Scanned pages/files
Request | Server response | Status |
http://artis-likai.7958.com/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Sat, 12 Apr 2014 08:59:36 GMT Location: http://www.7958.com/404.html Server: Microsoft-IIS/6.0 Content-Type: text/html; charset=utf-8 Set-Cookie: VFgM_cd62_saltkey=fKR4rKRz; expires=Mon, 12-May-2014 08:59:35 GMT; path=/; domain=.7958.com; httponly Set-Cookie: VFgM_cd62_lastvisit=1397289575; expires=Mon, 12-May-2014 08:59:35 GMT; path=/; domain=.7958.com Set-Cookie: VFgM_cd62_sid=D90OlO; expires=Sun, 13-Apr-2014 08:59:35 GMT; path=/; domain=.7958.com Set-Cookie: VFgM_cd62_lastact=1397293175%09index.php%09; expires=Sun, 13-Apr-2014 08:59:35 GMT; path=/; domain=.7958.com X-Powered-By: PHP/5.2.17 | clean |
http://www.7958.com/404.html | HTTP/1.1 200 OK Connection: close Date: Sat, 12 Apr 2014 08:59:37 GMT Server: nginx Vary: Accept-Encoding Content-Type: text/html; charset=utf-8 Set-Cookie: VFgM_cd62_saltkey=a5g2qV3d; expires=Mon, 12-May-2014 08:59:36 GMT; path=/; domain=.7958.com; httponly Set-Cookie: VFgM_cd62_lastvisit=1397289576; expires=Mon, 12-May-2014 08:59:36 GMT; path=/; domain=.7958.com | clean |
http://www.7958.com/ | 200 OK Content-Length: 32389 Content-Type: text/html | clean |
http://img1.7958.com/static/disk/js/jquery-1.8.2.min.js | 200 OK Content-Length: 93436 Content-Type: application/x-javascript | clean |
http://img1.7958.com/static/disk/js/jquery.tipsy.js | 200 OK Content-Length: 14903 Content-Type: application/x-javascript | clean |
http://js.adm.cnzz.net/js/abase.js | 200 OK Content-Length: 21394 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function FixedRealShow(){return document.body?(this.init.apply(this,arguments),void 0):!1}(function(window){function FnRegister(e,t){return w[e]||(w[e]=t)}function parseParams(e){var t=map[e];return t?{id:e||e,af:t.af||!1,did:t.aid||0,slotType:t.stype,isbefore:t.pop||0,htmlcode:t._html||0,width:t._w||0,height:t._h||0,stime:1e3*t.time||5e3,ptime:1e3*t.parktime||0,loadtime:1e3*t.loadtime||0,closePosition:t.cb||0,scroll:t.sc||0,position:t.pos||0,mleft:t._m_left||0,mtop:t._m_top||0,ip:t.ip||"",isifr Antivirus reports:
| ||
http://img1.7958.com/static/disk/js/top1.js?109 | 200 OK Content-Length: 6119 Content-Type: application/x-javascript | clean |
http://img1.7958.com/static/disk/js/sesame.js | 200 OK Content-Length: 46550 Content-Type: application/x-javascript | clean |
http://www.cnzz.com/js/slider.js | 200 OK Content-Length: 4302 Content-Type: application/javascript | clean |
http://www.7958.net/api.php?mod=js&bid=114 | 200 OK Content-Length: 1032 Content-Type: text/html | clean |
http://www.7958.net/forum.php?mod=viewthread&tid=348796 | 200 OK Content-Length: 60929 Content-Type: text/html | clean |
http://www.7958.net/static/js/common.js?MYJ | 200 OK Content-Length: 21634 Content-Type: application/x-javascript | clean |
http://www.7958.net/static/js/forum.js?MYJ | 200 OK Content-Length: 22145 Content-Type: application/x-javascript | clean |
http://www.7958.net/static/js/logging.js?MYJ | 200 OK Content-Length: 603 Content-Type: application/x-javascript | clean |
http://js.adm.cnzz.net/s.php?sid=225639 | 200 OK Content-Length: 3677 Content-Type: application/x-javascript | clean |
http://cpro.baidustatic.com/cpro/ui/c.js | 200 OK Content-Length: 36000 Content-Type: application/x-javascript | clean |
http://www.7958.net/static/js/forum_viewthread.js?MYJ | 200 OK Content-Length: 26476 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: artis-likai.7958.com
Result:
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sat, 12 Apr 2014 08:59:36 GMT
Location: http://www.7958.com/404.html
Server: Microsoft-IIS/6.0
Content-Type: text/html; charset=utf-8
Set-Cookie: VFgM_cd62_saltkey=fKR4rKRz; expires=Mon, 12-May-2014 08:59:35 GMT; path=/; domain=.7958.com; httponly
Set-Cookie: VFgM_cd62_lastvisit=1397289575; expires=Mon, 12-May-2014 08:59:35 GMT; path=/; domain=.7958.com
Set-Cookie: VFgM_cd62_sid=D90OlO; expires=Sun, 13-Apr-2014 08:59:35 GMT; path=/; domain=.7958.com
Set-Cookie: VFgM_cd62_lastact=1397293175%09index.php%09; expires=Sun, 13-Apr-2014 08:59:35 GMT; path=/; domain=.7958.com
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: artis-likai.7958.com
Result:
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Sat, 12 Apr 2014 08:59:36 GMT
Location: http://www.7958.com/404.html
Server: Microsoft-IIS/6.0
Content-Type: text/html; charset=utf-8
Set-Cookie: VFgM_cd62_saltkey=fKR4rKRz; expires=Mon, 12-May-2014 08:59:35 GMT; path=/; domain=.7958.com; httponly
Set-Cookie: VFgM_cd62_lastvisit=1397289575; expires=Mon, 12-May-2014 08:59:35 GMT; path=/; domain=.7958.com
Set-Cookie: VFgM_cd62_sid=D90OlO; expires=Sun, 13-Apr-2014 08:59:35 GMT; path=/; domain=.7958.com
Set-Cookie: VFgM_cd62_lastact=1397293175%09index.php%09; expires=Sun, 13-Apr-2014 08:59:35 GMT; path=/; domain=.7958.com
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: artis-likai.7958.com
Referer: http://www.google.com/search?q=artis-likai.7958.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: artis-likai.7958.com
Referer: http://www.google.com/search?q=artis-likai.7958.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=artis-likai.7958.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://artis-likai.7958.com/
Result: artis-likai.7958.com is not infected or malware details are not published yet.
Result: artis-likai.7958.com is not infected or malware details are not published yet.