Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=her38.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: her38.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Tue, 27 Jan 2015 03:10:57 GMT
Server: Microsoft-IIS/6.0
Content-Length: 34330
Content-Type: text/html; Charset=UTF-8
Set-Cookie: ASPSESSIONIDASBDDACT=GOFPCHOCPDCHKALJFEFPGCOK; path=/
X-Powered-By: ASP.NET
...34330 bytes of data.
GET / HTTP/1.1
Host: her38.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Tue, 27 Jan 2015 03:10:57 GMT
Server: Microsoft-IIS/6.0
Content-Length: 34330
Content-Type: text/html; Charset=UTF-8
Set-Cookie: ASPSESSIONIDASBDDACT=GOFPCHOCPDCHKALJFEFPGCOK; path=/
X-Powered-By: ASP.NET
...34330 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: her38.com
Referer: http://www.google.com/search?q=her38.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: her38.com
Referer: http://www.google.com/search?q=her38.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://her38.com/ | 200 OK Content-Length: 34330 Content-Type: text/html | clean |
http://www.her38.com/themes/Sean_Cms/SCRIPT/common.js | 200 OK Content-Length: 51585 Content-Type: application/x-javascript | clean |
http://www.her38.com/themes/Sean_Cms/SCRIPT/Sean_script.js | 200 OK Content-Length: 5580 Content-Type: application/x-javascript | clean |
http://www.her38.com/themes/Sean_Cms/SCRIPT/flash.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://www.her38.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://www.her38.com/function/c_html_js_add.asp | 200 OK Content-Length: 1102 Content-Type: application/x-javascript | clean |
http://e.70e.com/js/cpc_wz_tw_stxw_gun.js | 200 OK Content-Length: 1455 Content-Type: application/x-javascript | clean |
http://e.7clink.com/cpc.php?c=2251_728_90_1_1C2C4C6C7C8C9C10C11C13C14_1 | 200 OK Content-Length: 601 Content-Type: application/x-javascript | clean |
http://click.mycctvmedia.com/page/s.php?s=814&w=660&h=60 | 200 OK Content-Length: 661 Content-Type: text/html | clean |
http://e.70e.com/js/cpc_wz_tw_ztyw.js | 200 OK Content-Length: 1441 Content-Type: application/x-javascript | clean |
http://js.yiwad.com/i.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://e.7clink.com/cpc.php?c=2251_250_250_1_1C2C4C6C7C8C9C10C11C13C14_1 | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://click.mycctvmedia.com/page/s.php?s=813&w=250&h=250 | 200 OK Content-Length: 662 Content-Type: text/html | clean |
http://cpro.86lego.com/page/s.php?s=698&w=250&h=250 | 200 OK Content-Length: 723 Content-Type: text/html | clean |
http://js.a3p4.net/page/?s=222297 | 200 OK Content-Length: 12 Content-Type: text/html | clean |