www.baidu.com - suspicious URL scan, 15 Aug 2026
MalwareAnalyzer by Cyble scanned www.baidu.com and returned a suspicious verdict (score 46). The page resolved to 103.235.46.115 on Rooms 2201-03, 22/F, World Wide House in HK. The domain was registered 9805 days ago through MarkMonitor Information Technology (Shanghai) Co., Ltd.. 38 domains and 1 IP were contacted, over 12 HTTP requests. 3 malware samples communicate with this URL (STRATO, Nitol). This is a point-in-time observation from 15 Aug 2026; the page may have changed since.
Scan result
- Verdict: suspicious (score 46) · Confidence 52%
- Scanned URL:
http://www.baidu.com/ - Domain: www.baidu.com · IP: 103.235.46.115 · AS55967 · HK
- Server: BWS/1.1
- Page title: 百度一下,你就知道
- HTTP status: 200 · text/html; charset=utf-8
- Registrar: MarkMonitor Information Technology (Shanghai) Co., Ltd. · domain age 9805 days · created 1999-10-11
- HTTP requests captured: 12
- Scan tier: fast · observed 2026-08-15 16:29:18 UTC
Malware communicating with this URL (3)
These samples were observed contacting or being served from www.baidu.com. Each links to its full analysis.
- STRATO - referenced ·
1bfff6fda12148582641583026420a70· first seen 2026-08-15 - Nitol - referenced ·
00d91b827e3710cdb5c092a3626295d6· first seen 2026-08-15 - STRATO - referenced ·
10ff5772b6e9eaab24f54ac4a09cbc71· first seen 2026-08-13
Antivirus & YARA (1 of 44 engines)
- YARA: SophosLabs IoCs (public) [yara]: SOPHOS_Gootloader_JS (page content)
These signatures matched text in the page. Pages that quote or document malware can match them, so on their own they do not make a page malicious.
Why this verdict
- Antivirus/YARA detection in page content: SOPHOS_Gootloader_JS
- Served over plaintext HTTP
Contacted infrastructure
- 103.235.46.115 - AS55967 Rooms 2201-03, 22/F, World Wide House (Hong Kong)
Observed indicators
- www.baidu.com
- pss.bdstatic.com
- dss0.bdstatic.com
- dss1.bdstatic.com
- ss1.bdstatic.com
- sp0.baidu.com
- sp1.baidu.com
- sp2.baidu.com
- psstatic.cdn.bcebos.com
- su.bdimg.com
- passport.baidu.com
- news.baidu.com
- www.hao123.com
- map.baidu.com
- tieba.baidu.com
- haokan.baidu.com
- image.baidu.com
- pan.baidu.com
- wenku.baidu.com
- chat.baidu.com
Other scans of www.baidu.com (10)
This host has been scanned before. Each scan is a separate observation, so a verdict here does not carry over to the others.
- 23 Aug 2026 - unknown ·
http://fasson.vip/ - 23 Aug 2026 - unknown ·
http://fasson.vip/ - 22 Aug 2026 - suspicious ·
https://www.baidu.com/ - 21 Aug 2026 - suspicious ·
https://www.baidu.com/ - 21 Aug 2026 - suspicious ·
https://www.baidu.com/ - 21 Aug 2026 - suspicious ·
https://www.baidu.com/ - 21 Aug 2026 - suspicious ·
https://www.baidu.com/ - 21 Aug 2026 - suspicious ·
https://www.baidu.com/ - 21 Aug 2026 - suspicious ·
https://www.baidu.com/ - 20 Aug 2026 - unknown ·
http://fasson.vip/
Questions about www.baidu.com
- Is www.baidu.com safe?
- No. MalwareAnalyzer scanned www.baidu.com on 15 Aug 2026 and returned a suspicious verdict with a score of 46 out of 100. Treat it as hostile until it is re-checked.
- What malware is associated with www.baidu.com?
- 3 analysed samples communicate with this URL, including STRATO, Nitol.
- How was www.baidu.com checked?
- A static pass resolved DNS, captured TLS and headers and followed the redirect chain, and where the fast tier allows, a headless browser rendered the page and recorded every request. Egress is SSRF-locked. Signatures that matched only page text are weighted far below one that matched a served file, because a page documenting malware matches the same rules.
Scanned at the fast tier - see how URL scanning works.
Scan another URL · Latest analyzed threats · All scans of www.baidu.com
Scanned on MalwareAnalyzer by Cyble · Open interactive scan