Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bbs.longhuixian.com
Result:
HTTP/1.1 200 OK
Date: Mon, 06 Jul 2015 21:00:24 GMT
Server: IIS
Content-Length: 50344
Content-Type: text/html; charset=gbk
Set-Cookie: 9fZV_9a99_saltkey=DHOzlIUq; expires=Wed, 05-Aug-2015 21:00:23 GMT; path=/; domain=.longhuixian.com; httponly
Set-Cookie: 9fZV_9a99_lastvisit=1436212823; expires=Wed, 05-Aug-2015 21:00:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_sid=OEy4k8; expires=Tue, 07-Jul-2015 21:00:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_lastact=1436216423%09index.php%09; expires=Tue, 07-Jul-2015 21:00:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_stats_qc_reg=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_cloudstatpost=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_onlineusernum=2; expires=Mon, 06-Jul-2015 21:05:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: safedog-flow-item=F5CE010AE18B0913DCC051222BE3591E; expires=Tue, 7-Jul-2015 16:00:24 GMT; domain=longhuixian.com; path=/
X-Powered-By: WAF/2.0
X-Powered-By: WAF/2.0
...50344 bytes of data.
GET / HTTP/1.1
Host: bbs.longhuixian.com
Result:
HTTP/1.1 200 OK
Date: Mon, 06 Jul 2015 21:00:24 GMT
Server: IIS
Content-Length: 50344
Content-Type: text/html; charset=gbk
Set-Cookie: 9fZV_9a99_saltkey=DHOzlIUq; expires=Wed, 05-Aug-2015 21:00:23 GMT; path=/; domain=.longhuixian.com; httponly
Set-Cookie: 9fZV_9a99_lastvisit=1436212823; expires=Wed, 05-Aug-2015 21:00:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_sid=OEy4k8; expires=Tue, 07-Jul-2015 21:00:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_lastact=1436216423%09index.php%09; expires=Tue, 07-Jul-2015 21:00:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_stats_qc_reg=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_cloudstatpost=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT; path=/; domain=.longhuixian.com
Set-Cookie: 9fZV_9a99_onlineusernum=2; expires=Mon, 06-Jul-2015 21:05:23 GMT; path=/; domain=.longhuixian.com
Set-Cookie: safedog-flow-item=F5CE010AE18B0913DCC051222BE3591E; expires=Tue, 7-Jul-2015 16:00:24 GMT; domain=longhuixian.com; path=/
X-Powered-By: WAF/2.0
X-Powered-By: WAF/2.0
...50344 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: bbs.longhuixian.com
Referer: http://www.google.com/search?q=bbs.longhuixian.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bbs.longhuixian.com
Referer: http://www.google.com/search?q=bbs.longhuixian.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://bbs.longhuixian.com/ | 200 OK Content-Length: 50344 Content-Type: text/html | clean |
http://bbs.longhuixian.com/template/xinleng2015/image/js/jquery.js | 200 OK Content-Length: 94692 Content-Type: application/x-javascript | clean |
http://bbs.longhuixian.com/data/cache/common.js?FVj | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://bbs.longhuixian.com/test404page.js | 200 OK Content-Length: 3174 Content-Type: text/html | clean |
http://bbs.longhuixian.com/data/cache/forum.js?FVj | 200 OK Content-Length: 19423 Content-Type: application/x-javascript | clean |
http://bbs.longhuixian.com/template/xinleng2015/image/js/hdsc.js | 200 OK Content-Length: 1933 Content-Type: application/x-javascript | clean |
http://s84.cnzz.com/stat.php?id=4617656&web_id=4617656&show=pic1 | 200 OK Content-Length: 10057 Content-Type: application/javascript | clean |
http://bbs.longhuixian.com/home.php?mod=misc&ac=sendmail&rand=1436216423 | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
http://discuz.gtimg.cn/cloud/scripts/discuz_tips.js?v=1 | 200 OK Content-Length: 6173 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bbs.longhuixian.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bbs.longhuixian.com/
Result: bbs.longhuixian.com is not infected or malware details are not published yet.
Result: bbs.longhuixian.com is not infected or malware details are not published yet.