证明当前恶意行为。
- 公开证据 URL https://www.menlosecurity.com/blog/the-evolution-of-clickfix-from-cleartext-to-server-side-polymorphism
- 公开证据 URL https://otx.alienvault.com/indicator/domain/southfloridademolition.com
- 分析师观察 The Menlo indicator list contained southfloridademolition[.]com as a bare domain entry and did not preserve an exact URL, response, file, payload, or hash for it.
- 分析师观察 OTX returned four apex pulses that all referenced the same Menlo report and zero pulses for the exact www host.
urlscan 返回 12 个公开根域名扫描:旧 WordPress 企业网站、真实 Cloudflare challenge 和当前网站,但没有确切恶意对象。Wayback 保存的普通企业页面在已获取快照中没有 ClickFix 指令。有数据时,OTX URL 观察没有 Google Safe Browsing 匹配。可访问 sandbox 搜索未显示该确切主机任务;受限来源视为局限,而非干净结果。
- 公开证据 URL https://urlscan.io/domain/southfloridademolition.com
- 公开证据 URL https://urlscan.io/result/019d8f75-b569-75cc-99f5-67f6eb059dae/
- 公开证据 URL https://urlscan.io/result/019e463e-75fc-758a-bd85-6da96a298530/
- 公开证据 URL https://urlscan.io/result/01a022ed-dc8a-74eb-a02a-dda9fdca8bd6/
- 公开证据 URL https://web.archive.org/web/20260412001248id_/https://southfloridademolition.com/
- 分析师观察 The 12 urlscan apex records showed the prior business site, a genuine Cloudflare challenge, or the current business site; no exact malicious response, file, payload, or hash was preserved.
- 分析师观察 Fetched Wayback pages from the prior WordPress deployment contained coherent business content and no reproduced ClickFix or PowerShell instruction.
- 分析师观察 Public sandbox and intelligence indexes were finite; authorization failures and unavailable indexes were not treated as evidence of safety.
根域名与 www 通过 Cloudflare 解析。证书覆盖根域名与 wildcard,有效期为 2026-08-01 至 2026-10-30。Certificate Transparency 显示 app.southfloridademolition.com;该主机重定向到需要身份验证的 Cloudflare Access 登录,其私有内容未审查。这些基础设施事实界定范围,本身不能证明安全。
- DNS 信息 A: 104.21.17.25, 172.67.219.157
- 证书信息 Certificate covered southfloridademolition.com and *.southfloridademolition.com and was valid 2026-08-01 through 2026-10-30.
- 分析师观察 app.southfloridademolition.com was protected by Cloudflare Access, so authenticated private content was outside the public review.
范围与限制
- 审查覆盖根域名、www、sitemap 中 53 个 URLs、公开代码、表单、downloads、DNS、TLS、Gridinsoft 报告、URL intelligence、threat context、sandbox 搜索和历史公开内容。
- 无法访问 Cloudflare account、source repository、hosting panel、private server logs、Google Search Console 或 authenticated content。公开 HTTP 结果支持 WordPress 表面已移除,但不能证明所有私有 PHP、database 或 server 组件都不存在。
- Menlo 清单保留的是域名指标,而非确切恶意路径、响应、文件、payload、hash 或执行。档案可能遗漏条件式、地域性、隐藏、短时、已删除或未索引内容。
- 需要身份验证的 app.southfloridademolition.com 服务不在公开审查范围。未提交业务咨询表单,也未执行任何文件。
- 公开 search、urlscan、OTX、Wayback、sandbox 与 threat-intelligence 索引均有限。URLhaus 与 ThreatFox 需要授权,Common Crawl 不可用,部分 sandbox 搜索受限;不可用没有被视为干净结果。
- 外部 vendor 与 blacklist 标签由各方独立控制。域名级分类与具有可观察恶意行为的确切 URL 或样本不是同一证据对象。
帮助保护他人,快在社交媒体上分享此页面吧!知道southfloridademolition.com的人越多,骗子就越难得逞。 在社交媒体上分享此页面,帮助更多人评估southfloridademolition.com!