Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=aaron.fansju.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://aaron.fansju.com/ | HTTP/1.1 301 Moved Permanently Date: Sat, 28 Feb 2015 03:17:16 GMT Location: forum.php Server: Microsoft-IIS/6.0 Content-Length: 0 Content-Type: text/html X-Powered-By: ASP.NET X-Powered-By: PHP/5.3.8 | clean |
http://aaron.fansju.com/forum.php | 200 OK Content-Length: 58996 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.aaronyan.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gbk" /> <title>Ñ×ÑÇÂÚ¹ú¶È|²¼¶¡ÍÅ|Ñ×ÑÇÂÚ¼Ò×å - Powered by Discuz!</title> <meta name="keywords" content="Ñ×ÑÇÂÚ¼ÍÄîÈÕ,¼ÍÄîÈÕ¶©¹º,Ñ×ÑÇÂÚÐÂÎÅ,Ñ×ÑÇÂÚ΢²©,Ñ×Ñ ...[4119 bytes skipped]... | ||
http://aaron.fansju.com/static/js/common.js?tXD | 200 OK Content-Length: 69459 Content-Type: application/x-javascript | clean |
http://aaron.fansju.com/static/js/forum.js?tXD | 200 OK Content-Length: 22720 Content-Type: application/x-javascript | clean |
http://aaron.fansju.com/static/js/logging.js?tXD | 200 OK Content-Length: 603 Content-Type: application/x-javascript | clean |
http://cpro.baidustatic.com/cpro/ui/c.js | 200 OK Content-Length: 83863 Content-Type: application/x-javascript | clean |
http://js.users.51.la/5705.js | 200 OK Content-Length: 1908 Content-Type: application/x-javascript | clean |
http://tcss.qq.com/ping.js?v=1tXD | 200 OK Content-Length: 8909 Content-Type: application/x-javascript | clean |
http://aaron.fansju.com/home.php?mod=misc&ac=sendmail&rand=1425093437 | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
http://discuz.gtimg.cn/cloud/scripts/discuz_tips.js?v=1 | 200 OK Content-Length: 6173 Content-Type: application/x-javascript | clean |
http://aaron.fansju.com/plugin.php?id=wulin_jianghu:wlzb | 200 OK Content-Length: 13987 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.aaronyan.com ...[1778 bytes skipped]... ion-uri=http://aaron.fansju.com/forum.php;icon-uri=http://aaron.fansju.com/template/comiis_lssy/comiis_pic/bbs.ico" /> </head> <body id="nv_plugin" class="pg_CURMODULE" onkeydown="if(event.keyCode==27) return false;"> <div id="append_parent"></div><div id="ajaxwaitid"></div> <div id="toptb" class="cl"> <div class="wp"> <div class="z"><a href="http://www.aaronyan.com/" onclick="addFavorite(this.href, 'Ñ×ÑÇÂÚ¹ú target="_blank">ÑÇÂÚ¹ú¶È²¼¶¡ÍÅ</a>(www.aaronyan.com) °æȨËùÓÐ All Rights Reserved.<br /> ÁªÏµ²Ë²Ë£ºQQ£º38237 <script src="http://js.users.51.la/5705.js" type="text/javascript"></script> <noscript><a href="http://www.51.la/?5705" target="_blank"><img alt="我要啦免费统计" src="http://img.users.51.la/5705.asp" style="bo ...[1962 bytes skipped]... | ||
http://aaron.fansju.com/home.php?mod=misc&ac=sendmail&rand=1425093449 | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
http://aaron.fansju.com/member.php?mod=register | 200 OK Content-Length: 24395 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.aaronyan.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gbk" /> <title>¼ÓÈë¹ú¶È - Ñ×ÑÇÂÚ¹ú¶È - Powered by Discuz!</title> <meta name="keywords" content="" /> <meta name="description" content=",Ñ×ÑÇ ...[4187 bytes skipped]... | ||
http://aaron.fansju.com/static/js/register.js?tXD | 200 OK Content-Length: 8422 Content-Type: application/x-javascript | clean |
http://aaron.fansju.com/home.php?mod=misc&ac=sendmail&rand=1425093450 | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
http://aaron.fansju.com/connect.php?mod=login&op=init&referer=http%3A%2F%2Faaron.fansju.com%2F.%2F&statfrom=login_simple | HTTP/1.1 302 Moved Temporarily Date: Sat, 28 Feb 2015 03:17:38 GMT Location: https://graph.qq.com/oauth2.0/authorize?response_type=code&client_id=10004283&redirect_uri=http%3A%2F%2Faaron.fansju.com%2Fconnect.php%3Fmod%3Dlogin%26op%3Dcallback%26referer%3Dhttp%253A%252F%252Faaron.fansju.com%252F.%252F&state=95684a497a9ecd55181f69d58833ed31&scope=get_user_info%2Cadd_share%2Cadd_t%2Cadd_pic_t%2Cget_repost_list Server: Microsoft-IIS/6.0 Content-Length: 0 Content-Type: text/html; charset=gbk Set-Cookie: LKso_2132_saltkey=zq8q7mzL; expires=Mon, 30-Mar-2015 03:17:38 GMT; path=/; httponly Set-Cookie: LKso_2132_lastvisit=1425089858; expires=Mon, 30-Mar-2015 03:17:38 GMT; path=/ Set-Cookie: LKso_2132_sid=k6u6J7; expires=Sun, 01-Mar-2015 03:17:38 GMT; path=/ Set-Cookie: LKso_2132_lastact=1425093458%09connect.php%09login; expires=Sun, 01-Mar-2015 03:17:38 GMT; path=/ Set-Cookie: LKso_2132_stats_qc_reg=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Set-Cookie: LKso_2132_cloudstatpost=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/ Set-Cookie: LKso_2132_con_request_uri=http%3A%2F%2Faaron.fansju.com%2Fconnect.php%3Fmod%3Dlogin%26op%3Dcallback%26referer%3Dhttp%253A%252F%252Faaron.fansju.com%252F.%252F; path=/ X-Powered-By: ASP.NET X-Powered-By: PHP/5.3.8 | clean |
https://graph.qq.com/oauth2.0/authorize?response_type=code&client_id=10004283&redirect_uri=http%3a%2f%2faaron.fansju.com%2fconnect.php%3fmod%3dlogin%26op%3dcallback%26referer%3dhttp%253a%252f%252faaron.fansju.com%252f.%252f&state=95684a497a9ecd55181f69d58833ed31&scope=get_user_info%2cadd_share%2cadd_t%2cadd_pic_t%2cget_repost_list | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sat, 28 Feb 2015 03:15:50 GMT Location: http://openapi.qzone.qq.com/oauth/show?which=error&display=pc&error=100010&response_type=code&client_id=10004283&redirect_uri=http%3a%2f%2faaron.fansju.com%2fconnect.php%3fmod%3dlogin%26op%3dcallback%26referer%3dhttp%253a%252f%252faaron.fansju.com%252f.%252f&state=95684a497a9ecd55181f69d58833ed31&scope=get_user_info%2cadd_share%2cadd_t%2cadd_pic_t%2cget_repost_list Server: tws Content-Length: 0 Content-Type: text/html | clean |
http://openapi.qzone.qq.com/oauth/show?which=error&display=pc&error=100010&response_type=code&client_id=10004283&redirect_uri=http%3a%2f%2faaron.fansju.com%2fconnect.php%3fmod%3dlogin%26op%3dcallback%26referer%3dhttp%253a%252f%252faaron.fansju.com%252f.%252f&state=95684a497a9ecd55181f69d58833ed31&scope=get_user_info%2cadd_share%2cadd_t%2cadd_pic_t%2cget_repost_list | 200 OK Content-Length: 5601 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.aaronyan.com ...[3430 bytes skipped]... ent.write('<script src="http://tajs.qq.com/stats?sId=36511985" charset="UTF-8"><\/script>'); </script> <!--@fragment_bottom End --> <script> // PCé误页æå é Q.monitor(302300); // support论åé»è¾ var feed_back_link = document.getElementById("feed_back_link_err"); var dmRe = /http:\/\/([^/]*)\/?/i; window.crtDomain = 'http://www.aaronyan.com/' || (Q.getParameter && Q.getParameter("redirect_uri")); var errcode = '100010'; var dmHost = window.crtDomain.match(dmRe); if(feed_back_link) { feed_back_link.href += ("&SSTAG="+encodeURIComponent((dmHost&&dmHost[1])+".errorcode"+errcode)); } var t = +new Date() - Q.getParameter('auth_time'); // ææ失败 Q.mta('LoginFailed', {Appid: Q.appid, Ext1: Q.getParameter('error' ...[332 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: aaron.fansju.com
Result:
HTTP/1.1 301 Moved Permanently
Date: Sat, 28 Feb 2015 03:17:16 GMT
Location: forum.php
Server: Microsoft-IIS/6.0
Content-Length: 0
Content-Type: text/html
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.3.8
...0 bytes of data.
GET / HTTP/1.1
Host: aaron.fansju.com
Result:
HTTP/1.1 301 Moved Permanently
Date: Sat, 28 Feb 2015 03:17:16 GMT
Location: forum.php
Server: Microsoft-IIS/6.0
Content-Length: 0
Content-Type: text/html
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.3.8
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: aaron.fansju.com
Referer: http://www.google.com/search?q=aaron.fansju.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: aaron.fansju.com
Referer: http://www.google.com/search?q=aaron.fansju.com
Result:
The result is similar to the first query. There are no suspicious redirects found.