push.zhanzhang.baidu.com - suspicious URL scan, 24 Aug 2026
MalwareAnalyzer by Cyble scanned push.zhanzhang.baidu.com and returned a suspicious verdict (score 45). The page resolved to 163.177.17.97 on China Unicom Guangdong province network in CN. The domain was registered 9813 days ago through MarkMonitor Information Technology (Shanghai) Co., Ltd.. 1 domain and 1 IP were contacted. 3 malware samples communicate with this URL. This is a point-in-time observation from 24 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 45) · Confidence 54%
- Scanned URL:
http://push.zhanzhang.baidu.com/push.js - Domain: push.zhanzhang.baidu.com · IP: 163.177.17.97 · AS136958 · CN
- Server: bfe
- HTTP status: 200 · text/javascript
- Registrar: MarkMonitor Information Technology (Shanghai) Co., Ltd. · domain age 9813 days · created 1999-10-11
- Scan tier: fast · observed 2026-08-24 00:52:26 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from push.zhanzhang.baidu.com. Each links to its full analysis.
- b6e232457312de6171a0e002b5c937d2ff0fd9d44328e0694cd6000629262ff4 - referenced ·
b6e232457312de6171a0e002b5c937d2· first seen 2026-08-24 - f82fa8bd6317da8564bd12824fd292c9b326e294689adc711381688c3ec6b644 - referenced ·
f82fa8bd6317da8564bd12824fd292c9· first seen 2026-08-23 - 377f8295f4825a0a18bc6188f77b7097068ff8f1b886d0b2479c0c8e6778de8a - referenced ·
377f8295f4825a0a18bc6188f77b7097· first seen 2026-08-12
Antivirus & YARA (0 of 48 engines)
No engine flagged this page's content.
Why this verdict
- Grabbed file (push.js) is known suspicious in the corpus
- File download routed to the malware sandbox (push.js)
- Served over plaintext HTTP
Contacted infrastructure
- 163.177.17.97 - AS136958 China Unicom Guangdong province network (China)
Files served by this page
- push.js ·
674bc0c70f98d627b8a7e1d278a1f21f
Observed indicators
- push.zhanzhang.baidu.com
- 163.177.17.97
- http://push.zhanzhang.baidu.com/push.js
Other scans of push.zhanzhang.baidu.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://doingthing.com/downloads/blog/geust/files/fuxusuji.pdf - 21 Aug 2026 - unknown ·
https://www.4tuku.com/ - 21 Aug 2026 - unknown ·
http://colescastle.com/clients/875019/File/liwomisil.pdf - 21 Aug 2026 - unknown ·
http://colescastle.com/clients/875019/File/liwomisil.pdf - 21 Aug 2026 - unknown ·
https://www.nsw88.com/ - 20 Aug 2026 - unknown ·
http://tydafa.com/dafa/uploadfiles/20210905194436.pdf - 19 Aug 2026 - unknown ·
http://9jamail.com/ - 19 Aug 2026 - unknown ·
http://9jamail.com/ - 19 Aug 2026 - unknown ·
http://9jamail.com/ - 19 Aug 2026 - unknown ·
http://www.tcihk.com/userfiles/rifepifu.pdf
Questions about push.zhanzhang.baidu.com
- Is push.zhanzhang.baidu.com safe?
- No. MalwareAnalyzer scanned push.zhanzhang.baidu.com on 24 Aug 2026 and returned a suspicious verdict with a score of 45 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with push.zhanzhang.baidu.com?
- 3 analysed samples communicate with this URL.
- How was push.zhanzhang.baidu.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of push.zhanzhang.baidu.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan