Scanned pages/files
Request | Server response | Status |
http://www.dingkeke.com/ | 200 OK Content-Length: 10554 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://l.bst.126.net/rsc/htm/music.html <iframe style="display:none" src="http://l.bst.126.net/rsc/htm/music.html" > | ||
http://l.bst.126.net/rsc/js/jquery-1.6.2.min.js | 200 OK Content-Length: 91572 Content-Type: application/x-javascript | clean |
http://l.bst.126.net/rsc/js/themecommon.js?0005 | 200 OK Content-Length: 2224 Content-Type: application/x-javascript | clean |
http://analytics.163.com/ntes.js | 200 OK Content-Length: 19650 Content-Type: application/x-javascript | clean |
http://www.dingkeke.com/w866-ztg-xiaoguo | 200 OK Content-Length: 6854 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://l.bst.126.net/rsc/htm/music.html <iframe style="display:none" src="http://l.bst.126.net/rsc/htm/music.html" > | ||
http://l.bst.126.net/rsc/js/theme/r/pagephotoshow.min.js?0002 | 200 OK Content-Length: 54020 Content-Type: application/x-javascript | clean |
http://www.dingkeke.com/hengrui | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 19 Aug 2014 17:51:31 GMT Location: http://a920696629.148.net222-3.net Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 Set-Cookie: NTESLOFTSI=2C3B80BB5C68A0626CCE3AC81C66B9DA.lofter1-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Fcustompage.do%3Fmydomain%3Dwww.dingkeke.com%26%26url%3Dhengrui|; Domain=.lofter.com; Expires=Wed, 20-Aug-2014 17:51:31 GMT; Path=/ | clean |
http://a920696629.148.net222-3.net/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 19 Aug 2014 17:50:35 GMT Location: forum.php Server: Microsoft-IIS/6.0 Content-Type: text/html X-Powered-By: ASP.NET X-Powered-By: PHP/5.2.17 | clean |
http://a920696629.148.net222-3.net/forum.php | 200 OK Content-Length: 13040 Content-Type: text/html | clean |
http://a920696629.148.net222-3.net/static/js/common.js?g22 | 200 OK Content-Length: 69606 Content-Type: application/x-javascript | clean |
http://www.dingkeke.com/static/js/forum.js?g22 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 19 Aug 2014 17:51:42 GMT Location: http://www.lofter.com/mydomainr.do?domain=www.dingkeke.com&path=/static/js/forum.js?g22 Server: nginx Content-Length: 154 Content-Type: text/html | clean |
http://www.lofter.com/mydomainr.do?domain=www.dingkeke.com&path=/static/js/forum.js?g22 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 19 Aug 2014 17:51:43 GMT Location: http://dingkeke.lofter.com/static/js/forum.js?g22&mydomainr=true Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID" Set-Cookie: NTESLOFTSI=02B72A7111AEC81ADC07FBB6F2023419.lofter1-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Fmydomainr.do%3FX-From-ISP%3D2%26domain%3Dwww.dingkeke.com%26path%3D%2Fstatic%2Fjs%2Fforum.js%3Fg22|; Domain=.lofter.com; Expires=Wed, 20-Aug-2014 17:51:43 GMT; Path=/ Set-Cookie: usertrack=ezq0d1Pzjq9pzi4xCWduAg==; expires=Wed, 19-Aug-15 17:51:43 GMT; domain=lofter.com; path=/ | clean |
http://dingkeke.lofter.com/static/js/forum.js?g22&mydomainr=true | 404 Not Found Content-Length: 6262 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://l.bst.126.net/rsc/htm/music.html <iframe style="display:none" src="http://l.bst.126.net/rsc/htm/music.html" > | ||
http://dingkeke.lofter.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 19 Aug 2014 17:51:45 GMT Location: http://www.dingkeke.com Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID" Set-Cookie: NTESLOFTSI=6559AB05E481ED734FD5CDFC11D50B41.blog197-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Fblogindex.do%3FloftBlogName%3Ddingkeke%26X-From-ISP%3D2|; Domain=.lofter.com; Expires=Wed, 20-Aug-2014 17:51:45 GMT; Path=/ Set-Cookie: usertrack=ezq0d1PzjrFsl0iFChv3Ag==; expires=Wed, 19-Aug-15 17:51:45 GMT; domain=lofter.com; path=/ | clean |
http://www.dingkeke.com/test404page.js | 404 Not Found Content-Length: 6262 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://l.bst.126.net/rsc/htm/music.html <iframe style="display:none" src="http://l.bst.126.net/rsc/htm/music.html" > | ||
http://www.dingkeke.com/waimai | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 19 Aug 2014 17:51:48 GMT Location: http://a920696629.148.net222-3.net/forum.php?mod=viewthread&tid=19&extra=page%3D1 Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 Set-Cookie: NTESLOFTSI=9E6D09B5E5548B5D1A4F97043ED2BAB2.lofter1-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Fcustompage.do%3Fmydomain%3Dwww.dingkeke.com%26%26url%3Dwaimai|; Domain=.lofter.com; Expires=Wed, 20-Aug-2014 17:51:47 GMT; Path=/ | clean |
http://a920696629.148.net222-3.net/forum.php?mod=viewthread&tid=19&extra=page%3d1 | 200 OK Content-Length: 9634 Content-Type: text/html | clean |
http://a920696629.148.net222-3.net/static/js/forum.js?g22 | 200 OK Content-Length: 22508 Content-Type: application/x-javascript | clean |
http://www.dingkeke.com/static/js/logging.js?g22 | 404 Not Found Content-Length: 6262 Content-Type: text/html | suspicious |
Hidden iFrame found. style: hidden src: http://l.bst.126.net/rsc/htm/music.html <iframe style="display:none" src="http://l.bst.126.net/rsc/htm/music.html" > | ||
http://www.dingkeke.com/view | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 19 Aug 2014 17:51:59 GMT Location: http://www.lofter.com/mydomainr.do?domain=www.dingkeke.com&path=/view Server: nginx Content-Length: 154 Content-Type: text/html | clean |
http://www.lofter.com/mydomainr.do?domain=www.dingkeke.com&path=/view | HTTP/1.1 302 Moved Temporarily Connection: close Date: Tue, 19 Aug 2014 17:51:59 GMT Location: http://dingkeke.lofter.com/view?mydomainr=true Server: nginx Content-Length: 0 Content-Type: text/html;charset=UTF-8 P3P: policyref="/w3c/p3p.xml", CP="CUR ADM OUR NOR STA NID" Set-Cookie: NTESLOFTSI=3B95AF12999F75F0D0606102C16214CD.lofter13-8010; Domain=.www.lofter.com; Path=/ Set-Cookie: firstentry=%2Fmydomainr.do%3FX-From-ISP%3D2%26domain%3Dwww.dingkeke.com%26path%3D%2Fview|; Domain=.lofter.com; Expires=Wed, 20-Aug-2014 17:51:59 GMT; Path=/ Set-Cookie: usertrack=ezq0eFPzjr9sBUiICoJPAg==; expires=Wed, 19-Aug-15 17:51:59 GMT; domain=lofter.com; path=/ | clean |
http://dingkeke.lofter.com/view?mydomainr=true | 200 OK Content-Length: 49932 Content-Type: text/html | clean |
http://l.bst.126.net/s/core.js?45acab90441a072f8028dc846cd9e468 | 200 OK Content-Length: 85344 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: dingkeke.com
Result:
GET / HTTP/1.1
Host: dingkeke.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: dingkeke.com
Referer: http://www.google.com/search?q=dingkeke.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: dingkeke.com
Referer: http://www.google.com/search?q=dingkeke.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=dingkeke.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://dingkeke.com/
Result: dingkeke.com is not infected or malware details are not published yet.
Result: dingkeke.com is not infected or malware details are not published yet.