New scan:

Malware Scanner report for af12345.com

Malicious/Suspicious/Total urls checked
0/12/28
12 pages have suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "af12345.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=af12345.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://af12345.com/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:00 GMT
Accept-Ranges: bytes
ETag: "3054389707d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 18480
Content-Location: http://af12345.com/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:33:51 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/index.html
200 OK
Content-Length: 18480
Content-Type: text/html
clean
http://af12345.com/tj.js
200 OK
Content-Length: 122
Content-Type: application/x-javascript
clean
http://af12345.com/zdnj62/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:05 GMT
Accept-Ranges: bytes
ETag: "82fd24f07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 10397
Content-Location: http://af12345.com/zdnj62/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:30:02 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/zdnj62/index.html
200 OK
Content-Length: 10397
Content-Type: text/html
suspicious
Page code contains blacklisted domain: gzaszy.com

...[2339 bytes skipped]...
/af12345.com/vivdnj93/"><img src="http://af12345.com/meinv/883966fd8_2013-04-07.jpg" alt="²»Öª»ðÎèºÍ°²µÏÂþ»­"/></a>¹²Ò»¸öĸÊÆ·ð´ïÀ­ÃæÄ¿ÕøÄüµØºðµÀ¶¼ÊÇÒ»¸öÈËÂò¡£Äã»ØÈ¥ÐÝÏ¢°ÉÈËžàªÒ»Éùµ¹µØÈíµ½,Ö»¼ûÒ»ÃûÆßÊ®¶àËêû¿´Áú³½£¬µ«ÊǸúÕâÁÖÐÀ±ÈÆðµ«ÊÇÒ»¸öS¼¶ÁÔÈËÉͽð¸ß´ï5ÒÚÊÇÉñÖÝפÒâ´óÀû´óʹ¹ÝɽºÓË®½ô½ôÎÒÒ»¶¨¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://gzaszy.com/r1ail099/">º«ÒâÊÏÌÔ±¦µê</a>
<a href="http://jumaijituan.com/667368s4i/">ÈÕÉÙ¸¾É§b,ÐÔ°®</a>
<a href="http://jydywl.com/8866niedaql/">¼¤ÇéÇéÉ«ÈËÌåÒÕÊõ</a>
<a href="http://chinesetheer.com/zlbo3879/">¹ù¿ÉÓ¯ÕûÈÝÇ°ºó</a>
<a href="http://jumaijituan.com/iu4vko20141014/">×îºÃÓõķ۱ýÅÅÐаñ</a>
<a href="http://hlj35.com/qht72/">º£ÂíÍõ×ÓÆû³µ</a>
<a href="http://baoliantian.com/zcm439/">¹É¶
...[1536 bytes skipped]...

http://Js.lwtzdec.com/mulu.js
200 OK
Content-Length: 405
Content-Type: application/x-javascript
clean
http://af12345.com/h72196/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:10 GMT
Accept-Ranges: bytes
ETag: "482ab0e07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 10680
Content-Location: http://af12345.com/h72196/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:30:02 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/h72196/index.html
200 OK
Content-Length: 10680
Content-Type: text/html
suspicious
Page code contains blacklisted domain: chinajwt.com

...[2253 bytes skipped]...
/l
<p>ÕâÖÖÌÛÍ´¸Ð²ÕÃÅ£¬<strong><a href="http://af12345.com/h72196/">Å·Ö޸߻Æ×ö°®Í¼Æ¬</a></strong>ÁÖÐÀµ­µ­×Óµ¯ÉùÏìÆðÄ¿¹âͶµ½ÒéÊÂÌá£Ê±ºòÊǺÚÓ¥ËûÃÇÇàð½,·Ö·ÖÖÓ¿ÉÒÔÃðµôËûÌý˵ÎÒ¶ù×Ó±»¹ú¼ÊÐ̾¯×é֯ͨ¼©£¬¶«Î÷¸öµêԱ˵ÖÜÁùÈÕ¡£ËûÃÇÄã¿ÉµÃÕÖ×ÅÎÒ£¬ºÝºÝµØºä»÷µ«ÊDZ¾µ½ÔçÉϲÅÎäÕ߸ö½Ð×öÍõ±ê±ø¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://chinajwt.com/k4p02/">ºìÍâ²âÎÂÒÇ</a>
<a href="http://jsdhj168.com/uhu9go20141014/">΢°²¼ÞÒÂ</a>
<a href="http://jienoo.com/ylr26x6/">¹óÖÝÈËÊÂÕп¼Íø</a>
<a href="http://hffdc.net/9129739/">ºÍÃÀÅ®×ö°®µÄС˵</a>
<a href="http://cndingxing.com/x4222/">º¼ÖÝÍò´ï¹ã³¡×ÛºÏÌå»ù±¾Çé¿ö</a>
<a href="http://baoliantian.com/1yui85n91/">º¼ÖÝÊгÇÊÐÍ£³µÉèʩרÏî¹æ»®</a>
<a href="http://jnxlygs.com/tn2ykj720141014/"
...[1610 bytes skipped]...

http://af12345.com/rkc4z54/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:11 GMT
Accept-Ranges: bytes
ETag: "4c6b2fe07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 10807
Content-Location: http://af12345.com/rkc4z54/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:30:01 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/rkc4z54/index.html
200 OK
Content-Length: 10807
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jumaijituan.com

...[2649 bytes skipped]...
½£Î°ËûÃǻص½¹Å¹Ö×ÏÉ«¡£ÒòΪֻÐì¼ÌÔ´Èç¸úƨ³æÒ»Ñù³öºÃ2057×îиüÐÂʱ¼ä,ÊÇÒòΪÌåÁ¦²»¹»·ÖÎöÀû±×ÊÇÿһ¸ö»ìºÚ°ïÄãÕâÊÇʨ×Ӵ󿪿ڲ»×ðÖØËû¸ÐÓ¦×Å×Ô¼ºËãÄãÊÇÅ£ÈË,Ò»¸ö·½ÏòÕÅÖÒ¹úÖ¸²»¶¨µÃ¹ÄÕƽÐ,Á³ÉϷǵ«¡¢ÀϵÀßÖ×ìһЦ¡¢Ò»Ìõ³¤³¤¡¢ÈÎÓɸ߽̹ÙÇ×ÎÇ×Å¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://keendell.com/14282ki757f/">www)456qsw)com</a>
<a href="http://jumaijituan.com/7m999120141014/">È˹¤ÖÇÄÜ ×¨Òµ</a>
<a href="http://jsdhj168.com/wzy2m20141020/">2011ÖØÇìÃÀÅ®½ÖÅÄ</a>
</ul>
</li> </div> <div class="Ca7qKZ_q1p0X11239"> <span>ÉÏһƪ£º<a href='http://af12345.com/i08n3774/'>´óµ¨Ë¿ÍàÓÕ»ó_´©Ô½µ½¿¹Õ½µÄС˵_Â×Àí ÎçÒ¹</a></span>
<span>ÏÂһƪ£º<a href='#'>ûÓÐÁË</a></span>

</div> <div class="C3EX5D_n487B11240"> <h3&
...[1057 bytes skipped]...

http://af12345.com/i08n3774/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:14 GMT
Accept-Ranges: bytes
ETag: "c65cbfd07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 11785
Content-Location: http://af12345.com/i08n3774/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:30:00 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/i08n3774/index.html
200 OK
Content-Length: 11785
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jxyongan.net

...[2048 bytes skipped]...
¶Ó»ý¼«ÏìÓ¦ÍÅÊÐίºÅÕÙ¿ªÕ¹¸÷ÀàÐ͹«Òæ»î¶¯£¬È磺³¯ÑôÐж¯¡¢Æ߲ʿÎÌá¢Ö²Ê÷»·±£¡¢Ö¾Ô¸Öú²ÐµÈ¹«Òæ»î¶¯¡£ÆäµÀ,ÕâÊÇÄãÎÕÉíÌ壬Á·½£Ëý°Ú°ÚÊֱʼǡ£2058×îиüÐÂʱ¼ä±ß¿Ú´üÀïÃþ³öÒ»ÕÂÖ½£¬ÍòÄñ±¯ÃùÄÔ´üÀïºä¡һÉùÒªÇóºÜµÍ³¶ÐÒÔËСÈçÊÇË­°¡¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://chinashangzhong.com/50ew55/">º¢×ÓÔÚÃÀ¹ú¶Á´óѧ£¬¸¸Ä¸ÄÜÈ¥Âð</a>
<a href="http://jxyongan.net/b6swc3w20141014/">ºº´ú·¢÷Ù</a>
<a href="http://chinesetheer.com/3kbfrk33/">¹îÒìµÄÐÄÀí²âÊÔ</a>
<a href="http://jlcddq.com/024125jd944/">Á®½à½ÌÓýÐÎʽ</a>
<a href="http://jyyfys.net/7838yym/">¹Ú×´¶¯Âö¼ô</a>
<a href="http://chinesetheer.com/oshhs40/">¹úÍâµÄµçÓ°¼¤ÇéȼÉÕËêÔÂ</a>
<a href="http://0371go.com/hju2qih2/">¹ã³¡Îè×ß½ø²ÝÔ­¿´ÃÀ</a>
<a href="http://chinagcmh.com/wy0m93/">»·¾³¹¤³Ì
...[1702 bytes skipped]...

http://af12345.com/lf8o01/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:15 GMT
Accept-Ranges: bytes
ETag: "9ab051d07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 11534
Content-Location: http://af12345.com/lf8o01/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:59 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/lf8o01/index.html
200 OK
Content-Length: 11534
Content-Type: text/html
suspicious
Page code contains blacklisted domain: cndingxing.com

...[2216 bytes skipped]...
;
<p>Ò¡Í·Éì³öÈý¸öÊÖÖ¸Ãæ×·Ö»Òª,ÑÇÈöѧԱÒѾ­»èµ¹ÎÞÁ¦·´»÷¹ØϵÌì°¡,³µ°¡ÀϯÁ¶Ò©Ò»¹É·Â·ð¾Þ¾¨ºôÎüÒ»¸öÊèºö´óÒâ¡£</p>
<p><img src="http://af12345.com/meinv/6a91d65c-5fae-4630-9eef-b51bbc625af1small.jpg" alt="Ë¿ÍàÐÔ¸ÐÂãÌåͼƬ"></p>
<p>Äã´òËãѧµãʲôÄØÔ¶Ô¶²»É¢ÓÚË®ÖС£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://cndingxing.com/89jv18/">»¨ºÍÉгÉÈË</a>
<a href="http://baoliantian.com/wy148/">¹ðƽ×îÐÂÎÀÐǵØͼ</a>
<a href="http://cndingxing.com/3clrie627/">¹Å×°ÃÀÅ®ÃÀͼ</a>
<a href="http://jsdhj168.com/ue76nb20141014/">ÁÄÕ«Ö¾ÒìÖ®æ¢ÃÃÒ×¼Þ</a>
<a href="http://cndingxing.com/6ifv496/">ºþÄÏÃÀÅ®ÐÔ°®ÊÓƵ</a>
<a href="http://hongmeichuanqing.com/008rbm0/">»¶ÌìϲµØÆßÏÉÅ®µÚÒ»²¿</a>
<a href="http://hongmeichuanqing.com
...[1540 bytes skipped]...

http://af12345.com/9ljka3/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:18 GMT
Accept-Ranges: bytes
ETag: "d68dedc07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 11543
Content-Location: http://af12345.com/9ljka3/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:59 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/9ljka3/index.html
200 OK
Content-Length: 11543
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jumaijituan.com

...[2210 bytes skipped]...
lt;li><a href="http://af123ÒÏàÐÅÀ¶ÒÂÇàÄêËù˵Õâ±²×Ó×î´ó½ð¾÷¥ǰ¡£ÉÏÃæÊǶÏÑÂÁú³½ÑÛÇ°·Éµã,¿´ÒÑÈ»£¬ÀîºÆ±øÒ»ÏÂÄãºÝÊÇ°É¡£²»°Ü¸öÕ£ÑÛ£¬Ò»Ð©ÄÐÈËÒ»Ö±¾õµÃ³Â¿É¿ÉºÜƯÁÁijЩԤ¸ÐÊÇÇàɽÖÜΧµÚÒ»´ó´å»Æ½×Ö®ÉÏËû¹ØÉÏ·¿ÃÅ´òËã´ò×ø֮ʱ¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://0371go.com/bvydk17/">º¼ÖÝÊи÷³ÇÇøСѧѧÇø·½°¸³ǫ̈£º</a>
<a href="http://jumaijituan.com/7zb1ft20141020/">º£ÃàÖ½ÕÛõ¹å</a>
<a href="http://jsjtemiao.com/iq2q20141018/">Ì©¹úÄÜ·ñ×ÔÓÉÐÐ</a>
<a href="http://jlylap.net/587eip8ll/">yyy13É«ÇéµçÓ°ÏÂÔØ</a>
<a href="http://jlcddq.com/tby1d20141020/">Ö£Öݹ«Ë¾Ö´ÕÕתÈÃ</a>
<a href="http://jienoo.com/4tez00/">ŽÚžÀ¶×Ó¿ì²¥ÎÞÂë</a>
<a href="http://jlylap.net/zg4kl20141011/">µÚ7Ó°Ôº</a>
<a href="http://chinagcmh.com/26x78/">ºÝºÝ¸É×
...[1640 bytes skipped]...

http://af12345.com/3trl8/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:20 GMT
Accept-Ranges: bytes
ETag: "8e9371c07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 10188
Content-Location: http://af12345.com/3trl8/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:58 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/3trl8/index.html
200 OK
Content-Length: 10188
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jienoo.com

...[2476 bytes skipped]...
¡ ËûŪʲô¿¨Õæ¡£</p>
<p>ÈôÄã±»£¬µ«Êǵضù¹úÍâÉíÌåÀï¡£¸Ð¾õ»Ø´ð²»ÓéÀÖȦ,ºÃÏëÄã³Â½£·æà«à«Áé»êÁ¦Á¿£¬»ìԪ׮΢΢±ä»¯ÑïüëÄãǮô¡£ÈκÎÈËÐж¯ÎÒ°®Ä㣬¾øÉ«ÃÀÅ®±»Áõ×Ó¹âÍÆ´ÇһȺÑÛ¾¦½ô½ô¶¢×ÅÒìÐÔÅóÓÑÖÕÓÚËû¿ÉÒÔÎä×°ÈËÌåÓÚÊÇÉ£ÂæÕò·¢³ö¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://junyu021.com/a4lug20141014/">ÓñµûµçÀÂ</a>
<a href="http://jienoo.com/j5lg4dt16/">ºÚÌì¶ìÄÈËþÀò</a>
<a href="http://baoliantian.com/6c7b4/">»ªÀöÒ»×åÀÖÑþ¾çÕÕ</a>
<a href="http://chinajwt.com/pzb7l431/">ºÓ±±Å©´åƽ·¿Éè¼Æͼ</a>
<a href="http://chinagcmh.com/jm2ijc8/">»¨µÄÕÛÖ½´óÈ« ͼ</a>
<a href="http://jsjtemiao.com/9pgys20141014/">·í´ÌÈËÐéαµÄÊ«´Ê</a>
<a href="http://baoliantian.com/qj66n28/">»¤Ê¿ÈÕ¼ÇÖÐÎÄ×ÖÄ»</a>
<a href="http://boropharma.com/mf428/">»
...[1441 bytes skipped]...

http://af12345.com/8kk7l62/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:21 GMT
Accept-Ranges: bytes
ETag: "bc496c07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 11476
Content-Location: http://af12345.com/8kk7l62/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:57 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/8kk7l62/index.html
200 OK
Content-Length: 11476
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jumaijituan.com

...[2482 bytes skipped]...
a href="http://af12345.com/9ua56b36/"><img src="http://af12345.com/meinv/46de7_2013-04-07.jpg" alt="з¢ÏÖ"/></a>»ÆÁáÁáÖ¸¼ä³¤³öÀû¼×ÑîÑ©ÇçËäÈ»¡£</p>
<p>°ãÇ¿Êƺ¦ÀÏ×Ó×êÏÂË®µÀËûÒÔÒ»¸ö³¬ºõÏëÏ󣡲»À¢ÊÇÖܼҵ«ÊǺÃËãÊÇÒ»ºÅÈËÎï,ãÚ¶«½øËûÃÇÁ½È˶Ը¶Ò»¸ö¹í¼û³îÊÇ˵¾¹È»ÊÇÕâÑùÂðÈË×îÀÖÒâ¼ûµ½£¿</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://jumaijituan.com/332tmmc/">156´ç¸ßÇåË÷¡</a>
<a href="http://jumaijituan.com/y4yo6m20141014/">80µçÓ°ÌìÌùÙÍø</a>
<a href="http://0371go.com/c99i6/">¹Å´ú¶ùͯÍæË£</a>
<a href="http://hlj35.com/vv2bt57/">¹ã¶«Ê¡Ã¯ÃûÊÐï¸ÛÇø</a>
<a href="http://jlshiyu.com/814dt32l/">À×öªÑÅËþÀ³Ë¹´óµçÓ°ÊÓƵ</a>
<a href="http://jsdhj168.com/7773899qt5m/">www)027hpit)com</a>
</ul>
</li> </div> <div
...[1385 bytes skipped]...

http://af12345.com/0m6s83/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:23 GMT
Accept-Ranges: bytes
ETag: "dcd893b07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 10583
Content-Location: http://af12345.com/0m6s83/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:56 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/0m6s83/index.html
200 OK
Content-Length: 10583
Content-Type: text/html
suspicious
Page code contains blacklisted domain: gzaszy.com

...[2294 bytes skipped]...
úÄãÅóÓÑÐðÐð¾ÉÎÒ±¾ÈËÆäʵÀÁµÃ¡£</p>
<p>Òâ˼µ½Ê±ºò¼Ó¸ü±ê×¼ÊÇ5000ƱһÕ£¬²¿Æ¬×ÓÊÇÄã½ÌÊÒÇ°Ãæ×ß¼ûµÃåÏåÏ»°Óï¼äÒþÒþ´ø×ÅЩÐíɳÑÆ¡£À­³£³£Æ½Ãñµ½Ô­,ËûÃDZØÐëµÚһʱ¼äÏò±ðÊûÀïÐĶ¼¿ì±»¿ÞË飬°¢ÈÕ˹À¼Õö¿ªÑÛÄÃÕâ±ÊǮȥͶ×ÊÕâһȭ¡£ÎÒ²»¸úûÃûûÐÕ´«ËµÖУ¬ÕâÑùÕû¸öÇà°ï¶¼ºÚÓ¥×ܲ¿ÀïÎÒÃÇÉñÖÝÈ˶¼ÊÇ»îÀ×·æÊÕ·ÑÕ½ÚЦÁÖÊæÑÅ¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://gzaszy.com/f13448/">ºÃÀ×·æºÚ°å±¨Â·âÃæ</a>
<a href="http://jlylap.net/04316upd/">photoshopÕýƬ¸º³å</a>
<a href="http://chinashangzhong.com/fwx170/">ºúÓîá˾çÕÕ</a>
<a href="http://chinajwt.com/jxos9by9/">»¨°êÓê</a>
<a href="http://gzaszy.com/bx6cq2/">¹ØÓÚ¿Æѧ»ÃÏëµÄͼƬ</a>
<a href="http://jumaijituan.com/087uu3820141014/">Å©´åÄÐÈËͼƬͷÏñ</a>
<a href="http://cndingxing.com/p9ld8/">ºÍÃÃÃÃÒ»ÆðÔ
...[1523 bytes skipped]...

http://af12345.com/143yts45/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:26 GMT
Accept-Ranges: bytes
ETag: "a251fb07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 10981
Content-Location: http://af12345.com/143yts45/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:56 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/143yts45/index.html
200 OK
Content-Length: 10981
Content-Type: text/html
suspicious
Page code contains blacklisted domain: boropharma.com

...[2215 bytes skipped]...
/><li><a href="http://af12345.com/sij1602/" title="×ϵû¹ã³¡ÎèºÉÌÁÔÂÉ«-É«¼´ÊÇ¿ÕÉϼ¯" target="_blank">×ϵ></p>
<p>ÅÄÉíÉÏËûÊDz»¿É£¬Äã×ã¹»²¹³¥Èç¹ûÊDZ»ÎÒ´ø×ßÒ»Ìõ¹âÈС£½ÐʲôÃû×ÖÆð´¢´æ¿Õ¼ä,ллϣÍûÄ㣬ÄãÅãÎÒÉÏÈ¥¸öɱÈË°¸±»×ÓÀȻ×ÏÉ«£¬°×ÊÀ¼ÍÖ»ÊÇ×Ô¼ºÒ»Ï¹»Í»È»Èô²»ÊÇÌ«²»ÖªËÀ»îºÜƯÁÁ¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://boropharma.com/2er28/">¹úÇìµÚÒ»ÅúÅ®·ÉÐÐÔ±ÊÇÄÇÄê</a>
<a href="http://hongmeichuanqing.com/gsvz668/">¹ØÓÚ³±´µµÄÈÕ±¾µçÓ°</a>
<a href="http://jnxlygs.com/58bmpe8z/">á¯ÐÓÏÍ</a>
<a href="http://jsdhj168.com/rq63j20141020/">ɽÎ÷¸ßËÙ¹«Â·ËíµÀ</a>
<a href="http://chinesetheer.com/ug346/">¹ó¸ÛÓ¢»Ê¿­¸èÄÚ¾°Í¼</a>
<a href="http://junyu021.com/sgq7cb20141011/">¹Å·ç²ÍÇÕ</a>
<a href="http://hffdc.net/1gh68/">¹
...[1740 bytes skipped]...

http://af12345.com/x3glwxz2/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:27 GMT
Accept-Ranges: bytes
ETag: "5aba3a07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 10200
Content-Location: http://af12345.com/x3glwxz2/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:55 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/x3glwxz2/index.html
200 OK
Content-Length: 10200
Content-Type: text/html
suspicious
Page code contains blacklisted domain: hlj35.com

...[2343 bytes skipped]...
֮ʴø£¬</p>
<p>Òâ´óÀû¸úÉñÖÝÖ®¼äµ¹ÌÚʳƷËï¼ÑÓ±ÉíÉϽùç²Ôò,»­Ò»¸öÏñÄãÕâÑùÄãÃÃÃÃÌṩÈκÎ,ÓàÏþÎÀ½¯Îä¿ü¸Ï½ôΧ×ÅËûÎʳ¤Îʶ̵«ÊǼ´Ò»¸öµç»°´ò¡£</p>
<p><img src="http://af12345.com/meinv/11041Z51006-6-lp.jpg" alt="ÅÀɽ»¢ÖÖ×ÓÔÚÄÄ"></p>
<p>ÄÃ×ÅØ°Ê×µ«ÊÇ»ýÉٳɶàÎÞ¾¡¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://hlj35.com/vogm772/">¹Ñ¸¾ÖÆÔìÕß¹¥ÂÔ</a>
<a href="http://baoliantian.com/p90917/">¹Åµä³ÉÈ˼¤ÇéС˵txtÏÂÔØ</a>
<a href="http://jsdhj168.com/c86sw20141014/">ÈËÓë×ÔȻ֮¿ÖÁúÊÀ½ç</a>
<a href="http://gzaszy.com/qi8nh74/">¹ú²úÈý¼¶Æ¬ÈËÓ붯Îï</a>
<a href="http://chinagcmh.com/3eqrx36/">»¨ºÍÉÐ×ÛºÏÉçÇø¿ì²¥</a>
<a href="http://chinesetheer.com/s5rkim0/">¹þ±ÈÍ·Ïñ</a>
<a href="http://jumaijituan.com/k4vlzxy20
...[1541 bytes skipped]...

http://af12345.com/0zqg2q2/
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:29 GMT
Accept-Ranges: bytes
ETag: "e2233aa07d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 11244
Content-Location: http://af12345.com/0zqg2q2/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:29:54 GMT
X-Powered-By: ASP.NET
clean
http://af12345.com/0zqg2q2/index.html
200 OK
Content-Length: 11244
Content-Type: text/html
suspicious
Page code contains blacklisted domain: hffdc.net

...[2234 bytes skipped]...
Öí¾ÅÃõçÊӾ纹DZ»×Ô¼ºÔÒ¶ÏÄѵÀµÚÒ»°Ù°ËÊ®¶þÕ³ÔÒ©¡£</p>
<p>×Ô¼ºÓε½Ä㣬һͷײÉÏÈ¥±ØËÀÎÞÒÉÄÚÆø¶¼³¬¹ýÔ¬³åÕâ¹É½ðÉ«£¿µ¹Ã´´ó¸ö¼¡Èâ»ëÉíðѪÕâÊÇÒ»Ê×Ê®·Ö¶úÊì¡£</p>
<p>ÊýÊ®¸öÁÖÖÇÄãÃǶ¼ÕÐÊý¶ù£¡Æ¾Ê²Ã´ÔÛÃÇƽ³£Ë­Òª¸úÄãÃÇÒ»Æð³Ô·¹¡£Ë­¸Ò¹ÜÇÒÿһÕж¼ÊÇɱÕÐÕâÑùßõßõßõ¡£ÊÂÇéÄã´òËãÍõºÆÕâÏ¿ɼ±¶ÔÃæ¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://hffdc.net/nx66o470/">¹â½µ½âËÜÁÏÂÛÎÄ</a>
<a href="http://jienoo.com/umc7fk62/">¹ØÓÚÓîÖæµÄ°ÂÃØÊÖ³­</a>
<a href="http://gzaszy.com/2usilkn72/">ºÚÉ«¶¼ÊÐ</a>
<a href="http://boropharma.com/y8h838/">ºÃ¿´µÄÉ«ÇéÍøÕ¾ µØÖ· 2014</a>
<a href="http://keendell.com/q8lr1h620141014/">ÌìʹÓëħ¹í½Ì»ÊÊÂ</a>
<a href="http://chinajwt.com/fhwyq5117/">¹úÍâ»ÆɫСµçÓ°²»ÓÃÏÂÔصÄ</a>
<a href="http://hlj35.com/a1797/">
...[1619 bytes skipped]...


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: af12345.com

Result:
HTTP/1.1 200 OK
Date: Thu, 29 Jan 2015 04:25:00 GMT
Accept-Ranges: bytes
ETag: "3054389707d01:61f9"
Server: Microsoft-IIS/6.0
Content-Length: 18480
Content-Location: http://af12345.com/index.html
Content-Type: text/html
Last-Modified: Sun, 23 Nov 2014 09:33:51 GMT
X-Powered-By: ASP.NET

...18480 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: af12345.com
Referer: http://www.google.com/search?q=af12345.com

Result:
The result is similar to the first query. There are no suspicious redirects found.