This company has verified ownership of the profile and can respond to reviews.
Suspicious Website
Gridinsoft currently classifies this site as Suspicious Website. The report highlights 1 blacklist detections, no established public user-review history, and heuristic security signals. These risks are driven by active warning signals despite the site's longer domain history.
Figure 1. Trust signal radar for codernav.com. Larger shaded area indicates stronger trust signals.
How we scored codernav.com
On-page mentions:
Games, Streaming Platform
Tech signals:
Wordpress Platform, Redis Object Cache
Negative signals:
security-provider warnings
a malware or phishing blacklist detection (1)
heuristic signals associated with scam
automated caution checks
Positive signals:
the domain owner has claimed this profile
a long-term domain history (5.1 years)
an active SSL certificate (3 months)
Context signals:
standard payment methods
content related to online gaming; streaming media
Last checked September 8, 2026 at 11:16 AM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Codernav.com
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260828233940-191021c9
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Suspicious Website
Evidence basis
First-party site analysisExternal vendor intelligence: Context only โ not used for this decision
The independent Gridinsoft review supports retaining Suspicious Website for codernav.com. The root did not reproduce an unrelated automatic redirect, and no specific malware sample, payload, URL, or hash was proven. However, the site exposes a large encoded outbound-navigation namespace and an operator-authored resource tutorial that instructs users to use obscured, password-protected archives and bypass a browser unsafe-download warning. These first-party conditions justify caution without overstating the evidence as proof of a particular malware payload. External vendor labels were not used for this verdict.
Analyst findings
Medium2
Info1
Medium01
Security-warning bypass and obscured archive guidance
An operator-authored page directs users to a same-parent resource host, describes multi-layer encryption intended to prevent reports and removal, instructs users to rename unexpected file extensions to ZIP, and advises bypassing an Edge unsafe-download warning. This is an affirmative security-sensitive distribution condition even though no specific archive was proven malicious in this review.
Medium02
Large encoded outbound-navigation namespace
The service exposes thousands of site and article pages and routes many third-party destinations through the same-origin /go/ mechanism. The exact current destination inventory could not be fully enumerated or followed through the anti-automation boundary, so the root cannot establish that every linked object and destination is safe.
Info03
No specific malware sample proven
The current root did not automatically redirect to an unrelated host, and the review did not identify a specific malware file, payload, hash, credential receiver, or exploit. The Suspicious Website decision is based on the reproduced navigation and download-guidance risks, not on a claim that a particular malware sample was observed.
Review 6 documented observations
View evidence
01Content
The current Gridinsoft report reached the expected Chinese-language link-directory deployment and retained Suspicious Website. The root stayed on codernav.com, and the report did not name an exact malicious URL, file, payload, hash, credential receiver, or exploit. The report contained no positive behavior signal, so the independent decision follows from the separately reproduced navigation and download-guidance surface rather than from an unspecified malware inference.
Analyst observationThe current report retained Suspicious Website and contained no positive behavior signal or named exact harmful object.
02HTTP response
Direct desktop, mobile, and scanner-profile requests to the apex, www, and start hosts resolved to the same server but received HTTP 403 anti-automation responses. The apex response stayed on the requested host and contained only a script that navigated back to the same root. The live robots file and sitemap remained publicly accessible with HTTP 200.
HTTP status403
Final URLhttps://codernav.com/
Page elementThe 403 response used a same-origin browser navigation back to the root and did not expose an unrelated redirect destination.
Analyst observationrobots.txt and sitemap.xml returned HTTP 200 while the reviewed HTML routes and the outbound-navigation route were blocked by the same anti-automation boundary.
03Navigation
The live sitemap enumerated 39,356 same-host URLs, including 5,382 site-entry pages, 7,012 numeric article pages, 26,724 tag pages, and account or favorites surfaces. A preserved 2026 root page contained 168 links handled through the same-origin /go/ route with encoded third-party destinations, while the live robots policy excluded /go/ from crawling.
HTTP status200
Page elementLive sitemap counts: 39,356 total URLs; 5,382 /sites/ pages; 7,012 numeric article pages; 26,724 tag pages.
Page elementThe preserved 2026 root page contained 168 navigation links whose third-party destinations were encoded and handled by the same-origin /go/ route.
Page elementThe live robots policy disallowed /go/.
04Historical content
A May 2026 public snapshot preserved an operator-authored tutorial that pointed users to alist.codernav.com for more than 10 TB of resources. It said archives used multiple encryption layers to prevent reports and removal, instructed users to rename files with unexpected extensions to ZIP, supplied the archive password, and advised bypassing an Edge unsafe-download warning by using another browser or keeping the download. The exact tutorial URL remains listed in the current live sitemap.
Public artifact URLhttps://codernav.com/7755.html
Page elementThe tutorial identified alist.codernav.com as a resource repository with more than 10 TB of content.
Page elementThe tutorial instructed users to download archives locally, rename unexpected file extensions to ZIP, and use the supplied password after describing multiple encryption layers intended to prevent reports and removal.
Page elementFor an Edge unsafe-download warning, the tutorial advised using another browser or selecting the option to keep the download.
Analyst observationThe live sitemap still listed https://codernav.com/7755.html with its recorded 2024-10-13 last-modified value.
05TLS
The referenced alist resource host currently resolved to the same 119.91.2.76 server as the apex. Its HTTPS endpoint presented the apex certificate, whose names covered only codernav.com and www.codernav.com, so hostname validation failed for alist.codernav.com. HTTP and a certificate-ignoring HTTPS request both returned the same anti-automation 403 boundary; no resource archive was downloaded or executed.
DNS factcodernav.com, www.codernav.com, start.codernav.com, and alist.codernav.com resolved to 119.91.2.76 during the review.
Certificate factThe presented certificate covered codernav.com and www.codernav.com but did not cover alist.codernav.com.
HTTP status403
Analyst observationNo file listing, archive, executable, or payload was retrieved from the resource host.
06Limitation
The review identified security-sensitive download guidance and a large encoded outbound-navigation surface, but it did not identify or execute a specific malware file, payload, hash, credential-theft page, or exploit served by codernav.com. The retained category is therefore Suspicious Website, not a claim that a particular current sample was proven malicious.
Analyst observationNo exact malware file, payload, URL, or hash was identified in the reviewed scope.
Analyst observationNo unrelated automatic root redirect or credential receiver was reproduced.
Scope and limitations
The site returned anti-automation HTTP 403 responses for the reviewed HTML and outbound-navigation routes, so the exact current destination behavior could not be exercised directly from the review network.
No exact resource file, archive URL, or hash was supplied with the appeal. No archive, executable, or other payload was downloaded or executed.
The live sitemap and encoded outbound-link namespace are too large and changeable for exhaustive destination review; a specific disputed URL or file requires object-level analysis.
The historical tutorial content was verified from a May 2026 public snapshot and its continued presence in the live sitemap, but the origin page body could not be retrieved directly through the current anti-automation boundary.
Private server files, authenticated accounts, administrative tools, upload workflows, and server logs were not accessed. Public search, scanner, threat-intelligence, and archive indexes are incomplete.
What is Codernav?
According to its current page title, codernav.com presents itself as โๅผๅ่ ๅฏผ่ช - ้ไธ่ฑๅผ๏ผๅฏ็ผ็ผๅฝ็ฃใโ. The sections below evaluate the site-specific reputation and technical findings.
Figure 2.
Website screenshot for Codernav.com.
2026-09-08 14:16:05
This domain was registered August 16, 2021 at 6:12 PM through the company Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn)
WHOIS registrant details are private. Separately, the business has verified control of its Gridinsoft profile.
Use caution with codernav.com. Its current Gridinsoft trust score is 35/100; review the site-specific findings below before use.
Why is codernav.com marked "Suspicious Website"?
Gridinsoft's current assessment of codernav.com is based on automated caution checks and heuristic signals associated with scam. Verified ownership of the Gridinsoft business profile is a positive signal. The listed status means the domain currently appears in Gridinsoft's own Threat List; it is not a consensus of external providers. 1 of 27 publicly displayed security sources report a warning.
A structured view of the site's detected themes, page signals, and related online footprint elements.
Reliable Payment Method
Payment processing utilizes established and secure payment systems including major credit cards, PayPal, or other recognized financial service providers. These payment methods typically offer fraud protection and dispute resolution mechanisms to safeguard consumers.
Games
Streaming Platform
Wordpress Platform
Our analyzer determines that this website is using WordPress CMS. WordPress is the most popular content management system, powering over 43% of websites globally.
Bootstrap Framework
codernav.com uses Bootstrap, a widely-adopted open-source framework for responsive web development. Bootstrap enables efficient creation of mobile-friendly interfaces through standardized components and styling.
Redis Object Cache
jQuery Library
Heuristic - Scam
Heuristic Risk
China
Established Domain
This site has maintained active domain presence over time, indicating operational continuity.
Listed by Gridinsoft
Gridinsoft Internet Security classified this site as unsafe. As a VirusTotal partner, our detections contribute to broader protection across tools and browsers.
Claimed Company Profile
The company behind codernav.com has claimed its profile in the Gridinsoft portal and provided verified ownership details.
tttdh.comwww.chahu.comyouxisgj.comtranslate.google.comwww.zjnav.comt3.gstatic.cnwww.weiyun.comvisagoia.commail.qq.comcalendar.google.comdongpian17.comwww.lanzou.comto-do.live.comcover.xgdh.cncodernav.com
and 73 more
Security Analysis
Detection SignaturesThese signatures are used to generate the security fingerprint below.
If you own Codernav.com and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about codernav.com, the fewer chances they have to deceive someone else.Help others evaluate codernav.com by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about codernav.com, the fewer chances they have to deceive someone else. Help others evaluate codernav.com by sharing this page on social media!