Scanned pages/files
Request | Server response | Status |
http://www.22pic.com/ | 200 OK Content-Length: 54993 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://l.bst.126.net/rsc/htm/music.html <iframe style="display:none" src="http://l.bst.126.net/rsc/htm/music.html" > | ||
http://l.bst.126.net/rsc/js/pagelayer/pagelayer.js?0011 | 200 OK Content-Length: 26178 Content-Type: application/x-javascript | clean |
http://l.bst.126.net/rsc/js/jquery-1.6.2.min.js | 200 OK Content-Length: 91572 Content-Type: application/x-javascript | clean |
http://lofter.ph.126.net/jw6oduESim0EXyuyySdCww==/5629524822980561900.js | 200 OK Content-Length: 8821 Content-Type: application/javascript | clean |
http://lofter.ph.126.net/q9lts_5USlOXrxZlBbf-6g==/6597113747121111241.js | 200 OK Content-Length: 3253 Content-Type: application/javascript | clean |
http://l.bst.126.net/rsc/js/themecommon.js?0025 | 200 OK Content-Length: 21263 Content-Type: application/x-javascript | clean |
http://analytics.163.com/ntes.js | 200 OK Content-Length: 20233 Content-Type: application/x-javascript | clean |
http://www.22pic.com/view | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 08 Nov 2015 22:23:39 GMT Location: http://www.lofter.com/userentry.do?hostBlogId=805268&needDecode=true&target=http://iatiy.lofter.com/view Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 Set-Cookie: NTESLOFTSI=54B70294C18F4D03E040955FBB286977.classa-lofter5-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Farchive.do%3Fmydomain%3Dwww.22pic.com%26|; Domain=.lofter.com; Expires=Mon, 09-Nov-2015 22:22:45 GMT; Path=/ | clean |
http://www.lofter.com/userentry.do?hostblogid=805268&needdecode=true&target=http://iatiy.lofter.com/view | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 08 Nov 2015 22:22:46 GMT Location: http://iatiy.lofter.com/view Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID" Set-Cookie: NTESLOFTSI=F6C2DB1423930CF545376493ADC8C4AB.classa-lofter9-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Fuserentry.do%3FX-From-ISP%3D2%26hostblogid%3D805268%26needdecode%3Dtrue%26target%3Dhttp%3A%2F%2Fiatiy.lofter.com%2Fview|; Domain=.lofter.com; Expires=Mon, 09-Nov-2015 22:22:46 GMT; Path=/ Set-Cookie: PRIVILEGE_USER_IDENTIFICATION=-1; Domain=.lofter.com; Path=/ Set-Cookie: usertrack=ZUcIilY/yzYehjjvBL1NAg==; expires=Mon, 07-Nov-16 22:22:46 GMT; domain=lofter.com; path=/ | clean |
http://iatiy.lofter.com/view | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 08 Nov 2015 22:22:47 GMT Location: http://www.lofter.com/userentry.do?hostBlogId=805268&needDecode=true&target=http://iatiy.lofter.com/view Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID" Set-Cookie: NTESLOFTSI=455A0CEB970235AD7D03487A7FDA031A.classa-lofter4-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Farchive.do%3FloftBlogName%3Diatiy%26X-From-ISP%3D2|; Domain=.lofter.com; Expires=Mon, 09-Nov-2015 22:22:47 GMT; Path=/ Set-Cookie: usertrack=ZUcIilY/yzcc4zjrBKHhAg==; expires=Mon, 07-Nov-16 22:22:47 GMT; domain=lofter.com; path=/ | clean |
http://www.lofter.com/test404page.js | 404 Not Found Content-Length: 1872 Content-Type: text/html | clean |
http://www.lofter.com/ | 200 OK Content-Length: 1418 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://reg.163.com/crossdomain_all.do <iframe onload="jumpto()" style="display:none" src="http://reg.163.com/crossdomain_all.do"> | ||
http://www.lofter.com/contact | 200 OK Content-Length: 7850 Content-Type: text/html | clean |
http://l.bst.126.net/s/core.js?802416d382627e0d6599ef310d89b604 | 200 OK Content-Length: 85582 Content-Type: application/x-javascript | clean |
http://l.bst.126.net/s/pt_page_contact.js?7f4ae88a2df5bd1eb0fde46a6d2b315d | 200 OK Content-Length: 98688 Content-Type: application/x-javascript | clean |
http://www.lofter.com/app/QRCodedownload?act=qbipaddl_20141014_01 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 08 Nov 2015 22:22:55 GMT Location: http://www.lofter.com/app/?qrcode=qbipaddl_20141014_01 Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID" Set-Cookie: NTESLOFTSI=DB1650B8FB03E2FB143BD33B64BFB749.classa-lofter4-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Fqrdownload.do%3FX-From-ISP%3D2%26act%3Dqbipaddl_20141014_01|; Domain=.lofter.com; Expires=Mon, 09-Nov-2015 22:22:55 GMT; Path=/ Set-Cookie: usertrack=ZUcIi1Y/yz8+/d1IBKZMAg==; expires=Mon, 07-Nov-16 22:22:55 GMT; domain=lofter.com; path=/ | clean |
http://www.lofter.com/app/?qrcode=qbipaddl_20141014_01 | 200 OK Content-Length: 6869 Content-Type: text/html | clean |
http://l.bst.126.net/s/pt_page_util_mobiledescnew.js?ecde7dfcd94edc5b34eee3fc708d002f | 200 OK Content-Length: 98807 Content-Type: application/x-javascript | clean |
http://www.lofter.com/feedback.do | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sun, 08 Nov 2015 22:22:58 GMT Location: http://www.lofter.com/login Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID" Set-Cookie: NTESLOFTSI=95661618DEB42F1507315740DDAC8845.classa-lofter1-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Ffeedback.do%3FX-From-ISP%3D2|; Domain=.lofter.com; Expires=Mon, 09-Nov-2015 22:22:58 GMT; Path=/ Set-Cookie: usertrack=ZUcIilY/y0IYyzjfBL/7Ag==; expires=Mon, 07-Nov-16 22:22:58 GMT; domain=lofter.com; path=/ | clean |
http://www.lofter.com/login | 200 OK Content-Length: 1418 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://reg.163.com/crossdomain_all.do <iframe onload="jumpto()" style="display:none" src="http://reg.163.com/crossdomain_all.do"> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 22pic.com
Result:
GET / HTTP/1.1
Host: 22pic.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: 22pic.com
Referer: http://www.google.com/search?q=22pic.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 22pic.com
Referer: http://www.google.com/search?q=22pic.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=22pic.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://22pic.com/
Result: 22pic.com is not infected or malware details are not published yet.
Result: 22pic.com is not infected or malware details are not published yet.