Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=docin8.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://docin8.com/ | 200 OK Content-Length: 8873 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.1docin.com ...[4056 bytes skipped]... ttp://www.docin8.com <script language="javascript" type="text/javascript" src="http://js.users.51.la/5929978.js"></script></div> <div class="foot">ÓÑÇéÁ´½Ó£º<a href="http://wenku.baidu.com" target="_blank">°Ù¶ÈÎÄ¿â</a> <a href="http://www.docin.com" target="_blank">¶¹¶¡Íø</a> <a href="http://www.doc88.com" target="_blank">µÀ¿Í°Í°Í</a> <a href="http://www.1docin.com" target="_blank">¶¹¶¡ÎÄ¿â</a> <a href="http://www.jiemuwang.com" target="_blank">½ÚÄ¿Íø</a> <a href="http://www.xunlei5.com" target="_blank">µçÓ°ÌìÌÃ</a></div><script src="http://j.77power.com/adscpv/i.php?z=55239"></script><script src='http://j.77power.com/i.php?z=77121'></script><script src="http://p1.1lo0.net/code/popjs.asp?pid=104625" charset="gb2312"></script><script src="http://f1.1lo0.net ...[152 bytes skipped]... | ||
http://docin8.com/file/js/js.js | HTTP/1.1 200 OK Date: Tue, 03 Mar 2015 14:00:03 GMT Accept-Ranges: bytes ETag: "0dde7340ccce1:1824" Server: Microsoft-IIS/6.0 Content-Length: 3803 Content-Location: http://docin8.com/file/js/js.js Content-Type: application/x-javascript Last-Modified: Fri, 18 Oct 2013 12:47:30 GMT X-Powered-By: ASP.NET | clean |
http://docin8.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://images.sohu.com/cs/jsfile/js/l.js | 200 OK Content-Length: 48514 Content-Type: application/x-javascript | clean |
http://js.users.51.la/5929978.js | 200 OK Content-Length: 1945 Content-Type: application/x-javascript | clean |
http://j.77power.com/adscpv/i.php?z=55239 | 200 OK Content-Length: 2449 Content-Type: text/html | clean |
http://j.77power.com/i.php?z=77121 | 200 OK Content-Length: 1759 Content-Type: text/html | clean |
http://p1.1lo0.net/code/popjs.asp?pid=104625 | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://f1.1lo0.net/code/pop_cpf.asp?pid=104626 | 200 OK Content-Length: 36 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: docin8.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Tue, 03 Mar 2015 14:00:01 GMT
Server: Microsoft-IIS/6.0
Content-Length: 8873
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCDTQATS=KFFECDNCJFJLAKHHNIPHLNDP; path=/
X-Powered-By: ASP.NET
...8873 bytes of data.
GET / HTTP/1.1
Host: docin8.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Tue, 03 Mar 2015 14:00:01 GMT
Server: Microsoft-IIS/6.0
Content-Length: 8873
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQCDTQATS=KFFECDNCJFJLAKHHNIPHLNDP; path=/
X-Powered-By: ASP.NET
...8873 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: docin8.com
Referer: http://www.google.com/search?q=docin8.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: docin8.com
Referer: http://www.google.com/search?q=docin8.com
Result:
The result is similar to the first query. There are no suspicious redirects found.