www.baidu.com - suspicious URL scan, 21 Aug 2026
MalwareAnalyzer by Cyble scanned www.baidu.com and returned a suspicious verdict (score 28). The page resolved to 103.235.46.115 on Rooms 2201-03, 22/F, World Wide House in HK. The domain was registered 9811 days ago through MarkMonitor Information Technology (Shanghai) Co., Ltd.. 39 domains and 2 IPs were contacted, over 12 HTTP requests. 6 malware samples communicate with this URL (Mirai, HUILoader, AntiVM, PowerShell). The request followed 1 redirect before landing. This is a point-in-time observation from 21 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 28) · Confidence 34%
- Scanned URL:
https://baidu.com/ - Domain: www.baidu.com · IP: 103.235.46.115 · AS55967 · HK
- Server: BWS/1.1
- Page title: 百度一下,你就知道
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: MarkMonitor Information Technology (Shanghai) Co., Ltd. · domain age 9811 days · created 1999-10-11
- TLS issuer: C=BE, O=GlobalSign nv-sa, CN=GlobalSign RSA OV SSL CA 2018 · valid to Jan 24 02: · subject C=CN, ST=Beijing, L=Beijing, O=Beijing Baidu Netcom Science Technology Co., Ltd., CN=baidu.com
- Evidenced operator: Beijing Baidu Netcom Science Technology Co., Ltd.
- HTTP requests captured: 12
- Scan tier: fast · observed 2026-08-21 19:11:26 UTC
Redirect chain
https://baidu.com/https://www.baidu.com/
Malware communicating with this URL (6)
These samples were observed contacting or being served from www.baidu.com. Each links to its full analysis.
- custom-element-template.js - referenced ·
fb3db0ebf5867a685ac255380bdecee2· first seen 2026-08-21 - swan-template.js - referenced ·
3ed9a2a8c23d45e118550d04349a71a1· first seen 2026-08-21 - Mirai - referenced ·
0795e6fcc25cb34317d8190d1ad13258· first seen 2026-08-21 - HUILoader - referenced ·
c967025f2a9cc66f22c535611f617ea9· first seen 2026-08-18 - AntiVM - referenced ·
257d968d7d78362779f32e3223545e96· first seen 2026-08-18 - PowerShell - referenced ·
aa5c738b0077a86e235f68cf0cf7ef26· first seen 2026-08-12
Antivirus & YARA (1 of 47 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Valid TLS, no impersonation or off-origin credential post
Contacted infrastructure
- 103.235.46.115 - AS55967 Rooms 2201-03, 22/F, World Wide House (Hong Kong)
- 111.63.65.247 - AS24547 China Mobile Communications Corporation (China)
Observed indicators
- www.baidu.com
- pss.bdstatic.com
- dss0.bdstatic.com
- dss1.bdstatic.com
- ss1.bdstatic.com
- sp0.baidu.com
- sp1.baidu.com
- sp2.baidu.com
- psstatic.cdn.bcebos.com
- su.bdimg.com
- passport.baidu.com
- news.baidu.com
- www.hao123.com
- map.baidu.com
- tieba.baidu.com
- haokan.baidu.com
- image.baidu.com
- pan.baidu.com
- wenku.baidu.com
- chat.baidu.com
Other scans of www.baidu.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://fasson.vip/ - 23 Aug 2026 - unknown ·
http://fasson.vip/ - 22 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 21 Aug 2026 - suspicious
- 20 Aug 2026 - unknown ·
http://fasson.vip/ - 20 Aug 2026 - suspicious
Questions about www.baidu.com
- Is www.baidu.com safe?
- No. MalwareAnalyzer scanned www.baidu.com on 21 Aug 2026 and returned a suspicious verdict with a score of 28 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.baidu.com?
- 6 analysed samples communicate with this URL, including Mirai, HUILoader, AntiVM, PowerShell.
- How was www.baidu.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.baidu.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan