Trusted but Verify
Current checks include security-provider warnings. Review the detected warnings and supporting trust evidence before relying on the site.
Trust signal radarNormalized trust signals for chosei-kai.comDomain Maturity: 5022 daysDomain MaturityWarning Cleanliness: 8 detectionsWarningCleanlinessSafety Level: 0 negative tagsSafetyLevelPositive Signals: 1 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .comTrust ZoneOperational Signals: 0 detected servicesOperationalSignalsLocation Credibility: Hosting country JPLocation Credibility
Figure 1. Trust signal radar for chosei-kai.com. Larger shaded area indicates stronger trust signals.
How we scored chosei-kai.com
Tech signals:
Wordpress Platform, Clipboard Support
Positive signals:
a long-term domain history (13.8 years)
an active SSL certificate (3 months)
Negative signals:
security-provider warnings
Last checked September 3, 2026 at 6:30 PM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Chosei-kai.com
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260903174836-87eabac2
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Safe
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context โ not used for this decision
The independent first-party review confirmed that chosei-kai.com hosted a real Shaw-branded phishing page on two exact hidden paths in early May 2026, but those paths were blocked within days and now return HTTP 404 across multiple request profiles. The current apex, www alias, 79-page public sample, same-origin enquiry forms, redirects, DNS, and TLS were consistent with the stated Japanese medical organization, and no current phishing page, external credential receiver, harmful download, malware payload, or exploit was reproduced. Current external warnings are therefore contradictory broad reputation context rather than support for retaining a present domain-wide Phishing classification.
Analyst findings
Info4
Info01
Historical Shaw phishing page was confirmed and is no longer served
Public May 2026 URL-scanner evidence preserved an exact Shaw-branded page asking for email and password on two hidden paths. Those paths now return HTTP 404 across desktop, crawler, and Gridinsoft profiles. The former phishing object is confirmed, while its present removal is an informational remediation finding rather than a current harmful condition.
Info02
Current phishing behavior was not reproduced
The current apex, www alias, public pages, forms, redirects, and previously abused paths did not reproduce brand impersonation, an external credential receiver, or another phishing flow. The public forms remained same-origin and did not request passwords or other authentication secrets.
Info03
Reviewed public surface was consistent with the medical organization
The registrable parent and www alias served the same Japanese medical organization site, the reviewed forms and navigation remained consistent with enquiry and recruitment functions, and the bounded page review exposed no executable or archive delivery link or unrelated final host.
Info04
Current blacklist labels did not identify a current harmful object
The remaining adverse results were domain-wide reputation categories. Unlike the concrete May phishing page, they did not identify a current malicious URL, credential receiver, file, payload, hash, exploit, or observed harmful execution. They therefore remain contradictory context rather than a reproducible basis for a current broad Phishing classification.
Review 9 documented observations
View evidence
01HTTP response
HTTP on the registrable parent redirected once to the HTTPS apex, and HTTPS www redirected once to the same apex. The final page returned HTTP 200 as the Japanese Chosei-kai medical organization site. Desktop, mobile, Googlebot, Gridinsoft, and Google-referrer profiles produced identical normalized visible content; the reviewed root did not initiate an unrelated redirect or automatic download.
Page elementThe page title was ้ท็ไผ and the visible content described the Chosei-kai medical corporation and its hospitals.
Analyst observationAll five profiles had normalized visible-text SHA-256 51064254d30bcd24c10a1e96cbde25b29d3adc92e13c6e958a2f754129998c57.
02Navigation
A bounded two-level review requested 79 same-site pages discovered from the live navigation. Seventy-eight returned HTTP 200; one old image path returned HTTP 404. No reviewed page ended on an unrelated host, linked an executable or archive download, embedded an external credential form, or exposed a file-upload interface. External navigation was limited to Google and Google Maps hosts.
Analyst observation79 same-site pages were requested: 78 returned HTTP 200 and one obsolete GIF path returned HTTP 404.
Analyst observationNo executable, installer, script payload, or archive download link was identified in the reviewed navigation.
Analyst observationThe only external hosts found in page navigation or resources were google.com, google.co.jp, maps.google.co.jp, and goo.gl.
03Form
The two public forms were same-origin Contact Form 7 enquiry and recruitment forms. They requested ordinary contact, address, recruitment, and message fields and posted back to their respective chosei-kai.com paths. They did not request a password, payment card, one-time code, or wallet secret. No form was submitted.
Public artifact URLhttps://chosei-kai.com/inquiry
Public artifact URLhttps://chosei-kai.com/inquiry_recruit
Page elementThe general enquiry form requests name, phonetic name, telephone, address, email confirmation, and a message.
Page elementThe recruitment form adds recruitment categories and otherwise uses ordinary contact and message fields.
Analyst observationBoth form actions remained on chosei-kai.com; no password or external credential receiver was present.
04Historical content
Public urlscan records from May 6 through May 8, 2026 preserve a real object-level incident on two exact paths. The pages returned HTTP 200 with the title Sign in - Shaw and displayed a Shaw Webmail interface asking for a Shaw email address and password under a two-factor-authentication message. The saved scan marked phishing against Shaw. The retrieved record demonstrates a historical phishing page, not merely a domain blacklist category; no credential was entered and no malware file or executable payload was recorded.
HTTP status200
Page elementShaw Webmail branding, Confirm your 2 Factor Authentication, Shaw email, Password, and Sign in.
Public artifact URLhttps://urlscan.io/result/019e0538-c6dd-7368-906b-b43a62bf2b18/
Public artifact URLhttps://urlscan.io/result/019dfd5a-d461-771d-adf4-9b2acc34446e/
Analyst observationThe urlscan page identified the saved response as phishing against Shaw and recorded response SHA-256 a8759ded511e4bf2b202f0727c798a4bac14268ab3fea0d1d21f88cb2ac7aee1.
05HTTP response
The two exact Shaw paths now returned the site's normal HTTP 404 page for desktop, Googlebot, and Gridinsoft profiles. The later reported /00d1/ and /0000/ directories also returned HTTP 404 across those profiles, while direct directory listing for /wp-content/uploads/ returned HTTP 403. The historical phishing content and a credential interface were not reproduced on any of these paths.
HTTP status404
Final URLhttps://chosei-kai.com/Arress/shaw/index.html
Final URLhttps://chosei-kai.com/Arres/shaw/index.html
Final URLhttps://chosei-kai.com/00d1/
Final URLhttps://chosei-kai.com/0000/
Analyst observationEach historical or later reported path returned the same unavailable result for desktop, crawler, and Gridinsoft request profiles.
Analyst observationThe upload-directory root returned HTTP 403 rather than exposing a browsable file index.
06TLS
The apex and www host resolved to 183.90.240.43 on Xserver infrastructure. The current certificate covered both names and was valid from August 22 through November 20, 2026. Verisign RDAP recorded the domain as active and registered since December 24, 2012, with the same five Xserver nameservers observed in DNS.
DNS factchosei-kai.com and www.chosei-kai.com resolved to 183.90.240.43; authoritative nameservers were ns1.xserver.jp through ns5.xserver.jp.
Certificate factThe current TLS certificate covered chosei-kai.com and www.chosei-kai.com and was valid from 2026-08-22 through 2026-11-20.
Public artifact URLhttps://rdap.verisign.com/com/v1/domain/chosei-kai.com
Analyst observationThe exact host and registrable parent are the same apex; www was reviewed as a separate alias.
07Historical content
urlscan returned 25 records: the exact Shaw pages were live in early May, blocked by May 8 through May 11, and returned ordinary 404 pages in June and July; later /00d1/ and /0000/ scans were blocked or unavailable. OTX contained one May 9 bulk phishing-list pulse with a domain-only indicator and 68 URL observations, including the Shaw path already removed by May 13. Wayback indexed successful root and medical-site content from 2013 through 2026, but exact-path archive retrieval was unavailable during this review.
Public artifact URLhttps://urlscan.io/domain/chosei-kai.com
Public artifact URLhttps://otx.alienvault.com/indicator/domain/chosei-kai.com
Public artifact URLhttps://web.archive.org/web/*/chosei-kai.com/
Analyst observationThe exact urlscan records establish the former phishing page and its subsequent removal; the OTX pulse is only a domain indicator without an exact sample or behavior record.
Analyst observationWayback CDX exposed successful root and medical-site records beginning in 2013 and continuing through 2026; archive coverage is incomplete.
08Limitation
Current external aggregation retained seven malicious and one suspicious domain blacklist labels outside Gridinsoft, with separate adverse Avira and Norton results. These labels did not name a current URL, credential receiver, file, payload, hash, or execution trace. The public Triage search returned no report; Hybrid Analysis, ANY.RUN, Joe Sandbox, URLQuery, URLhaus API, and ThreatFox API details were unavailable or authentication-limited and were treated as unknown. Recent public OpenPhish, URLhaus, and ThreatFox feeds had no exact match.
Analyst observationThe current aggregate matrix retained alphaMountain.ai, Chong Lua Dao, CyRadar, Fortinet, Lionic, SOCRadar, VIPRE, and Forcepoint ThreatSeeker domain-level results; direct Avira and Norton results were also adverse.
Analyst observationBitdefender categorized the site as health and did not return a malicious result.
Analyst observationNo accessible external record beyond the historical Shaw pages supplied a current exact harmful object or behavioral sandbox trace.
Analyst observationUnavailable or authentication-restricted sources were treated as unknown rather than clean.
09Limitation
The current review did not reproduce the historical Shaw impersonation, an external credential receiver, an unrelated redirect, automatic executable or archive delivery, a malware file, payload, hash, exploit, or harmful execution trace. The current Gridinsoft report also contained no positive first-party behavior signal supporting the active Phishing category. The historical exact-path phishing page remains a confirmed past incident, while current domain blacklist categories are broader reputation context.
Analyst observationNo current phishing page, credential receiver, malware file, payload, hash, exploit, or harmful execution trace was reproduced.
Analyst observationThe fresh Gridinsoft report contained no positive first-party behavior signal supporting the active Phishing classification.
Analyst observationA concrete historical object and a current domain-wide blacklist category are distinct evidence classes; only the former was directly demonstrated, and it is no longer served.
Scope and limitations
The verdict applies to the current public apex, www alias, reviewed page sample, public forms, and identified historical paths. Authenticated content, private files, server-side source, databases, logs, mailboxes, administrator state, and future changes were not assessed.
No contact or recruitment form was submitted, and no credential, personal data, payment data, or one-time code was entered. The historical phishing interface was inspected from preserved public scanner metadata and imagery without interacting with it.
The preserved historical response and screenshot establish a Shaw-branded email-and-password interface, but they do not prove a submitted credential, victim loss, malware file, payload execution, operator identity, or criminal attribution; none of those stronger claims is made.
The current WordPress sitemap endpoint returned HTTP 404, so the public-page review used a bounded two-level traversal from live navigation. It requested 79 same-site pages; 78 returned HTTP 200 and one obsolete image path returned HTTP 404.
Public search, URL-scanner, sandbox, threat-intelligence, feed, and archive indexes are incomplete. Authentication-restricted or unavailable sources were treated as unknown rather than clean.
A Safe current verdict does not erase the confirmed historical phishing incident or certify future content; it states that the active broad Phishing classification was not supported by reproducible current first-party evidence in the reviewed scope.
This domain was registered December 24, 2012 at 3:43 AM through the company GMO Internet Group, Inc. d/b/a Onamae.com
and ownership information is not publicly available.
We reviewed chosei-kai.com and found mostly positive signals. Current checks lean toward a legitimate, lower-risk profile, although a few caution points still keep it short of a fully verified standing. The current trust score is 79/100. Key signals include security-provider warnings and a domain age of 13.8 years. Verify key details before sharing personal information or relying on the site for important actions.
FAQ
Is chosei-kai.com safe?
Based on current analysis, chosei-kai.com appears to be generally safe. The final verdict also reflects manual expert review. Basic verification is still reasonable before relying on the site.
Why does chosei-kai.com look trustworthy?
Key factors include registrar information (GMO Internet Group, Inc. d/b/a Onamae.com) and hosting in JP. The trust score blends security detections, domain and infrastructure signals, and on-page behavior patterns. Taken together, these factors support a mostly positive trust assessment, although routine verification is still reasonable.
Chosei-kai Digital Footprints
A structured view of the site's detected themes, page signals, and related online footprint elements.
Wordpress Platform
Our analyzer determines that this website is using WordPress CMS. WordPress is the most popular content management system, powering over 43% of websites globally.
Bootstrap Framework
This site uses Bootstrap, a widely-adopted open-source framework for responsive web development. Bootstrap enables efficient creation of mobile-friendly interfaces through standardized components and styling.
jQuery Library
Clipboard Support
Established Domain
chosei-kai.com has maintained active domain presence over time, indicating operational continuity.
External provider warnings: 8/29
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
alphaMountain.ai
Phishing
Chong Lua Dao
Malicious
CyRadar
Phishing
Fortinet
Phishing
Lionic
Phishing
SOCRadar
Phishing
VIPRE
Phishing
Forcepoint ThreatSeeker
Suspicious
External provider results for Chosei-kai.com, last checked September 3, 2026.
โ VirusTotal
Domain Information
CreatedDecember 24, 2012 at 3:43 AMUpdated: August 6, 2026 at 1:50 AM ยท Expires: December 24, 2026 at 3:43 AM
Domain Age13.8 years
RegistrantJP (Japan)
RegistrarGMO Internet Group, Inc. d/b/a Onamae.comIANA ID: 49
If you own Chosei-kai.com and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about chosei-kai.com, the fewer chances they have to deceive someone else.Help others evaluate chosei-kai.com by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about chosei-kai.com, the fewer chances they have to deceive someone else. Help others evaluate chosei-kai.com by sharing this page on social media!