Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=35tl.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://35tl.com/ | 200 OK Content-Length: 18754 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1027 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[21973 bytes skipped]... | ||
http://35tl.com/function.js | 200 OK Content-Length: 151 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: 55881111.com document.writeln("<iframe height=\"1930px\" width=\"100%\" src=\"http:\/\/55881111.com\" scrolling=\"no\" style=\"border:0px; margin:0px\"><\/iframe>") Decoded script: <iframe height="1930px" width="100%" src="http://55881111.com" scrolling="no" style="border:0px; margin:0px"></iframe> | ||
http://35tl.com/total.js | 200 OK Content-Length: 149 Content-Type: application/x-javascript | clean |
http://35tl.com/ganxidianlirun/ | 200 OK Content-Length: 10657 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[11180 bytes skipped]... | ||
http://35tl.com/images/js/jquery.min.js | 200 OK Content-Length: 72174 Content-Type: application/x-javascript | clean |
http://35tl.com/ganxidianchengben/ | 200 OK Content-Length: 10927 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[11450 bytes skipped]... | ||
http://35tl.com/ganxijijiage/ | 200 OK Content-Length: 10922 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[11445 bytes skipped]... | ||
http://35tl.com/ganxidianjiamengzhinan/ | 200 OK Content-Length: 11205 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[11770 bytes skipped]... | ||
http://35tl.com/ganxishebei/ | 200 OK Content-Length: 8042 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[8091 bytes skipped]... | ||
http://35tl.com/jiamengxiyi/ | 200 OK Content-Length: 14179 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[15218 bytes skipped]... | ||
http://35tl.com/ganxidianjiamenganli/ | 200 OK Content-Length: 9339 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1145 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[9616 bytes skipped]... | ||
http://35tl.com/ganxidianxiangguanwenda/ | 200 OK Content-Length: 11438 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[12003 bytes skipped]... | ||
http://35tl.com/ganxijiamengdianzhanshi/ | 200 OK Content-Length: 8238 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[1139 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>&l ...[8287 bytes skipped]... | ||
http://35tl.com/ganxijiamengdianzhanshi/2013/0718/695.html | 200 OK Content-Length: 7431 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[703 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>& ...[7723 bytes skipped]... | ||
http://35tl.com/ganxijiamengdianzhanshi/2013/0718/696.html | 200 OK Content-Length: 7371 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 172.241.204.92 ...[703 bytes skipped]... ='/function.js' ></script> <body> <div id="main"> <div id="header"> <div id="logo"><a href="/" name="top"><img src="/templets/laundry/images/logo.gif" alt="ÐÂʱ´úÓéÀÖ³Ç" /></a></div> <div id="head_right"></div> <br /><span onclick="var strHref=window.location.href;this.style.behavior='url(#default#homepage)';this.setHomePage('http://172.241.204.92');" style="CURSOR: hand">ÉèΪÊ×Ò³</span><br><span style="CURSOR: hand" onClick="window.external.addFavorite('http://172.241.204.92','ÐÂʱ´úÓéÀÖ³Ç_ÓéÀÖ³Ç×îÐÂÓÅ»Ý_¿ª»§ËÍ18ÔªÌåÑé½ð_Ãâ·ÑËÍ18Ôª_×¢²áËÍ18ÔªÏÖ½ð_ÓéÀÖ³Ç×¢²áËÍ18ÌåÑé½ð_²¨Òô×¢²áËͲʽð')" title="ÐÂʱ´úÓéÀÖ³Ç">Êղر¾Õ¾</span> </div> <!--µ¼º½¿ªÊ¼--> <ul id="nav"> <li><a href='/'>Ê× Ò³</a></li> <li>& ...[7651 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 35tl.com
Result:
HTTP/1.1 200 OK
Date: Sun, 06 Apr 2014 03:09:35 GMT
Accept-Ranges: bytes
ETag: "1ae33096c96ce1:47d1"
Server: Microsoft-IIS/6.0
Content-Length: 18754
Content-Location: http://35tl.com/index.html
Content-Type: text/html
Last-Modified: Sun, 11 Aug 2013 08:23:19 GMT
X-Powered-By: ASP.NET
...18754 bytes of data.
GET / HTTP/1.1
Host: 35tl.com
Result:
HTTP/1.1 200 OK
Date: Sun, 06 Apr 2014 03:09:35 GMT
Accept-Ranges: bytes
ETag: "1ae33096c96ce1:47d1"
Server: Microsoft-IIS/6.0
Content-Length: 18754
Content-Location: http://35tl.com/index.html
Content-Type: text/html
Last-Modified: Sun, 11 Aug 2013 08:23:19 GMT
X-Powered-By: ASP.NET
...18754 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 35tl.com
Referer: http://www.google.com/search?q=35tl.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 35tl.com
Referer: http://www.google.com/search?q=35tl.com
Result:
The result is similar to the first query. There are no suspicious redirects found.