Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=36cd.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gesticondo.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 14 Oct 2015 05:30:25 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 232677
Content-Type: text/html
Last-Modified: Sat, 29 Aug 2015 00:19:36 GMT
...232677 bytes of data.
GET / HTTP/1.1
Host: gesticondo.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 14 Oct 2015 05:30:25 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 232677
Content-Type: text/html
Last-Modified: Sat, 29 Aug 2015 00:19:36 GMT
...232677 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gesticondo.com
Referer: http://www.google.com/search?q=gesticondo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gesticondo.com
Referer: http://www.google.com/search?q=gesticondo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.36cd.com/ | HTTP/1.1 302 Found Connection: close Date: Thu, 29 Jan 2015 22:32:42 GMT Location: http://ww15.36cd.com/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.3-7+squeeze23 | malicious |
http://ww15.36cd.com/ | 200 OK Content-Length: 12829 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 36cd.com ...[659 bytes skipped]... /> .add_link li a{width: 105px; color:#0098c8; font:normal 16px/32px "å®ä½"; height:32px; overflow:hidden; display:inline-block; margin: 0 0 0 12px;} .add_link li a:hover{ text-decoration:underline;} .boxbg { background-color: #000; border: 1px solid #303030; } </style> <script type="text/javascript">var gl={trackingurl:'http://ww15.36cd.com/tracking.php',searchurl:'http://ww15.36cd.com/index.php',relatedsearch:'Related Search',searchbutton:'Search',ckurl:'',cdn:'http://'+document.domain+'/'};var req={ps:["afd","bd3"],adtest:'off',dm:'36cd.com',fdm:'ww15.36cd.com',landerid:323,buy:true,adultallowed:true,cusbuy:'<span class="buy"> </span>',contactinfo:'',partner:'afd',dks:['å·¦æè碱å¤å°é±ä¸ç ','è£ é¥°ç½','è´å¯ ','å¾å©','游ææºå®ä½å¨ ','å°å·ä¸ç¨pcæ¿','å »çåº','çå±','æ§éç¢ ',' ...[2950 bytes skipped]... | ||
http://www.google.com/adsense/domains/caf.js | 200 OK Content-Length: 207644 Content-Type: text/javascript | clean |
http://www.36cd.com/js/parking_caf_281_1409192.js | 404 Not Found Content-Length: 227 Content-Type: text/html | clean |
http://www.36cd.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |