Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=595cq.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.595cq.net/ | 200 OK Content-Length: 244 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: d687ef1ed80f97de.0075.cdn.78302.com <meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<script language="javascript" type="text/javascript" src="http://d687ef1ed80f97de.0075.cdn.78302.com/nipaiyi/cdn/js/20150209213403001.js?d=595cq.0032.utnvg.com"></script> | ||
http://d687ef1ed80f97de.0075.cdn.78302.com/nipaiyi/cdn/js/20150209213403001.js?d=595cq.0032.utnvg.com | 200 OK Content-Length: 67851 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: www.595cq.net ...[3722 bytes skipped]... o:p></o:p></span></p>"); document.writeln(" </td>"); document.writeln(" </tr>"); document.writeln("</table>"); document.writeln("<p class=MsoNormal><span lang=EN-US><o:p> </o:p></span></p>"); document.writeln(" </tr>"); document.writeln("</table>"); document.writeln(" <EMBED src=\"123.mp3\" tppabs=\"http://www.595cq.net/123.mp3\" width=\"0\" height=\"0\" border=0 autostart=\"ture\" loop=\"ture\"></EMBED>"); document.writeln("</div>"); document.writeln("<script language=\"javascript\" type=\"text/javascript\" src=\"http://anti-ddos.78302.com/antiddos/safe.js?d=595cq.0032.utnvg.com\"></script></body>"); document.writeln("</html>"); document.writeln("<SCRIPT language=JavaScript>alert(\"\/\/=========Likeinfo´«ÆæÓÎÏ·¹«¸æ=========\/\/n\/\/ ...[142 bytes skipped]... Decoded script: ...[21196 bytes skipped]... 10.5pt'>ÏÂÔØ<span lang=EN-US><o:p></o:p></span></span></span></p> <p class=MsoNormal><span class=style41><span lang=EN-US style='font-size:10.5pt'><o:p> </o:p></span></span></p> <p class=MsoNormal><span style='font-size:9.0pt'>×îÐÂ<span lang=EN-US><a href="http://www.595cq.net/LoginTool/dlq.zip" tppabs="http://595cq.net/LoginTool/dlq.zip" target="_blank">2015<span lang=EN-US><span lang=EN-US>°æµÇ½Æ÷ÍøͨÓû§µã»÷ÏÂÔØ</span></span></a> </span>×îÐÂ<span lang=EN-US><a href="http://www.595cq.net/LoginTool/dlq.zip" tppabs="http://595cq.net/LoginTool/dlq.zip" target ...[35623 bytes skipped]... | ||
http://www.595cq.net/test404page.js | 404 Not Found Content-Length: 5209 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 595cq.net
Result:
GET / HTTP/1.1
Host: 595cq.net
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: 595cq.net
Referer: http://www.google.com/search?q=595cq.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 595cq.net
Referer: http://www.google.com/search?q=595cq.net
Result:
The result is similar to the first query. There are no suspicious redirects found.