Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=easyclass321.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://easyclass321.com/ | 200 OK Content-Length: 23584 Content-Type: text/html | malicious |
Malicious iFrame found. src: http://www.easyclass321.com/miaov_demo.html This URL is marked by Google as suspicious <iframe id="ad"frameborder=0 src="http://www.easyclass321.com/miaov_demo.html"> | ||
http://static.bshare.cn/b/buttonLite.js | 200 OK Content-Length: 20302 Content-Type: application/x-javascript | clean |
http://static.bshare.cn/b/bshareC0.js | 200 OK Content-Length: 4843 Content-Type: application/x-javascript | clean |
http://easyclass321.com/jiamengjiandanxuetang/ | HTTP/1.1 200 OK Date: Thu, 21 Aug 2014 16:25:31 GMT Accept-Ranges: bytes ETag: "f0fb20a98d9fcf1:eb13" Server: Microsoft-IIS/6.0 Content-Length: 18459 Content-Location: http://easyclass321.com/jiamengjiandanxuetang/index.html Content-Type: text/html Last-Modified: Mon, 14 Jul 2014 18:01:39 GMT X-Powered-By: ASP.NET | clean |
http://easyclass321.com/jiamengjiandanxuetang/index.html | 200 OK Content-Length: 18459 Content-Type: text/html | clean |
http://kxlogo.knet.cn/seallogo.dll?sn=e14062632030050601dns5000000&size=0 | 200 OK Content-Length: 0 | clean |
http://kxlogo.knet.cn/test404page.js | 404 Not Found Content-Length: 580 Content-Type: text/html | clean |
http://js.users.51.la/16414030.js | 200 OK Content-Length: 1980 Content-Type: application/x-javascript | clean |
http://v3.jiathis.com/code/jiathis_r.js?uid=1356602267674313&type=left&move=0&btn=l5.gif | 200 OK Content-Length: 19710 Content-Type: application/x-javascript | clean |
http://code.54kefu.net/kefu/js/45/347245.js | 200 OK Content-Length: 510 Content-Type: application/x-javascript | clean |
http://easyclass321.com/jiamengjiandanxuetang/wzessy_20140311.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://easyclass321.com/guankanshipin/ | HTTP/1.1 200 OK Date: Thu, 21 Aug 2014 16:25:43 GMT Accept-Ranges: bytes ETag: "2c155fec849fcf1:eb13" Server: Microsoft-IIS/6.0 Content-Length: 12735 Content-Location: http://easyclass321.com/guankanshipin/index.html Content-Type: text/html Last-Modified: Mon, 14 Jul 2014 16:59:06 GMT X-Powered-By: ASP.NET | clean |
http://easyclass321.com/guankanshipin/index.html | 200 OK Content-Length: 12735 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"24"},"share":{}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)]; Antivirus reports:
| ||
http://easyclass321.com/jingyanfenxiang/ | HTTP/1.1 200 OK Date: Thu, 21 Aug 2014 16:25:48 GMT Accept-Ranges: bytes ETag: "eaf192b99a2cf1:eb13" Server: Microsoft-IIS/6.0 Content-Length: 17599 Content-Location: http://easyclass321.com/jingyanfenxiang/index.html Content-Type: text/html Last-Modified: Fri, 18 Jul 2014 15:01:35 GMT X-Powered-By: ASP.NET | clean |
http://easyclass321.com/jingyanfenxiang/index.html | 200 OK Content-Length: 17599 Content-Type: text/html | clean |
http://easyclass321.com/jingyanfenxiang/wzessy_20140311.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://easyclass321.com/chenggonganli/ | HTTP/1.1 200 OK Date: Thu, 21 Aug 2014 16:25:54 GMT Accept-Ranges: bytes ETag: "e8aa7a13d79fcf1:eb13" Server: Microsoft-IIS/6.0 Content-Length: 21322 Content-Location: http://easyclass321.com/chenggonganli/index.html Content-Type: text/html Last-Modified: Tue, 15 Jul 2014 02:47:11 GMT X-Powered-By: ASP.NET | clean |
http://easyclass321.com/chenggonganli/index.html | 200 OK Content-Length: 21322 Content-Type: text/html | clean |
http://easyclass321.com/chenggonganli/wzessy_20140311.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: easyclass321.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 21 Aug 2014 16:25:28 GMT
Server: Microsoft-IIS/6.0
Content-Type: text/html; charset=gb2312
X-Died: timeout at scan.pm line 1546.
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: easyclass321.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 21 Aug 2014 16:25:28 GMT
Server: Microsoft-IIS/6.0
Content-Type: text/html; charset=gb2312
X-Died: timeout at scan.pm line 1546.
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: easyclass321.com
Referer: http://www.google.com/search?q=easyclass321.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: easyclass321.com
Referer: http://www.google.com/search?q=easyclass321.com
Result:
The result is similar to the first query. There are no suspicious redirects found.