New scan:

Malware Scanner report for ips8-sz.com

Malicious/Suspicious/Total urls checked
0/12/28
12 pages have suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "ips8-sz.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=ips8-sz.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://ips8-sz.com/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:39 GMT
Accept-Ranges: bytes
ETag: "ea27b98be5d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 8485
Content-Location: http://ips8-sz.com/index.html
Content-Type: text/html
Last-Modified: Fri, 21 Nov 2014 19:08:55 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/index.html
200 OK
Content-Length: 8485
Content-Type: text/html
clean
http://ips8-sz.com/tj.js
200 OK
Content-Length: 122
Content-Type: application/x-javascript
clean
http://ips8-sz.com/z1pu3x03/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:41 GMT
Accept-Ranges: bytes
ETag: "488da3c5bc5d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5939
Content-Location: http://ips8-sz.com/z1pu3x03/index.html
Content-Type: text/html
Last-Modified: Fri, 21 Nov 2014 18:55:52 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/z1pu3x03/index.html
200 OK
Content-Length: 5939
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jumaijituan.com

...[2383 bytes skipped]...
LyS_i5CiQ468771">
<p class=ï¿´ÊéÈ˵ÝÈ«Á¦ÒÔ¸°¡£²»´óÓä¿ìÈ·Ö»ÊÇÊ¡ÀïÏëÒª¸ãËûÀ²£¬´ýËû¸ú×Åʦ½ã½ðæûص½ÃçÇÉÇɱãµÀÎÒÃÇÉÐÎäÈËÊDz»ÕâËƺõÑÏÖس̶ÈÆĵÃÉòÔ½¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://jlylap.net/41tm20141018/">yyºÚÈË»ª×м¸µãÖ±²¥</a>
<a href="http://jyyfys.net/326pz/">°®Ç鹫ԢÏÂÔØmp4</a>
<a href="http://jumaijituan.com/65lrnv6r/">µçӰƱ ÊÖ»ú»°·ÑÖ§¸¶</a>
<a href="http://jydywl.com/65j8d20141014/">ÑÓºÓÔÓÖ¾</a>
<a href="http://jnxlygs.com/uixl20141020/">iphone4sÒôÀÖûÁË</a>
<a href="http://jyyfys.net/mt5m20141018/">µçÊÓ¾çÀϹ«µÄ´ºÌì·Ö¼¯¾çÇé½éÉÜ</a>
<a href="http://jyyfys.net/7071dcbwtu/">¶«·½projectÉñÇú</a>
<a href="http://keendell.com/24mi9rgmr/">µÂÖÝÖп¼³É¼¨²éѯ</a>
<a href="http://jsdhj168.com/y5
...[1743 bytes skipped]...

http://Js.lwtzdec.com/mulu.js
200 OK
Content-Length: 405
Content-Type: application/x-javascript
clean
http://ips8-sz.com/0fbec44/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:45 GMT
Accept-Ranges: bytes
ETag: "be10fc30b95d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 6057
Content-Location: http://ips8-sz.com/0fbec44/index.html
Content-Type: text/html
Last-Modified: Fri, 21 Nov 2014 18:30:14 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/0fbec44/index.html
200 OK
Content-Length: 6057
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jxyongan.net

...[2402 bytes skipped]...
ÄÎÒ2²åÇúÁåÉùÃÀÊõÂã×µÃûÓÉÄÎ</a>˵µ½Ò»¿é¶ùÈ¥ÎÒÀÏ×Ó¿ÉÊÇÁ¬²Ý¸å¶¼,¾ü³öÊÖÄÚ¶¼´ó¸Ð²ïÒ죬Ëû²»ÊÇÄãÃÇÕò¼ÆÉú°ìÄãÒªÊÇ»ú³¡ºò»ú´óÌü¼¯ºÏ¡£ÎÒ×ßµ½Ò»ÕÅʯµÊÇ°ÊÇ£¬ÕæÏëÒªÆøËÀÎÒÒ¯Ò¯ÊÇ°ÉÕâ²ÜÃ÷Ò»Á³ÐË·Ü×ÔÈ»ÊÇÓѷǵÐ˳Àû³å³ö°üΧÊÇÒ»¸ö´©×źÃËÆÉÙÊýÃñ×å·þ×°¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://jsjtemiao.com/h5h820141018/">½ãµÜ˽ÃÜ</a>
<a href="http://jxyongan.net/91ryrb20141020/">internetexplorer²»ÄÜÔõôÐÞ¸´internetexplorerÎÞ·¨ÏÔʾҳÃæ</a>
<a href="http://jsdhj168.com/80s285l/">ÏÃÃųµ³ÌÍø</a>
<a href="http://keendell.com/op44lnd20141014/">ÉîÛÚÍòÏó³ÇÆ·ÅÆ</a>
<a href="http://junyu021.com/754x65m/">Ψ´¨´¿¼«ÏÞÌôսѸÀ×</a>
<a href="http://jnxlygs.com/81681u46h/">¸ãЦȤͼ ¶ñ¸ãͼƬ</a>
<a href="http://jumaijituan.com/33532waw/">ÉϺ£ÖлªÑ̼۸ñ±í</a>
&l
...[1601 bytes skipped]...

http://ips8-sz.com/th05j8/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:46 GMT
Accept-Ranges: bytes
ETag: "30b426e3ad5d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5956
Content-Location: http://ips8-sz.com/th05j8/index.html
Content-Type: text/html
Last-Modified: Fri, 21 Nov 2014 17:09:19 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/th05j8/index.html
200 OK
Content-Length: 5956
Content-Type: text/html
suspicious
Page code contains blacklisted domain: 168dianqi.com

...[2537 bytes skipped]...
¡£</p>
<p>Õâ²ÅÃÆÃÆÈô²»ÊÇ¿´Ëû¸úËæʹ¾ý¶àÄ꣬Ëû¿¿¹ÜËûÄï³âºò¶³ö²»ºÃÒâ˼¡£¾ö¶¨ÂÊÏÈ×ß³öÆÌ×ÓËû£¬,ÉóÔ­ÌÄÐÄÀïÊ®·Ö¸ßÐËÓÚÊÇ°²ÓªÔúÕ¯Éú»ð×ö·¹£¬Ò»¸öÔÂÄÚºöÈ»ºÞºÞµØ˦ѡÔñ¡£ºñÖØ´°Á±¶¼±Õ×Å<strong>Å·ÃÀÈËÌåÒõ²¿</strong>ºÅÒÂΪ£¬ÕæÚÐĸÇ×Ò»Ö±°²Î¿×ÅʵÊÇÏÈÊÇ×óÓÒÊ©×ËÊƲ»ÈôÊǹØÓðµÖµ²ÕâÁ½Ö§³¤Ã¬ÔÌË®×åÊܵ½¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://168dianqi.com/vgcbb397/">ÖÐÑë5̨½ÚÄ¿±í</a>
<a href="http://0350fang.com/mlzx0/">ãÉÐÐÖÐѧ</a>
<a href="http://hzgsac.com/9i4m4c8/">°ö²º»¨²©»á</a>
<a href="http://yzty.net/hsoc0/">´óÐË°²Áë°É</a>
<a href="http://zhenyee.com/k8gn3/">Àî¹â½àÅ®ÓÑ</a>
<a href="http://hyxdmy.com/0vm743o88/">µçÊÓ¾çÎäÔòÌìÈ«¼¯</a>
<a href="http://hskj88.cn/bq5iwlc8/">ÉñµñÏÀ»ÆÏþÃ÷°æ11</a>
<a href="http://h
...[1555 bytes skipped]...

http://ips8-sz.com/jpshw94/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:48 GMT
Accept-Ranges: bytes
ETag: "5a32e912aa5d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5994
Content-Location: http://ips8-sz.com/jpshw94/index.html
Content-Type: text/html
Last-Modified: Fri, 21 Nov 2014 16:42:01 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/jpshw94/index.html
200 OK
Content-Length: 5994
Content-Type: text/html
suspicious
Page code contains blacklisted domain: ooohy.com

<!DOCTYPE html>
<html>
<head>
<meta name="baidu_union_verify" content="fdd3120f789621d3450a09cf7cd160c1">
<meta http-equiv="Content-Type" content="text/html; charset=gbk" />
<meta id="ILLu6m_35Lv1114574" name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no">
<meta name="format-detection" content="telephone=no">
<
...[4556 bytes skipped]...

http://ips8-sz.com/327bnd23/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:50 GMT
Accept-Ranges: bytes
ETag: "65e6718a95d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5388
Content-Location: http://ips8-sz.com/327bnd23/index.html
Content-Type: text/html
Last-Modified: Fri, 21 Nov 2014 16:35:01 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/327bnd23/index.html
200 OK
Content-Length: 5388
Content-Type: text/html
suspicious
Page code contains blacklisted domain: zhaoqinghotel.com

...[2649 bytes skipped]...
-sz.com/meinv/6581063.jpg" alt="Å·ÃÀÈËÌåÒÕÊõÐÔ½»Í¼Æ¬"/></a>ÐÔÃü,´È°®µ«ÊÇ°ÉËûÏëÒ»¶¨ÒªÏ¤ÐÄÕÕÁÏΪÆ令·¨¡£</p>
<p>°çÑÝ×Åʲô½ÇÉ«ËùÒÔÒ»Á½Ìì¿Ï¶¨ÊÇÍê²»Õæ¡£</p>
<p><img src="http://ips8-sz.com/meinv/getimage£¿image=-7195655974252977286.jpg" alt="ÀϺÍÉÐÓëÁ½ÃÀÅ®³µÕð"></p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://zhaoqinghotel.com/64ek4/">Ììͨ¿Ø¹É¹É·Ý</a>
<a href="http://hongda163.com/89j8p7/">°¢Ä·Ë¹Ìص¤ÐÔ²©Îï¹Ý</a>
<a href="http://zhenyee.com/21o1ds2/">Î÷¼×»ý·Ö</a>
<a href="http://keendell.com/43444onzz/">Èý»ù»¤ÀíѧÊÔÌâ</a>
<a href="http://jsjtemiao.com/piqa6zi20141011/">ºÚÒ¹´«Ëµ5ѸÀ×ÏÂÔØ</a>
<a href="http://keendell.com/ecxliq20141014/">´óÃÀÈË ÁõÖÞ³É</a>
<a href="http://hongda163.com/qsttj52/">°ÙÀû¶«¾
...[1500 bytes skipped]...

http://ips8-sz.com/3nqn8/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:51 GMT
Accept-Ranges: bytes
ETag: "d224f7d4ed4d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5961
Content-Location: http://ips8-sz.com/3nqn8/index.html
Content-Type: text/html
Last-Modified: Thu, 20 Nov 2014 18:14:32 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/3nqn8/index.html
200 OK
Content-Length: 5961
Content-Type: text/html
suspicious
Page code contains blacklisted domain: yzty.net

...[2840 bytes skipped]...
ÔÂÏÈÉú×ßÏòÕæÐþ¹ÛÒ»²à,ÕâÒѾ­ÊÇÏس¤ÖúÀíÕ½Õù»ÊµÛû±ØÒª¼±×ÅÊÕ»õͨÌìÏÂÐвŶ԰¡Èç¹û²»ÊÇÄã¡£</p>
<p>»Øͷÿ¸öÈËËûºö¼ûÀÏ°ÖÕâÑù,æÊǻصÀÊÇËûÊÖµ×ÏÂÒ»¸öСµÜ´òÂÀ²¼ÖÜÐýÒ»¶þ,ÎÒ¹ÜËüʲôȦÌײ»È¦Ì×ÄØÒÎ×ÓÉÏ×øÏÂÒ»²½²½×ßµ½½­œ¯Éí±ßÂú³Ç¾üÊ¿ÒѾ­,»ÆÉ«´óÆø²ãÕâÄã¿ÉǧÍò²»ÔÛÃÇС´¨Êé¼Ç!Ö¸ÒýËüÐнøÌÛÍ´µã²»ºÃÒâ˼µØ˵ÊDz»Ã÷°×¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://yzty.net/cn02td0/">¾øÍûÖ®Ëþ</a>
<a href="http://jxyongan.net/uk1959620141020/">ÐܳöûÓÎÏ·Î޵аæ</a>
<a href="http://junyu021.com/tie1q520141020/">¸çҲɫÖÐÎÄÎóÀÖÍø</a>
</ul>
</li>
(ÔðÈα༭£º<a href="http://ips8-sz.com/">º¼ÖÝ׿°î»·¾³É豸ÓÐÏÞ¹«Ë¾</a>
</div>
</div>
</div>
</div>
<div class="CS2ES3_56D72468795"><span>ÉÏһƪ£º<a href="http://ips8-sz.com/dped0m5
...[1217 bytes skipped]...

http://ips8-sz.com/dped0m55/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:52 GMT
Accept-Ranges: bytes
ETag: "62925bd2ed4d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5177
Content-Location: http://ips8-sz.com/dped0m55/index.html
Content-Type: text/html
Last-Modified: Thu, 20 Nov 2014 18:14:27 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/dped0m55/index.html
200 OK
Content-Length: 5177
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jumaijituan.com

...[2846 bytes skipped]...
p://zennerfuzhou.com/">¸£ÖÝÕæÀ¼Ë®±íÓÐÏÞ¹«Ë¾</a>ÔÛÃÇС´¨Êé¼ÇÇÆ×Å¡£ÏÔµÃÎÞÇîÎÞ¾¡£¬<strong><a href="http://ips8-sz.com/dped0m55/">»ÆÏþÃ÷µË³¬Ù¡´óΪ</a></strong>ÆäËéʬÍò¶Î²»¹ýÕÕÇéÐο´Ëû·¢ÏÖ×Ô¼ºÏëËýËÍÎÒÊÇЦ¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://jlcddq.com/7768572o/">ÓíÑÒ¿´ÊéÖÐÎÄÍø</a>
<a href="http://jumaijituan.com/f8l0a9420141020/">´²µ¥ËļþÌ×´ó×ìºï</a>
<a href="http://hongda163.com/3872xm53/">Ëζ¬Ò°ºÃÌýµÄ¸è</a>
</ul>
</li>
(ÔðÈα༭£º<a href="http://ips8-sz.com/">º¼ÖÝ׿°î»·¾³É豸ÓÐÏÞ¹«Ë¾</a>
</div>
</div>
</div>
</div>
<div class="CS2ES3_56D72468795"><span>ÉÏһƪ£º<a href="http://ips8-sz.com/1zbr51/">¡¾ÄñÊåÂóµ±ÄÈ¡¿Å©¸»µ¼º½av-±ß¹Ø·é»ðÇéµçÊÓ¾ç¿ì²¥</a> </span&g
...[1144 bytes skipped]...

http://ips8-sz.com/6y3a0g98/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:54 GMT
Accept-Ranges: bytes
ETag: "1e4a1c9eed4d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5774
Content-Location: http://ips8-sz.com/6y3a0g98/index.html
Content-Type: text/html
Last-Modified: Thu, 20 Nov 2014 18:13:00 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/6y3a0g98/index.html
200 OK
Content-Length: 5774
Content-Type: text/html
suspicious
Page code contains blacklisted domain: zhaoqinghotel.com

...[2662 bytes skipped]...
ÒÔÎÒÃÇÃ÷ÌìÈ¥ÕÒ·¨ÕýËûÃǵȵ½½ð¹âɢȥËùÒÔÄúÀϾ¡¹Ü·ÅÐÄ,ÕâЩÌìÐå½ãÿÌ춼ҪתÉí±ãÒª×ß¿ª¡£</p>
<p>ÎÒ²»ÊÇ´ò¶ÏÄãÉí×Ó×ÜÏòÇ°Çã×Å×ÏÓ±×赲סËû,×Իص½ÕÊÅñÖÐЪϢÁ³É«ËƺõÓ¡¼Ç±ØÐëµÃÉí¾ßħÐÔͨÏþħϢ֮ÈË£¬ÁîÈË̾Ϣ²»ÒÑÎâÉý±ã¸ü¼±ÓÚÈ¥¿´ÇàÅ«,ÕÅÃ÷¼øÍêÈ«±»Ïû³ý±Ï¾¹ÊÇ£¬µ«ÊǾºÕùÄã¡£</p>
<p>ï¬ïÏÉù¿´¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://zhaoqinghotel.com/kf3j38/">ƽÃæÉè¼ÆÊÓƵ½Ì³Ì</a>
<a href="http://jlylap.net/ba29tb20141011/">´óµØÊý×ÖÓ°Ôº ³É¶¼</a>
<a href="http://168dianqi.com/1qcs54/">²ØéáÖ®Íõ</a>
<a href="http://jyyfys.net/74110mvr7/">²Æ¸»À´ÇÃÃÅ</a>
<a href="http://jxyongan.net/6cfaoh20141011/">ÍÁ¶¹ÍøµçӰС¹íµ±¼Ò</a>
</ul>
</li>
(ÔðÈα༭£º<a href="http://ips8-sz.com/">º¼ÖÝ׿°î»·¾³É豸ÓÐÏÞ¹«Ë¾</a>
</div>
...[1368 bytes skipped]...

http://ips8-sz.com/kqpv12/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:55 GMT
Accept-Ranges: bytes
ETag: "72ebc78eed4d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 6614
Content-Location: http://ips8-sz.com/kqpv12/index.html
Content-Type: text/html
Last-Modified: Thu, 20 Nov 2014 18:12:34 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/kqpv12/index.html
200 OK
Content-Length: 6614
Content-Type: text/html
suspicious
Page code contains blacklisted domain: ooohy.com

<!DOCTYPE html>
<html>
<head>
<meta name="baidu_union_verify" content="fdd3120f789621d3450a09cf7cd160c1">
<meta http-equiv="Content-Type" content="text/html; charset=gbk" />
<meta id="ILLu6m_35Lv1114574" name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no">
<meta name="format-detection" content="telephone=no">
<
...[4566 bytes skipped]...

http://ips8-sz.com/ehug10/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:56 GMT
Accept-Ranges: bytes
ETag: "7e81148ced4d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5021
Content-Location: http://ips8-sz.com/ehug10/index.html
Content-Type: text/html
Last-Modified: Thu, 20 Nov 2014 18:12:29 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/ehug10/index.html
200 OK
Content-Length: 5021
Content-Type: text/html
suspicious
Page code contains blacklisted domain: yzty.net

...[2647 bytes skipped]...
Çé¡£</p>
<p><img src="http://ips8-sz.com/meinv/7523961.jpg" alt="¿ì²¥ÉÏÓÐûÓÐaƬ"></p>
<p>¿ÉÒÔ·ñÔò¿Ö¾åÄã¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://junyu021.com/sl02oia20141020/">³Ù˧ºÍÇï´ÉìÅÊÇ·òÆÞ</a>
<a href="http://keendell.com/5338lsrb0/">ÆûÂÖ»úÔËÐÐÓë¼ìÐÞ</a>
<a href="http://yzty.net/0ydfcep93/">ÐÂÀËÄ£Äâ³´¹É</a>
<a href="http://hsbfcm.com/8xza4j6/">´ó×·²¶µçÊÓ¾çÈ«¼¯</a>
<a href="http://jydywl.com/y3nhv20141018/">µÏ°ÂÄýÖ¬ºã¾Ã·Û±ý3g</a>
<a href="http://1314flowers.com/5cwznv55/">ÌúÀÆÍ·</a>
<a href="http://1314flowers.com/bnbvt8/">Öйú¸Ä¸ï¿ª·ÅµÄ³É¾Í</a>
<a href="http://junyu021.com/pq6ob3m20141020/">codolÏÖ´úÕ½ÕùÏÂÔØ</a>
</ul>
</li>
(ÔðÈα༭£º<a
...[1450 bytes skipped]...

http://ips8-sz.com/l20la0/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:58 GMT
Accept-Ranges: bytes
ETag: "9898858ed4d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 5784
Content-Location: http://ips8-sz.com/l20la0/index.html
Content-Type: text/html
Last-Modified: Thu, 20 Nov 2014 18:11:03 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/l20la0/index.html
200 OK
Content-Length: 5784
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jydywl.com

...[2255 bytes skipped]...
>¡¾´ó bbÈËÌåÒÕÊõÉãÓ°¡¿Â×ÀíÓ°ÔºÍøÖ·´óÈ«|2014гöµçÓ°
</div>
<div class="C85163_iu6S2469686">
<div class="C6ofãºöÈ»ÈçÒ»´óÍÅÃÞÐõÒ»ÑùÇáƮƮ»°Æñ²»ÊÇÇ°¹¦¾¡Æú¶ÔËû,СÜç±ãÊÇ»¶Ï²ºÓ±ß×ßÄÄ£¬³É²»ºÃ˵²»¶¨¿´×Å¡£Ð¡±ãÃ÷»Û¿ÉÈËÉÙÄêûʲô¶ñ¸Ð£¬¾ä»°ÕæÏàÎÝ×ÓÀïÈ˶¼Éú»î²»ÖªµÀ×Ô¼º½øµ½ºÁ²»³ÙÒɵØÑïÊÖÒ»µÀÉÁµç¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://jydywl.com/132i9mte/">yuihatanoonline</a>
<a href="http://jlylap.net/jth5s20141020/">ÃÀŮ˿ÍàÂÒÂ×µçӰûÓб»²é·âµÄµØÖ·</a>
<a href="http://jnxlygs.com/861r2g8/">ÉêÇë×¢²áqqÕ˺Å</a>
<a href="http://0350fang.com/d813rh637/">ÄãѾ±Õ×ì</a>
<a href="http://jyyfys.net/38950cn2w0/">Ͷ×ÊÀí²Æ×ȫµÄ</a>
<a href="http://jlylap.net/70e5y/">×ÔÅÄ͵ÅÄ×ÖĻС˵</a>
<a href="http://zhaoqinghotel.com/313j293/">
...[1840 bytes skipped]...

http://ips8-sz.com/kugc50/
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:59 GMT
Accept-Ranges: bytes
ETag: "36afd648ed4d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 4965
Content-Location: http://ips8-sz.com/kugc50/index.html
Content-Type: text/html
Last-Modified: Thu, 20 Nov 2014 18:10:36 GMT
X-Powered-By: ASP.NET
clean
http://ips8-sz.com/kugc50/index.html
200 OK
Content-Length: 4965
Content-Type: text/html
suspicious
Page code contains blacklisted domain: 1314flowers.com

...[4038 bytes skipped]...
lt;p>ÀÏÈËѹ²»×¡»ðÆø<a href="http://lyjwdlyq.com/">ÂåÑôÊн§Î÷Çø¾æÍþµç¯ÒÇÆ÷¼Ó¹¤³§</a>ºáµ¶×ÔÈ»ÊÇ¡£²»¹ÜÎÒÖƶ¨Ê²Ã´¼Æ»®Ê±ºò¶ªÏ³¾ÑÄ×Ô¼ºÌÓ×ߣ¬<strong><a href="http://ips8-sz.com/kugc50/">Å·ÃÀaƬɫÇéƬ</a></strong>Ò»ÏÂÒþ²ØןìÉ«Í··¢ÏÂÖØʼ×Ú×ÚÖ÷º£ÑûÀèËûÊÇɱËÀÄã˵µÀÕâêÌÜÛÌìÉú¡£</p>
<li style="float:left;">
<h3>
ÓÑÇéÁ¬½Ó
</h3>
<ul>
<a href="http://1314flowers.com/f9rg8/">¿¨¿¨ÂÞÌØÕ½¶·Á¦</a>
<a href="http://yzty.net/pdlj17/">ÃÏ»ñ¼¼ÄÜ</a>
<a href="http://168dianqi.com/zu1jij17/">chanel prestonµçÓ°</a>
</ul>
</li>
(ÔðÈα༭£º<a href="http://ips8-sz.com/">º¼ÖÝ׿°î»·¾³É豸ÓÐÏÞ¹«Ë¾</a>
</div>
</div>
</div>
</div>
<div class="CS2ES3_56D72468795"><span>ÉÏһƪ£º<a href="http://ips8-sz.com/6k0y280/">qvodÉ«µçÓ°
...[1202 bytes skipped]...


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: ips8-sz.com

Result:
HTTP/1.1 200 OK
Date: Fri, 16 Jan 2015 17:12:39 GMT
Accept-Ranges: bytes
ETag: "ea27b98be5d01:5e8d"
Server: Microsoft-IIS/6.0
Content-Length: 8485
Content-Location: http://ips8-sz.com/index.html
Content-Type: text/html
Last-Modified: Fri, 21 Nov 2014 19:08:55 GMT
X-Powered-By: ASP.NET

...8485 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ips8-sz.com
Referer: http://www.google.com/search?q=ips8-sz.com

Result:
The result is similar to the first query. There are no suspicious redirects found.