Scanned pages/files
Request | Server response | Status |
http://www.cheyuan168.com/content/ | 404 Not Found Content-Length: 9286 Content-Type: text/html | clean |
http://mat1.gtimg.com/www/js/mininav/mininavjs1.3_min.js | 200 OK Content-Length: 9352 Content-Type: application/x-javascript | clean |
http://qzonestyle.gtimg.cn/qzone_v6/lostchild/data.js | 200 OK Content-Length: 10186 Content-Type: application/x-javascript | clean |
http://mat1.gtimg.com/www/austin/xr/babygh_v1.0.2.js | 200 OK Content-Length: 1967 Content-Type: application/x-javascript | clean |
http://mat1.gtimg.com/www/austin/xr/babygh_iShare_v1.0.1.js | 200 OK Content-Length: 16073 Content-Type: application/x-javascript | clean |
http://pingjs.qq.com/pingV3_1_2.js | 200 OK Content-Length: 15162 Content-Type: application/x-javascript | clean |
http://www.cheyuan168.com/forum.php | 200 OK Content-Length: 68769 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"16"},"slide":{"type":"slide","bdImg":"0","bdPos":"right","bdTop":"73.5"}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)]; Antivirus reports:
| ||
http://www.cheyuan168.com/data/cache/common.js?zi3 | 200 OK Content-Length: 18124 Content-Type: application/x-javascript | clean |
http://www.cheyuan168.com/data/cache/forum.js?zi3 | 200 OK Content-Length: 6317 Content-Type: application/x-javascript | clean |
http://www.cheyuan168.com/data/cache/logging.js?zi3 | 200 OK Content-Length: 390 Content-Type: application/x-javascript | clean |
http://www.cheyuan168.com/data/cache/md5.js?zi3 | 200 OK Content-Length: 1637 Content-Type: application/x-javascript | clean |
http://www.cheyuan168.com/source/plugin/mo_weibo_dzx/mo_weibo_dzx.js | 200 OK Content-Length: 719 Content-Type: application/x-javascript | clean |
http://images.sohu.com/cs/jsfile/js/l.js | 200 OK Content-Length: 45411 Content-Type: application/x-javascript | clean |
http://api.ichaotu.com/widget/sign?v=1.0&detect=1&t=widget&&i=kx_8E&s=discuzX3.1&site=http://www.cheyuan168.com/ | 200 OK Content-Length: 144 Content-Type: text/html | clean |
http://statics.ichaotu.com/widget/TujoinSign/sign.js?t=widget&i=kx_8E&detect=1 | 200 OK Content-Length: 4036 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cheyuan168.com
Result:
GET / HTTP/1.1
Host: cheyuan168.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: cheyuan168.com
Referer: http://www.google.com/search?q=cheyuan168.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cheyuan168.com
Referer: http://www.google.com/search?q=cheyuan168.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=cheyuan168.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://cheyuan168.com/
Result: cheyuan168.com is not infected or malware details are not published yet.
Result: cheyuan168.com is not infected or malware details are not published yet.