Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=92xiaohua.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 92xiaohua.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 08 Jan 2015 19:34:43 GMT
Location: http://www.442214.com/
Server: IIS
Content-Length: 145
Content-Type: text/html
X-Cache: MISS from Znncnn.com
X-Cache-Lookup: MISS from Znncnn.com:80
...145 bytes of data.
GET / HTTP/1.1
Host: 92xiaohua.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 08 Jan 2015 19:34:43 GMT
Location: http://www.442214.com/
Server: IIS
Content-Length: 145
Content-Type: text/html
X-Cache: MISS from Znncnn.com
X-Cache-Lookup: MISS from Znncnn.com:80
...145 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 92xiaohua.com
Referer: http://www.google.com/search?q=92xiaohua.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 92xiaohua.com
Referer: http://www.google.com/search?q=92xiaohua.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://92xiaohua.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 08 Jan 2015 19:34:43 GMT Location: http://www.442214.com/ Server: IIS Content-Length: 145 Content-Type: text/html X-Cache: MISS from Znncnn.com X-Cache-Lookup: MISS from Znncnn.com:80 | clean |
http://www.442214.com/ | HTTP/1.1 200 OK Connection: close Date: Thu, 08 Jan 2015 19:36:07 GMT Accept-Ranges: bytes ETag: "743ef616702bd01:356e" Server: IIS Content-Length: 34911 Content-Location: http://www.442214.com/index.html Content-Type: text/html Last-Modified: Thu, 08 Jan 2015 18:22:41 GMT Set-Cookie: safedog-flow-item=59ADEA175521CA6620FAB80B0F957C1D; expires=Dec, 14-Feb-2151 22:47:23 GMT; domain=442214.com; path=/ X-Cache: MISS from Znncnn.com X-Cache-Lookup: MISS from Znncnn.com:80 X-Powered-By: WAF/2.0 | clean |
http://www.442214.com/index.html | HTTP/1.1 200 OK Connection: close Date: Thu, 08 Jan 2015 19:36:11 GMT Accept-Ranges: bytes ETag: "743ef616702bd01:356e" Server: IIS Content-Length: 34911 Content-Location: http://www.442214.com/index.html Content-Type: text/html Last-Modified: Thu, 08 Jan 2015 18:22:41 GMT Set-Cookie: safedog-flow-item=59ADEA175521CA6620FAB80B0F957C1D; expires=Dec, 14-Feb-2151 22:47:27 GMT; domain=442214.com; path=/ X-Cache: MISS from Znncnn.com X-Cache-Lookup: MISS from Znncnn.com:80 X-Died: timeout at scan.pm line 1566. X-Powered-By: WAF/2.0 | clean |
http://www.442214.com/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |