Scanned pages/files
Request | Server response | Status |
http://likai.7958.com/content/ | HTTP/1.1 404 Not Found Date: Sat, 12 Apr 2014 03:49:00 GMT Server: Microsoft-IIS/6.0 Content-Length: 17568 Content-Type: text/html | clean |
http://www.7958.com/ | 200 OK Content-Length: 32389 Content-Type: text/html | clean |
http://img1.7958.com/static/disk/js/jquery-1.8.2.min.js | 200 OK Content-Length: 93436 Content-Type: application/x-javascript | clean |
http://img1.7958.com/static/disk/js/jquery.tipsy.js | 200 OK Content-Length: 14903 Content-Type: application/x-javascript | clean |
http://js.adm.cnzz.net/js/abase.js | 200 OK Content-Length: 21394 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function FixedRealShow(){return document.body?(this.init.apply(this,arguments),void 0):!1}(function(window){function FnRegister(e,t){return w[e]||(w[e]=t)}function parseParams(e){var t=map[e];return t?{id:e||e,af:t.af||!1,did:t.aid||0,slotType:t.stype,isbefore:t.pop||0,htmlcode:t._html||0,width:t._w||0,height:t._h||0,stime:1e3*t.time||5e3,ptime:1e3*t.parktime||0,loadtime:1e3*t.loadtime||0,closePosition:t.cb||0,scroll:t.sc||0,position:t.pos||0,mleft:t._m_left||0,mtop:t._m_top||0,ip:t.ip||"",isifr Antivirus reports:
| ||
http://img1.7958.com/static/disk/js/top1.js?109 | 200 OK Content-Length: 6119 Content-Type: application/x-javascript | clean |
http://img1.7958.com/static/disk/js/sesame.js | 200 OK Content-Length: 46550 Content-Type: application/x-javascript | clean |
http://www.cnzz.com/js/slider.js | 200 OK Content-Length: 4302 Content-Type: application/javascript | clean |
http://www.7958.net/api.php?mod=js&bid=114 | 200 OK Content-Length: 1032 Content-Type: text/html | clean |
http://www.7958.net/forum.php?mod=viewthread&tid=348796 | 200 OK Content-Length: 60929 Content-Type: text/html | clean |
http://www.7958.net/static/js/common.js?MYJ | 200 OK Content-Length: 69376 Content-Type: application/x-javascript | clean |
http://www.7958.net/static/js/forum.js?MYJ | 200 OK Content-Length: 22145 Content-Type: application/x-javascript | clean |
http://www.7958.net/static/js/logging.js?MYJ | 200 OK Content-Length: 603 Content-Type: application/x-javascript | clean |
http://js.adm.cnzz.net/s.php?sid=225639 | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://js.adm.cnzz.net/test404page.js | 404 Not Found Content-Length: 620 Content-Type: text/html | clean |
http://cpro.baidustatic.com/cpro/ui/c.js | 200 OK Content-Length: 55355 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: likai.7958.com
Result:
GET / HTTP/1.1
Host: likai.7958.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: likai.7958.com
Referer: http://www.google.com/search?q=likai.7958.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: likai.7958.com
Referer: http://www.google.com/search?q=likai.7958.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=likai.7958.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://likai.7958.com/
Result: likai.7958.com is not infected or malware details are not published yet.
Result: likai.7958.com is not infected or malware details are not published yet.