Scanned pages/files
Request | Server response | Status |
http://www.isaibo.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 30 Sep 2014 10:10:29 GMT Location: forum.php Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html | clean |
http://www.isaibo.com/forum.php | 200 OK Content-Length: 23884 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"16"},"slide":{"type":"slide","bdImg":"6","bdPos":"right","bdTop":"166.5"},"image":{"viewList":["qzone","tsina","tqq","renren","weixin"],"viewText":"å享å°ï¼","viewSize":"16"}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)]; Antivirus reports:
| ||
http://www.isaibo.com/data/cache/common.js?LLb | 200 OK Content-Length: 61122 Content-Type: text/javascript | clean |
http://www.isaibo.com/data/cache/forum.js?LLb | 200 OK Content-Length: 19549 Content-Type: text/javascript | clean |
http://www.isaibo.com/data/cache/logging.js?LLb | 200 OK Content-Length: 390 Content-Type: text/javascript | clean |
http://www.isaibo.com/home.php?mod=misc&ac=sendmail&rand=1412071727 | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
http://discuz.gtimg.cn/cloud/scripts/discuz_tips.js?v=1 | 200 OK Content-Length: 6173 Content-Type: application/x-javascript | clean |
http://www.isaibo.com/./ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 30 Sep 2014 10:10:38 GMT Location: forum.php Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html | clean |
http://www.isaibo.com/./forum.php | 200 OK Content-Length: 23884 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"16"},"slide":{"type":"slide","bdImg":"6","bdPos":"right","bdTop":"166.5"},"image":{"viewList":["qzone","tsina","tqq","renren","weixin"],"viewText":"å享å°ï¼","viewSize":"16"}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)]; Antivirus reports:
| ||
http://www.isaibo.com/./data/cache/common.js?LLb | 200 OK Content-Length: 61122 Content-Type: text/javascript | clean |
http://www.isaibo.com/./data/cache/forum.js?LLb | 200 OK Content-Length: 19549 Content-Type: text/javascript | clean |
http://www.isaibo.com/./data/cache/logging.js?LLb | 200 OK Content-Length: 390 Content-Type: text/javascript | clean |
http://www.isaibo.com/./home.php?mod=misc&ac=sendmail&rand=1412071727 | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
http://www.isaibo.com/././ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 30 Sep 2014 10:10:42 GMT Location: forum.php Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html | clean |
http://www.isaibo.com/././forum.php | 200 OK Content-Length: 23884 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"16"},"slide":{"type":"slide","bdImg":"6","bdPos":"right","bdTop":"166.5"},"image":{"viewList":["qzone","tsina","tqq","renren","weixin"],"viewText":"å享å°ï¼","viewSize":"16"}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)]; Antivirus reports:
| ||
http://www.isaibo.com/././data/cache/common.js?LLb | 200 OK Content-Length: 61122 Content-Type: text/javascript | clean |
http://www.isaibo.com/././data/cache/forum.js?LLb | 200 OK Content-Length: 19549 Content-Type: text/javascript | clean |
http://www.isaibo.com/././data/cache/logging.js?LLb | 200 OK Content-Length: 390 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: isaibo.com
Result:
GET / HTTP/1.1
Host: isaibo.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: isaibo.com
Referer: http://www.google.com/search?q=isaibo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: isaibo.com
Referer: http://www.google.com/search?q=isaibo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=isaibo.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://isaibo.com/
Result: isaibo.com is not infected or malware details are not published yet.
Result: isaibo.com is not infected or malware details are not published yet.