Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=88tyc.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gorillareisen.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 19 Jun 2014 21:10:20 GMT
Server: Apache
Content-Type: text/html
X-Powered-By: PHP/5.4.28
GET / HTTP/1.1
Host: gorillareisen.de
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 19 Jun 2014 21:10:20 GMT
Server: Apache
Content-Type: text/html
X-Powered-By: PHP/5.4.28
Second query (visit from search engine):
GET / HTTP/1.1
Host: gorillareisen.de
Referer: http://www.google.com/search?q=gorillareisen.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gorillareisen.de
Referer: http://www.google.com/search?q=gorillareisen.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://www.88tyc.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 06 Jul 2014 22:20:14 GMT Location: http://www.a88888.com Server: LiteSpeed Content-Length: 1172 Content-Type: text/html | malicious |
http://www.a88888.com/ | HTTP/1.1 200 OK Date: Sun, 06 Jul 2014 22:19:08 GMT Accept-Ranges: bytes ETag: "462f9adf599cf1:51df2" Server: Microsoft-IIS/6.0 Content-Length: 33537 Content-Location: http://www.a88888.com/index.html Content-Type: text/html Last-Modified: Sun, 06 Jul 2014 10:34:32 GMT X-Powered-By: ASP.NET | clean |
http://www.a88888.com/index.html | 200 OK Content-Length: 33537 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: tyc99.com ...[4643 bytes skipped]... ;<strong><span class="STYLE97">bbin88.com</span></strong> <span class="STYLE106">æ³¢é³</span></div></td> </tr> <tr> <td height="50"><div align="center" class="STYLE84">tyc5.com <span class="STYLE106">太é³å</span></div></td> <td width="355" height="50"><div align="center"><span class="STYLE84">tyc99.com</span> <span class="STYLE106">太é³å</span></div></td> <td width="355" height="50"><div align="center"><span class="STYLE84">ty55.com</span> <span class="STYLE106">太é³å</span></div></td> </tr> <tr> <td height="50"><div align="center" class="STYLE84">msc365.com <span class="STYLE106">太é³å</span></div></td> & ...[42435 bytes skipped]... | ||
http://www.a88888.com/tyc.html | 200 OK Content-Length: 10188 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: tyc99.com ...[6890 bytes skipped]... tr> <tr> <td width="200" height="50"><span class="STYLE57">tyc5.com</span></td> <td width="376" height="50"><span class="STYLE57">æå åæ°</span></td> <td height="50"><span class="STYLE57">ä»·æ ¼ï¼è®®ä»·</span></td> </tr> <tr> <td width="200" height="50"><span class="STYLE57">tyc99.com</span></td> <td width="376" height="50"><span class="STYLE57">æåAA</span></td> <td height="50"><span class="STYLE57">ä»·æ ¼ï¼è®®ä»·</span></td> </tr> <tr> <td width="200" height="50"><span class="STYLE57">tyc876.com</span></td> <td width="376" height="50"><span class="STYLE57">876 </span><span class="STYLE57"> ...[6258 bytes skipped]... | ||
http://www.a88888.com/ylc.html | 200 OK Content-Length: 17334 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 6h.hk ...[2618 bytes skipped]... ;å ¶ä»åå</a></span></div></td> <td width="157"><div align="center"><span class="STYLE37"><a href="http://www.a88888.com" target="_blank">è¿åé¦é¡µ</a></span></div></td> </tr> </table> <table width="1111" align="center"> <tr> <td width="200" height="50"><strong><span class="STYLE59">6h.hk</span></strong></td> <td width="315" height="50"><strong><span class="STYLE59">å åHK</span></strong></td> <td height="50"><strong><span class="STYLE59">ä»·æ ¼ï¼<span class="STYLE61">议价</span></span></strong></td> </tr> <tr> <td width="200" height="50"><strong><span class="STYLE59">vin8.com</span></s ...[21290 bytes skipped]... | ||
http://www.a88888.com/tyzb.html | 200 OK Content-Length: 10341 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 310zc.com ...[3908 bytes skipped]... gt; <tr> <td width="200" height="50"><span class="STYLE57">310zuqiu.com</span></td> <td width="350" height="50"><span class="STYLE57">310足çç½</span></td> <td height="50"><span class="STYLE57">ä»·æ ¼ï¼è®®ä»·</span></td> </tr> <tr> <td width="200" height="50"><span class="STYLE57">310zc.com</span></td> <td width="350" height="50"><span class="STYLE57">310足彩ç½</span></td> <td height="50"><span class="STYLE57">ä»·æ ¼ï¼è®®ä»·</span></td> </tr> <tr> <td width="200" height="50"><span class="STYLE57">310zucai.com</span></td> <td width="350" height="50"><span class="STYLE57">310足彩ç½</span></td> ...[9581 bytes skipped]... | ||
http://www.a88888.com/qt.html | 200 OK Content-Length: 10250 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: mingchayuan.com ...[8812 bytes skipped]... <tr> <td width="300" height="50"><span class="STYLE61">chunyinfang.com</span></td> <td width="200" height="50"><span class="STYLE57">纯é¶å</span></td> <td height="50"><span class="STYLE57">ä»·æ ¼ï¼è®®ä»·</span></td> </tr> <tr> <td width="300" height="50"><span class="STYLE61">mingchayuan.com</span></td> <td width="200" height="50"><span class="STYLE57">èè¶å</span></td> <td height="50"><span class="STYLE57">ä»·æ ¼ï¼è®®ä»·</span></td> </tr> <tr> <td width="300" height="50"><span class="STYLE61">zhichashijia.com</span></td> <td width="200" height="50"><span class="STYLE57">å¶è¶ä¸å®¶</span></td> ...[4470 bytes skipped]... | ||
http://www.a88888.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |