Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bbs.myecust.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://bbs.myecust.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bbs.myecust.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 07 Oct 2014 01:58:26 GMT
Server: lighttpd/1.4.34
Content-Type: text/html
Set-Cookie: 81f50_lastvisit=0%091412647106%09%2Findex.php; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_lastpos=index; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_lastvisit=0%091412647106%09%2Findex.php; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_ol_offset=39263; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_ci=index%091412647106%09%09; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: bbs.myecust.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 07 Oct 2014 01:58:26 GMT
Server: lighttpd/1.4.34
Content-Type: text/html
Set-Cookie: 81f50_lastvisit=0%091412647106%09%2Findex.php; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_lastpos=index; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_lastvisit=0%091412647106%09%2Findex.php; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_ol_offset=39263; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
Set-Cookie: 81f50_ci=index%091412647106%09%09; expires=Wed, 07-Oct-2015 01:58:26 GMT; path=/; domain=.myecust.com
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: bbs.myecust.com
Referer: http://www.google.com/search?q=bbs.myecust.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bbs.myecust.com
Referer: http://www.google.com/search?q=bbs.myecust.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://bbs.myecust.com/ | 200 OK Content-Length: 85874 Content-Type: text/html | clean |
http://bbs.myecust.com/js/core/core.js | 200 OK Content-Length: 24162 Content-Type: text/javascript | clean |
http://bbs.myecust.com/js/pw_ajax.js | 200 OK Content-Length: 12569 Content-Type: text/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21308 Content-Type: text/javascript | clean |
http://app.phpwind.net/static/js/client.js | 200 OK Content-Length: 13698 Content-Type: application/x-javascript | clean |
http://bbs.myecust.com/js/Deploy.js | 200 OK Content-Length: 1912 Content-Type: text/javascript | clean |
http://bbs.myecust.com/js/global.js | 200 OK Content-Length: 48541 Content-Type: text/javascript | clean |
http://bbs.myecust.com/mode/area/js/adminview.js | 200 OK Content-Length: 12222 Content-Type: text/javascript | clean |
http://bbs.myecust.com/js/app_global.js | 200 OK Content-Length: 9414 Content-Type: text/javascript | clean |
http://bbs.myecust.com/hack.php?H_name=jifen | 500 Internal Server Error Content-Length: 47358 Content-Type: text/html | clean |
http://bbs.myecust.com/profile.php?action=toolcenter | 200 OK Content-Length: 32117 Content-Type: text/html | clean |
http://bbs.myecust.com/sendpwd.php | 200 OK Content-Length: 30327 Content-Type: text/html | clean |
http://bbs.myecust.com/test404page.js | 404 Not Found Content-Length: 345 Content-Type: text/html | clean |
http://bbs.myecust.com/hack.php?H_name=bank | 200 OK Content-Length: 32113 Content-Type: text/html | clean |
http://bbs.myecust.com/hack.php?H_name=medal | 200 OK Content-Length: 54862 Content-Type: text/html | clean |