Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=5202626.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://5202626.com/ | 200 OK Content-Length: 100371 Content-Type: text/html | clean |
http://5202626.com/js/msclass.js | 200 OK Content-Length: 16525 Content-Type: application/x-javascript | clean |
http://kft.zoosnet.net/JS/LsJS.aspx?siteid=KFT88530477&float=1&lng=cn | 200 OK Content-Length: 8170 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.5202626.com var LR_lng = 'cn';var LR_sysurl = 'http://kft.zoosnet.net/';var LR_sysurl1 = 'http://kft.zoosnet.net/';var LR_isMobile = 0;var LR_3a252='FD78B5839F374D23BBD67921B76FD261';var LR_15e9a=LR_3a252.replace(/4/g,'8').replace(/5/g,'3');var LR_siteid = '88530477';var LR_3f74d=LR_15e9a.replace(/1/g,'3').replace(/0/g,'2');var LR_websiteid = 'KFT88530477';var LR_MCount=0;var LR_Tick=new Date().getTime().toString()+parseInt(Math.random()*499999999+Math.random()*40 ...[3665 bytes skipped]... | ||
http://kft.zoosnet.net/test404page.js | 404 Not Found Content-Length: 1163 Content-Type: text/html | clean |
http://5202626.com/js/MSClass.js | 404 Not Found Content-Length: 571 Content-Type: text/html | clean |
http://5202626.com/js/loutab.js | 200 OK Content-Length: 603 Content-Type: application/x-javascript | clean |
http://5202626.com/js/calendar.js | 200 OK Content-Length: 32523 Content-Type: application/x-javascript | clean |
http://5202626.com/js/lang/en.js | 404 Not Found Content-Length: 571 Content-Type: text/html | clean |
http://5202626.com/images/js/kf.js | 200 OK Content-Length: 841 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 5202626.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 22 Dec 2014 19:28:07 GMT
Via: 1.0 nilaiwowang.com:80 (squid/2.6.STABLE22)
Accept-Ranges: bytes
Server: nginx/1.0.10
Vary: Accept-Encoding
Content-Length: 100371
Content-Type: text/html
Last-Modified: Sun, 30 Nov 2014 09:18:32 GMT
X-Cache: MISS from nilaiwowang.com
X-Cache-Lookup: MISS from nilaiwowang.com:80
...100371 bytes of data.
GET / HTTP/1.1
Host: 5202626.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 22 Dec 2014 19:28:07 GMT
Via: 1.0 nilaiwowang.com:80 (squid/2.6.STABLE22)
Accept-Ranges: bytes
Server: nginx/1.0.10
Vary: Accept-Encoding
Content-Length: 100371
Content-Type: text/html
Last-Modified: Sun, 30 Nov 2014 09:18:32 GMT
X-Cache: MISS from nilaiwowang.com
X-Cache-Lookup: MISS from nilaiwowang.com:80
...100371 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 5202626.com
Referer: http://www.google.com/search?q=5202626.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 5202626.com
Referer: http://www.google.com/search?q=5202626.com
Result:
The result is similar to the first query. There are no suspicious redirects found.