Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=flower.x9.eu
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://flower.x9.eu/
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as SMS-fraud resource. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://flower.x9.eu/ | 200 OK Content-Length: 15230 Content-Type: text/html | clean |
http://flower.x9.eu/jquery.min.js | 200 OK Content-Length: 78766 Content-Type: application/javascript | clean |
http://flower.x9.eu/galleria.js | 200 OK Content-Length: 113377 Content-Type: application/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21241 Content-Type: text/javascript | clean |
http://flower.x9.eu/QqSFSRAyMw | 200 OK Content-Length: 31116 Content-Type: application/javascript | suspicious |
Page code contains blacklisted domain: x9.eu ...[1577 bytes skipped]... ngth==2 && resolution[0] > 860 && resolution[1] > 350) || (resolution && resolution.length==2 && resolution[0] == 0 && resolution[1] == 0) || resolution == undefined ) { var check = f5448ee8daabd76b3696bf0974e55748(); var _gaq = []; _gaq.push(['_setAccount', 'UA-35990445-6']); _gaq.push(['_setDomainName', 'flower.x9.eu']); _gaq.push(['_setCustomVar', 1, 'bereich', 'Webspace', 3]); _gaq.push(['_setCustomVar', 2, 'Domain', 'x9.eu', 3]); _gaq.push(['_setCustomVar', 5, 'Subdomain', 'flower.x9.eu', 3]); _gaq.push(['_setCustomVar', 3, 'ausgabe1', 'BinLayer (HybridAd)', 3]); _gaq.push(['_setCustomVar', 4, 'Domain-Target', 'x9.eu', 3]); _gaq.push(['_gat._anonymizeIp']); _gaq.push(['_trackPageview']); (function() { var ga = document.createElement('script ...[29466 bytes skipped]... | ||
http://flower.x9.eu/four-o-clocks-flowers.html | 200 OK Content-Length: 12987 Content-Type: text/html | clean |
http://flower.x9.eu/real-mexican-homemade-flower-tortillas-recipe.html | 200 OK Content-Length: 14639 Content-Type: text/html | clean |
http://flower.x9.eu/flower-pot-cookies.html | 200 OK Content-Length: 14185 Content-Type: text/html | clean |
http://flower.x9.eu/flowers-in-scotland.html | 200 OK Content-Length: 12971 Content-Type: text/html | clean |
http://flower.x9.eu/hippie-flower-car-decals.html | 200 OK Content-Length: 13573 Content-Type: text/html | clean |
http://flower.x9.eu/flower-power-apiary-grand-forks.html | 200 OK Content-Length: 14474 Content-Type: text/html | clean |
http://flower.x9.eu/flowers-for-mothers-day.html | 200 OK Content-Length: 14281 Content-Type: text/html | clean |
http://flower.x9.eu/japanese-flower-mushroom.html | 200 OK Content-Length: 13848 Content-Type: text/html | clean |
http://flower.x9.eu/flower-and-gift-delivery-zaporozhye.html | 200 OK Content-Length: 12861 Content-Type: text/html | clean |
http://flower.x9.eu/overseas-flower-del.html | 200 OK Content-Length: 13286 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: flower.x9.eu
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 13 Jul 2014 19:33:10 GMT
Accept-Ranges: bytes
ETag: "d7e67fae-3af2-49fd5ccdd3640"
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Last-Modified: Fri, 01 Apr 2011 06:48:40 GMT
GET / HTTP/1.1
Host: flower.x9.eu
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 13 Jul 2014 19:33:10 GMT
Accept-Ranges: bytes
ETag: "d7e67fae-3af2-49fd5ccdd3640"
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
Last-Modified: Fri, 01 Apr 2011 06:48:40 GMT
Second query (visit from search engine):
GET / HTTP/1.1
Host: flower.x9.eu
Referer: http://www.google.com/search?q=flower.x9.eu
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: flower.x9.eu
Referer: http://www.google.com/search?q=flower.x9.eu
Result:
The result is similar to the first query. There are no suspicious redirects found.