Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=consung.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.consung.net/ | 200 OK Content-Length: 47026 Content-Type: text/html | malicious |
Page code contains blacklisted domain: exploitgoogl.0xhost.net.exploitgoogl.0xhost.net <meta http-equiv="Content-Type" content="text/html; charset=GB2312" /> <titleÊÀ½ç±£¬°Ù¼ÒÀÖ,ÕæÈË°Ù¼ÒÀÖ,·ÆÂɱöÌ«Ñô³Ç,Ì«Ñô³ÇÓéÀÖ³Ç,bet365ÓéÀÖ³Ç,°Ù¼ÒÀÖ,°ÄÃÅ°Ù¼ÒÀÖ,Ì«Ñô³Ç,»Ê¹ÚÏÖ½ðÍø,TT ÓéÀÖ³Ç,ÐÂÆϾ©ÓéÀÖ³Ç,ÓéÀÖ³Ç×¢²á,°Ù¼ÒÀÖ¿ª»§,»Ê¹ÚÍø,»Ê¹ÚÏÖ½ðÍø,»Ê¹ÚÍøÖ·,»Ê¹Ú´úÀí,ȫѶÍø</title> <meta name="Keywords" content="ÊÀ½ç±£¬°Ù¼ÒÀÖ,ÕæÈË°Ù¼ÒÀÖ,·ÆÂɱöÌ«Ñô³Ç,Ì«Ñô³ÇÓéÀÖ³Ç,bet365ÓéÀÖ³Ç,°Ù¼ÒÀÖ,°ÄÃÅ°Ù ¼ÒÀÖ,Ì«Ñô³Ç,»Ê¹ÚÏÖ½ðÍø,TTÓéÀÖ³Ç,ÐÂÆϾ©ÓéÀÖ ...[4184 bytes skipped]... Malicious iFrame found. size: 0x0 src: http://shellmsf.0xhost.net/boke/index.php?mod=member&referer=%3f This URL is marked by Google as suspicious <iframe src=http://shellmsf.0xhost.net/boke/index.php?mod=member&referer=%3f width=0 height=0> Malicious iFrame found. size: 0x0 src: http://exploitgoogl.0xhost.net.exploitgoogl.0xhost.net This URL is marked by Google as suspicious <iframe src=http://exploitgoogl.0xhost.net.exploitgoogl.0xhost.net width=0 height=0> | ||
http://baijiale.0xhost.net/g.js | HTTP/1.1 302 Found Connection: close Date: Wed, 28 Jan 2015 21:15:40 GMT Age: 0 Location: http://suspended.0xhost.net/index.php?host=baijiale.0xhost.net Server: ATS/4.2.1 Content-Length: 336 Content-Type: text/html; charset=iso-8859-1 | clean |
http://suspended.0xhost.net/index.php?host=baijiale.0xhost.net | HTTP/1.1 200 OK Date: Wed, 28 Jan 2015 21:15:13 GMT Accept-Ranges: bytes ETag: "07f5122f824d01:0" Server: Microsoft-IIS/7.5 Content-Length: 1269 Content-Type: text/html Last-Modified: Wed, 31 Dec 2014 12:48:54 GMT | clean |
http://suspended.0xhost.net/zm9yy2vtug | HTTP/1.1 200 OK Date: Wed, 28 Jan 2015 21:15:38 GMT Accept-Ranges: bytes ETag: "07f5122f824d01:0" Server: Microsoft-IIS/7.5 Content-Length: 1269 Content-Type: text/html Last-Modified: Wed, 31 Dec 2014 12:48:54 GMT | clean |
http://suspended.0xhost.net/test404page.js | HTTP/1.1 200 OK Date: Wed, 28 Jan 2015 21:15:50 GMT Accept-Ranges: bytes ETag: "07f5122f824d01:0" Server: Microsoft-IIS/7.5 Content-Length: 1269 Content-Type: text/html Last-Modified: Wed, 31 Dec 2014 12:48:54 GMT | clean |
http://baijiale.0xhost.net/b.js | HTTP/1.1 302 Found Connection: close Date: Wed, 28 Jan 2015 21:15:42 GMT Age: 0 Location: http://suspended.0xhost.net/index.php?host=baijiale.0xhost.net Server: ATS/4.2.1 Content-Length: 336 Content-Type: text/html; charset=iso-8859-1 | clean |
http://baijiale.0xhost.net/baijiale.js | HTTP/1.1 302 Found Connection: close Date: Wed, 28 Jan 2015 21:15:42 GMT Age: 0 Location: http://suspended.0xhost.net/index.php?host=baijiale.0xhost.net Server: ATS/4.2.1 Content-Length: 336 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.consung.net/base/js/base.js | 200 OK Content-Length: 31131 Content-Type: application/x-javascript | clean |
http://www.consung.net/base/js/common.js | 200 OK Content-Length: 10754 Content-Type: application/x-javascript | clean |
http://www.consung.net/base/js/form.js | 200 OK Content-Length: 16332 Content-Type: application/x-javascript | clean |
http://www.consung.net/base/js/blockui.js | 200 OK Content-Length: 12587 Content-Type: application/x-javascript | clean |
http://www.consung.net/advs/js/advsheadlb.js | 200 OK Content-Length: 702 Content-Type: application/x-javascript | clean |
http://www.consung.net/menu/js/channelmenu_6.js | 200 OK Content-Length: 722 Content-Type: application/x-javascript | clean |
http://www.consung.net/search/js/searchform.js | 200 OK Content-Length: 663 Content-Type: application/x-javascript | clean |
http://shellmsf.0xhost.net/go.js | HTTP/1.1 200 OK Date: Wed, 28 Jan 2015 21:15:57 GMT Accept-Ranges: bytes ETag: "07f5122f824d01:0" Server: Microsoft-IIS/7.5 Content-Length: 1269 Content-Type: text/html Last-Modified: Wed, 31 Dec 2014 12:48:54 GMT | clean |
http://shellmsf.0xhost.net/zm9yy2vtug | HTTP/1.1 200 OK Date: Wed, 28 Jan 2015 21:15:32 GMT Accept-Ranges: bytes ETag: "07f5122f824d01:0" Server: Microsoft-IIS/7.5 Content-Length: 1269 Content-Type: text/html Last-Modified: Wed, 31 Dec 2014 12:48:54 GMT | clean |
http://js.users.51.la/439714.js | 200 OK Content-Length: 1879 Content-Type: application/x-javascript | clean |
http://count7.51yes.com/click.aspx?id=78397509&logo=1 | 200 OK Content-Length: 1773 Content-Type: text/html | clean |
http://baijiale.0xhost.net/2014.js | HTTP/1.1 302 Found Connection: close Date: Wed, 28 Jan 2015 21:15:55 GMT Age: 0 Location: http://suspended.0xhost.net/index.php?host=baijiale.0xhost.net Server: ATS/4.2.1 Content-Length: 336 Content-Type: text/html; charset=iso-8859-1 | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: consung.net
Result:
GET / HTTP/1.1
Host: consung.net
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: consung.net
Referer: http://www.google.com/search?q=consung.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: consung.net
Referer: http://www.google.com/search?q=consung.net
Result:
The result is similar to the first query. There are no suspicious redirects found.