Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ltddos.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.ltddos.com/ | 200 OK Content-Length: 238 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: d687ef1ed80f97de.0075.cdn.78302.com <meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<script language="javascript" type="text/javascript" src="http://d687ef1ed80f97de.0075.cdn.78302.com/nipaiyi/cdn/js/20150201055919005.js?d=www.ltddos.com"></script> | ||
http://d687ef1ed80f97de.0075.cdn.78302.com/nipaiyi/cdn/js/20150201055919005.js?d=www.ltddos.com | 200 OK Content-Length: 16368 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: www.ltddos.com ...[211 bytes skipped]... 1999/xhtml\">"); document.writeln("<link rel=\"Shortcut Icon\" href=\"http://img2.imgtn.bdimg.com/it/u=3639886997,2008005457&fm=23&gp=0.jpg\"> "); document.writeln("<head>"); document.writeln(" <meta http-equiv=\"Content-Type\" content=\"text/html; charset=utf-8\"/> "); document.writeln(" <link rel=\"stylesheet\" href=\"http://d687ef1ed80f97de.0075.cdn.78302.com/xf4/xf/css/cssreset.css?d=www.ltddos.com\" tppabs=\"http://www.ltddos.com/xf4/xf/css/cssreset.css\" />"); document.writeln(" <link rel=\"stylesheet\" href=\"http://d687ef1ed80f97de.0075.cdn.78302.com/xf4/xf/css/index4_3.css?d=www.ltddos.com\" tppabs=\"http://www.ltddos.com/xf4/xf/css/index4_3.css\" />"); document.writeln(" <title>À×öªddos_À×öªcc_ÍøÕ¾¹¥»÷-À×öª¹Ù·½ÍøÕ¾</title>"); document.writeln("<meta name=\"keywords\" content=\"À×öª¹Ù·½ÍøÕ¾ ¡¢À×öªddos¡¢À×öªcc¡¢ÍøÕ¾¹¥»÷\" />"); < ...[3420 bytes skipped]... Decoded script: ...[71 bytes skipped]... "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <link rel="Shortcut Icon" href="http://img2.imgtn.bdimg.com/it/u=3639886997,2008005457&fm=23&gp=0.jpg"> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"/> <link rel="stylesheet" href="http://d687ef1ed80f97de.0075.cdn.78302.com/xf4/xf/css/cssreset.css?d=www.ltddos.com" tppabs="http://www.ltddos.com/xf4/xf/css/cssreset.css" /> <link rel="stylesheet" href="http://d687ef1ed80f97de.0075.cdn.78302.com/xf4/xf/css/index4_3.css?d=www.ltddos.com" tppabs="http://www.ltddos.com/xf4/xf/css/index4_3.css" /> <title>À×öªddos_À×öªcc_ÍøÕ¾¹¥»÷-À×öª¹Ù·½ÍøÕ¾</title> <meta name="keywords" content="À×öª¹Ù·½ÍøÕ¾ ¡¢À×öªddos¡¢À×öªcc¡¢ÍøÕ¾¹¥»÷" /> <meta name="description" content="À×öªddosÃâ·ÑΪÄãÌṩÀ×öªcc¹¥»÷Æ÷ºÍÀ×öªddo ...[12438 bytes skipped]... | ||
http://www.ltddos.com/test404page.js | 404 Not Found Content-Length: 5222 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ltddos.com
Result:
GET / HTTP/1.1
Host: ltddos.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: ltddos.com
Referer: http://www.google.com/search?q=ltddos.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ltddos.com
Referer: http://www.google.com/search?q=ltddos.com
Result:
The result is similar to the first query. There are no suspicious redirects found.