Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bbs.ssyzj.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://bbs.ssyzj.com/ | 200 OK Content-Length: 120899 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"1","bdSize":"16"},"share":{}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)]; Antivirus reports:
| ||
http://bbs.ssyzj.com/static/js/common.js?Vj6 | 200 OK Content-Length: 21530 Content-Type: application/x-javascript | clean |
http://bbs.ssyzj.com/static/js/forum.js?Vj6 | 200 OK Content-Length: 22720 Content-Type: application/x-javascript | clean |
http://j.cloudid.anquanbao.com/t.js?ver=2015-01-11 | 200 OK Content-Length: 5631 Content-Type: application/x-javascript | clean |
http://bbs.ssyzj.com/static/js/logging.js?Vj6 | 200 OK Content-Length: 603 Content-Type: application/x-javascript | clean |
http://bbs.ssyzj.com/static/js/md5.js?Vj6 | 200 OK Content-Length: 5734 Content-Type: application/x-javascript | clean |
http://cpro.baidustatic.com/cpro/ui/c.js | 200 OK Content-Length: 83590 Content-Type: application/x-javascript | clean |
http://bbs.ssyzj.com/source/plugin/study_nge/template/default/js/common.js?Vj6 | 200 OK Content-Length: 5706 Content-Type: application/x-javascript | clean |
http://js.union.doudouguo.com/cpro.js | 200 OK Content-Length: 4834 Content-Type: application/x-javascript | suspicious |
Hidden iFrame found. size: 0x0 src: http://qiqu.bjjhdz.com/x/app/76_522.htm?uid= <iframe src="http://qiqu.bjjhdz.com/x/app/76_522.htm?uid=' + window.ddgu_uid + '" width="0" height="0" frameborder="0" scrolling="no"> Hidden iFrame found. size: 0x0 src: http://qiqu.bjjhdz.com/x/app/76_522.htm?uid= <iframe src="http://qiqu.bjjhdz.com/x/app/76_522.htm?uid=' + window.ddgu_uid + '&zoneid=' + window.ddgu_zid + '" width="0" height="0" frameborder="0" scrolling="no"> | ||
http://tcss.qq.com/ping.js?v=1Vj6 | 200 OK Content-Length: 8909 Content-Type: application/x-javascript | clean |
http://js.users.51.la/14847556.js | 200 OK Content-Length: 1980 Content-Type: application/x-javascript | clean |
http://s25.cnzz.com/stat.php?id=5065260&web_id=5065260&show=pic1 | 200 OK Content-Length: 10076 Content-Type: application/javascript | clean |
http://bbs.ssyzj.com/home.php?mod=misc&ac=sendmail&rand=1420909990 | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://bbs.ssyzj.com/test404page.js | 404 Not Found Content-Length: 4008 Content-Type: text/html | clean |
http://bbs.ssyzj.com/aqb_cc/error/js/jquery-1.8.js | 200 OK Content-Length: 67837 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bbs.ssyzj.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, private, post-check=0, pre-check=0, max-age=0
Connection: close
Date: Sat, 10 Jan 2015 17:13:20 GMT
Pragma: no-cache
Server: ASERVER/1.2.9-3
Content-Type: text/html; charset=gbk
Expires: -1
Set-Cookie: rcnV_abc4_saltkey=i05ms318; expires=Mon, 09-Feb-2015 17:13:10 GMT; path=/; domain=ssyzj.com; httponly
Set-Cookie: rcnV_abc4_lastvisit=1420906390; expires=Mon, 09-Feb-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_sid=mYRvPP; expires=Sun, 11-Jan-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_lastact=1420909990%09index.php%09; expires=Sun, 11-Jan-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_stats_qc_reg=deleted; expires=Fri, 10-Jan-2014 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_cloudstatpost=deleted; expires=Fri, 10-Jan-2014 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_onlineusernum=54; expires=Sat, 10-Jan-2015 17:18:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_sid=mYRvPP; expires=Sun, 11-Jan-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: _D_SID=5F0BC86F; path=/;
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.17
X-Powered-By-Anquanbao: MISS from chn-wh-tc-se3
GET / HTTP/1.1
Host: bbs.ssyzj.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, private, post-check=0, pre-check=0, max-age=0
Connection: close
Date: Sat, 10 Jan 2015 17:13:20 GMT
Pragma: no-cache
Server: ASERVER/1.2.9-3
Content-Type: text/html; charset=gbk
Expires: -1
Set-Cookie: rcnV_abc4_saltkey=i05ms318; expires=Mon, 09-Feb-2015 17:13:10 GMT; path=/; domain=ssyzj.com; httponly
Set-Cookie: rcnV_abc4_lastvisit=1420906390; expires=Mon, 09-Feb-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_sid=mYRvPP; expires=Sun, 11-Jan-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_lastact=1420909990%09index.php%09; expires=Sun, 11-Jan-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_stats_qc_reg=deleted; expires=Fri, 10-Jan-2014 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_cloudstatpost=deleted; expires=Fri, 10-Jan-2014 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_onlineusernum=54; expires=Sat, 10-Jan-2015 17:18:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: rcnV_abc4_sid=mYRvPP; expires=Sun, 11-Jan-2015 17:13:10 GMT; path=/; domain=ssyzj.com
Set-Cookie: _D_SID=5F0BC86F; path=/;
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.17
X-Powered-By-Anquanbao: MISS from chn-wh-tc-se3
Second query (visit from search engine):
GET / HTTP/1.1
Host: bbs.ssyzj.com
Referer: http://www.google.com/search?q=bbs.ssyzj.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bbs.ssyzj.com
Referer: http://www.google.com/search?q=bbs.ssyzj.com
Result:
The result is similar to the first query. There are no suspicious redirects found.