This company has verified ownership of the profile and can respond to reviews.
Verified Safe
Current checks include security-provider warnings. Review the detected warnings and supporting trust evidence before relying on the site.
Trust signal radarNormalized trust signals for mouzi.ccDomain Maturity: 134 daysDomain MaturityWarning Cleanliness: 4 detectionsWarningCleanlinessSafety Level: 0 negative tags, 1 warning signalSafetyLevelPositive Signals: 2 positive signalsPositiveSignalsPopularity: Estimated low traffic without Tranco or social profile dataPopularityTrust Zone: .ccTrust ZoneOperational Signals: 0 detected servicesOperationalSignalsLocation Credibility: Hosting country USLocation Credibility
Figure 1. Trust signal radar for mouzi.cc. Larger shaded area indicates stronger trust signals.
content related to file sharing and downloadable content; software products and downloads
Last checked September 5, 2026 at 3:07 PM by
Gridinsoft Trust Model v2.5.3
Share this report?
Independent Gridinsoft analysis
What Gridinsoft observed on Mouzi.cc
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
Current review
Review ID
GMA-20260825044534-8d7f5382
Reviewed
by Gridinsoft Threat Analyst
Analyst finding
Safe
Evidence basis
First-party site analysisExternal vendor intelligence: Contradictory context — not used for this decision
The independent current review supports Safe for mouzi.cc and its six current release links. A fresh Gridinsoft rescan reached the homepage with HTTP 200 and recorded no positive behavior signal. All 35 sitemap URLs remained on-site and exposed no form, credential prompt, iframe, automatic download, meta refresh, or scripted external redirect. The download links lead to the disclosed GitHub v0.1.5 release; five downloaded files matched GitHub's SHA-256 records, and source plus successful release workflows are public. The exact MSI has a public malicious sandbox score, but its visible indicators describe conditional installation of Microsoft's official Edge WebView2 prerequisite. The downloaded child exactly matches Microsoft's current file, and the report names no malware family or Mouzi command-and-control behavior. Eleven malicious and one suspicious vendor results remain broad blacklist labels without an exact current harmful object. Unsigned Windows artifacts reduce publisher assurance and should be signed, but do not establish malware. Safe describes the reviewed deployment and release set, not future content or a reproducible-build certification.
Analyst findings
Low1
Info4
Info01
The current broad domain detection was not reproduced
The fresh first-party rescan and complete current sitemap review identified no harmful path, credential flow, automatic download, unrelated redirect, malicious script, or positive behavior signal. The prior broad Suspicious Website category therefore conflicted with the current exact-object evidence.
Info02
The adverse MSI sandbox score maps to an official prerequisite
The exact current MSI has a public malicious sandbox score, but its visible indicators are the expected Tauri/WiX installation of Microsoft Edge WebView2. The sandbox child hash exactly matches the bootstrapper downloaded from Microsoft's official URL, with no named malware family or independently observed Mouzi command-and-control or credential behavior. This is object-level behavior analysis, not a dismissal based on a domain whitelist.
Info03
Remaining adverse results are broad blacklist categories
Eleven malicious and one suspicious external entries remain, but all are blacklist classifications without a current exact Mouzi URL, payload, response, screenshot, file hash, or behavior trace. Public URL scans, OTX, archives, and indexed sample searches did not supply a contrary harmful object. These labels remain external context rather than the basis for Gridinsoft's current verdict.
Low04
Unsigned Windows artifacts reduce publisher assurance
The current Windows portable and setup executables are not Authenticode-signed. This makes publisher identity harder for users and reputation systems to verify and should be remediated, but no malicious behavior follows from the absence of a signature alone.
Info05
The conflicting broad classification was corrected
Current reproducible Gridinsoft-owned evidence supports the normal Mouzi project site and its disclosed release objects. Because the retained broad Suspicious Website label had no reproducible current harmful basis, the current classification was corrected to Safe while preserving the unsigned-binary limitation and contradictory external reputation context.
Review 9 documented observations
View evidence
01Content
A fresh supported Gridinsoft rescan reached the exact HTTPS root with HTTP 200, stayed on mouzi.cc, and identified the Mouzi homepage. Before correction, Suspicious Website was retained by a broad domain signature even though the fresh first-party report contained no positive behavioral signal and identified no current harmful path, response, script, redirect, or download.
HTTP status200
Final URLhttps://mouzi.cc/
Page elementTitle: Mouzi | The fastest way to find your files
Analyst observationThe fresh supported rescan recorded an empty current positive-signal list; the prior result was supplied by a broad domain signature.
02Navigation
All 35 public URLs enumerated from the current sitemap returned HTTP 200 and remained on mouzi.cc. Desktop, Android, crawler, and command-line request profiles received byte-identical root HTML. Across the 35 pages there were no forms, password inputs, iframes, meta-refresh instructions, scripted location changes, or automatic external navigation. The www host redirected once to the HTTPS apex.
HTTP status200
Final URLhttps://mouzi.cc/
Redirect destinationhttps://mouzi.cc/
Analyst observationThirty-five sitemap URLs returned same-host HTTP 200 responses; 0 forms, 0 password inputs, 0 iframes, 0 meta refresh directives, and 0 scripted location assignments were found.
Analyst observationRoot HTML SHA-256 for all four request profiles: b82e4be21d3df9e2c4bb72198d5bc925e187eab64416664a00cc85b24d76bd0f.
03Download
The current site exposed six explicit download links, all to the public GitHub release v0.1.5: Windows setup, MSI, portable executable, AppImage, Debian package, and RPM. Five downloaded artifacts matched the SHA-256 digests published by GitHub's release API; the AppImage digest was also recorded from that API. The site did not start any download automatically. The public repository, tagged source, successful release workflows, and release assets were mutually consistent.
Public artifact URLhttps://github.com/hsr88/mouzi/releases/tag/v0.1.5
Public artifact URLhttps://github.com/hsr88/mouzi/tree/v0.1.5
A public Hybrid Analysis report marked the exact current MSI malicious with a threat score of 85, while also showing no malware family and 0 of 24 MetaDefender detections. Its visible adverse indicators describe hidden PowerShell downloading Microsoft's Edge WebView2 bootstrapper from go.microsoft.com, silently installing it, and Microsoft Edge Update processes. The MSI itself contains that conditional Tauri/WiX prerequisite command. A direct download from the same official Microsoft URL had the exact SHA-256 of the sandbox child, showing that the observed process activity belongs to the official runtime installer rather than to an identified Mouzi malware payload.
Public artifact URLhttps://www.hybrid-analysis.com/sample/b04f976ef5ee95b1c8b282f4c487daac1cc58390cf3bd4cc22a3f1cea720ed90
Public artifact URLhttps://developer.microsoft.com/en-us/microsoft-edge/webview2/
Analyst observationThe MSI command invokes the WebView2 bootstrapper only when an installed WebView2 version is not present; no Mouzi malware family, command-and-control host, or credential collection behavior was identified by the public report.
05Content
The public Rust and Tauri application source implements a local file-search utility backed by local files and SQLite. Source review found no configured application telemetry receiver or arbitrary remote service; explicit external-open actions point to the Mouzi site, GitHub, and Ko-fi. The website source is a static Astro deployment. The tagged release and subsequent asset-rebuild revision differ only in release documentation, date text, and the rebuild workflow rather than security-sensitive application behavior.
Public artifact URLhttps://github.com/hsr88/mouzi
Public artifact URLhttps://github.com/hsr88/mouzi/compare/b32e5ca...a75feaa
Analyst observationNo implemented application telemetry sender, credential receiver, remote-control endpoint, downloader, persistence mechanism, or arbitrary command execution path was identified in the reviewed source.
06Historical content
urlscan returned five records mentioning the domain. The relevant direct records included the apex and an older v0.1.0 setup executable and assigned no classification. One unrelated submitted softgratuit.eu URL redirected to mouzi.cc; that chain was an inbound third-party redirect to Mouzi, not an outbound redirect initiated by mouzi.cc. The older executable record preserved SHA-256 9787cd17239db5e6e43645f01095e4a595b4926dde96cb36aa357d6e25042c55 and no verdict.
Public artifact URLhttps://urlscan.io/domain/mouzi.cc
Analyst observationThe softgratuit.eu record shows an external site redirecting into mouzi.cc; it does not show mouzi.cc redirecting visitors to the external site or serving a malicious object.
07Historical content
Four Wayback root snapshots from May through August 2026 consistently preserve the Mouzi file-search site. The May snapshots link the same-host v0.1.0 Windows downloads, the June snapshot links v0.1.3 Windows and Linux downloads, and the August snapshot links the current v0.1.5 GitHub release. None of the four archived roots contained a form, password field, iframe, meta refresh, or scripted location assignment.
Public artifact URLhttps://web.archive.org/web/20260515191719/https://mouzi.cc/
Public artifact URLhttps://web.archive.org/web/20260520095927/https://mouzi.cc/
Public artifact URLhttps://web.archive.org/web/20260616115256/https://mouzi.cc/
Public artifact URLhttps://web.archive.org/web/20260818074212/https://mouzi.cc/
08Historical content
AlienVault OTX reported zero pulses for the exact domain. Searches of publicly indexed sandbox, URL-scan, threat-intelligence, malware-sample, and general web records found no harmful exact Mouzi URL or sample beyond the Hybrid Analysis MSI report reviewed separately. The fresh external matrix contained 45 harmless, eleven malicious, one suspicious, and 33 undetected results; all adverse entries were blacklist classifications and supplied no current object-level trace.
Public artifact URLhttps://otx.alienvault.com/indicator/domain/mouzi.cc
Analyst observationURLhaus and ThreatFox public API requests required authorization; Common Crawl and crt.sh were unavailable during review. Unavailable sources were treated as unverified, not clean.
Analyst observationmouzi.cc is itself the registrable apex, so the exact host and requested parent-domain scope are the same object. www.mouzi.cc is a redirecting alias to the apex; no broader parent verdict was inferred.
09Download
The reviewed portable and setup executables did not contain an Authenticode security directory, and the project states that code signing is pending. This reduces independently verifiable publisher identity and can increase reputation warnings, but it is a provenance and hardening weakness rather than evidence of malware behavior.
Analyst observationPortable and NSIS setup PE Security Directory values were zero; no Authenticode signature was present.
Public artifact URLhttps://mouzi.cc/download
Scope and limitations
The verdict covers the publicly reachable mouzi.cc apex, its www redirect, all 35 sitemap URLs, and the six v0.1.5 release links exposed at the recorded time; content and release objects can change after publication.
Five of six release assets were downloaded and hashed directly. The AppImage digest was verified against the GitHub release API but the AppImage itself was not downloaded during this review.
Source, tags, workflow history, and release assets were reviewed, but a clean-room byte-for-byte rebuild of every release artifact was not performed.
The Windows setup and portable executables were unsigned at review time. This limits publisher-identity assurance even though no malicious behavior was identified.
The public Hybrid Analysis report covered the current MSI. Not every release asset had an available public dynamic-analysis report, and no private commercial sandbox or authenticated threat-intelligence dataset was used.
Public search, sandbox, URL-scan, threat-intelligence, and archive indexes are incomplete. Sources that required authentication or were unavailable were treated as unverified, not clean.
No private hosting account, build runner, signing account, repository secret, local user data, or server filesystem was penetration-tested.
This domain was registered May 9, 2026 at 4:31 PM through the company Spaceship, Inc.
WHOIS registrant details are private. Separately, the business has verified control of its Gridinsoft profile.
We reviewed mouzi.cc and found mostly positive signals. Current checks lean toward a legitimate, lower-risk profile, although a few caution points still keep it short of a fully verified standing. The current trust score is 80/100. Key signals include security-provider warnings. Verify key details before sharing personal information or relying on the site for important actions.
Figure 2.
Website screenshot for Mouzi.cc.
2026-09-05 18:07:49
FAQ
Is mouzi.cc safe?
Based on current analysis, mouzi.cc appears to be generally safe. The final verdict also reflects manual expert review. Basic verification is still reasonable before relying on the site.
Why does mouzi.cc look trustworthy?
Key factors include registrar information (Spaceship, Inc.), hosting in US, a relatively new domain (4 months), and content related to file sharing and downloadable content; software products and downloads. The trust score blends security detections, domain and infrastructure signals, and on-page behavior patterns. Taken together, these factors support a mostly positive trust assessment, although routine verification is still reasonable.
Mouzi Digital Footprints
A structured view of the site's detected themes, page signals, and related online footprint elements.
Downloads
Watches
Linux
Microsoft Software
Multilanguage
The website provides multi-language support, demonstrating international accessibility and commitment to diverse user populations. Multi-language implementation typically indicates professional development standards and global operational scope, representing a positive trust indicator.
Google Tag Manager
This website uses Google Tag Manager to add and update tracking tags on its website.
Astro Framework
Social Media Links
The presence of social media links on the website indicates that it references social media accounts. This signal alone does not confirm ownership or authenticity of those profiles.
GitHub Profile
This site links to a GitHub profile or public repository associated with the project. This is a useful transparency signal, especially when the account has public activity.
Young Domain
This site was registered recently, which limits historical reputation data and long-term trust signals.
Claimed Company Profile
The company behind mouzi.cc has claimed its profile in the Gridinsoft portal and provided verified ownership details.
External provider warnings: 4/26
This section shows what independent external security sources say about this site.
A warning appears when one or more sources report malware, phishing, abuse, or other safety concerns. Each row shows the source and its verdict.
If no source reports a warning, the site is shown as clear in this section.
ADMINUSLabs
Malicious
Forcepoint ThreatSeeker
Malicious
Fortinet
Malware
ESET
Suspicious
External provider results for Mouzi.cc, last checked September 5, 2026.
— VirusTotal
Domain Information
CreatedMay 9, 2026 at 4:31 PMUpdated: August 9, 2026 at 12:34 PM · Expires: May 9, 2027 at 4:31 PM
Domain StatusClient Transfer ProhibitedDNSSEC: UNSIGNED
Top Level Domain.ccDomain Extension
Technical Details
IP Address216.150.1.129
Hosting ProviderAS16509 Amazon.com, Inc.Walnut, California, US
SSL CertificateYR1TLS 1.3 · Valid for: 3 months · from August 9, 2026 at 11:40 AM · to November 7, 2026 at 11:40 AM
Name Serversns1.vercel-dns.com ns2.vercel-dns.com
Content Analysis
Website titleMouzi — automatic Downloads folder organizer for Windows and Linux
Website descriptionMouzi is a free, open-source Downloads folder organizer for Windows and Linux. It quietly sorts downloaded files with rules you control. Local-only, no accounts, no telemetry.
If you own Mouzi.cc and want to challenge the trust score, please submit a review request via portal.gridinsoft.com. There you can claim your profile and add verified company/contact details. If you cannot access the portal, email legal(at)gridinsoft.com with proof of legitimacy and contact details. We never charge website owners for reviews or reconsideration requests. For more information, please review our Disclaimer.
A website report warns you. A PC scan protects you.
Unsafe sites can leave adware, unwanted apps, or hidden malware in downloads and browser settings. Run Gridinsoft Anti-Malware to check what may already be on this Windows PC.
Checks active threats, startup items, and suspicious downloads
Finds adware and unwanted apps linked to unsafe websites
Shows scan results before you decide what to remove
Your comment is currently undergoing moderation and will be published shortly.
Help protect others by sharing this page on social media! The more people who know about mouzi.cc, the fewer chances they have to deceive someone else.Help others evaluate mouzi.cc by sharing this page on social media!
Help protect others by sharing this page on social media! The more people who know about mouzi.cc, the fewer chances they have to deceive someone else. Help others evaluate mouzi.cc by sharing this page on social media!