Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=9emeinv.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.9emeinv.com/ | 200 OK Content-Length: 17875 Content-Type: text/html | clean |
http://www.9emeinv.com/templets/default/image/focus.js | 200 OK Content-Length: 9667 Content-Type: text/html | clean |
http://www.9emeinv.com/test404page.js | 200 OK Content-Length: 9667 Content-Type: text/html | clean |
http://ad.9emeinv.com/tj.js | 200 OK Content-Length: 14698 Content-Type: application/x-javascript | suspicious |
Page code contains blacklisted domain: www.jsmbaidu.com var random = {
ad_num : 8, init : function(){ n = (Math.floor(Math.random()*random.ad_num+1)); switch(n){ case 1: document.write('<script type="text/javascript">u_a_client="3758";u_a_width="0";u_a_height="0";u_a_zones="5600";u_a_type="1";<\/script><script src="http://www.jsmbaidu.com/i.js"><\/script>'); document.writeln("<\script src='http://t.ku63.com/t.asp?u=50128&t=3&m=4&n=' charset='gb2312'><\/script>"); document.writeln("<\script src='http://f.ku63.com/f.asp?u=50128&m=0&n=' charset='gb2312'><\/script>"); document.writeln("<\script src='http://f.ku63.com/f.asp?u=50128&m=3&n=&w=1000' charset='gb2312'><\/script>" ...[16371 bytes skipped]... | ||
http://ad.9emeinv.com/468_60.js | 200 OK Content-Length: 9078 Content-Type: application/x-javascript | clean |
http://ad.9emeinv.com/960_90.js | 200 OK Content-Length: 13508 Content-Type: application/x-javascript | clean |
http://www.9emeinv.com/plus/autoseo/auto.js | 200 OK Content-Length: 9667 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 9emeinv.com
Result:
GET / HTTP/1.1
Host: 9emeinv.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: 9emeinv.com
Referer: http://www.google.com/search?q=9emeinv.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 9emeinv.com
Referer: http://www.google.com/search?q=9emeinv.com
Result:
The result is similar to the first query. There are no suspicious redirects found.