Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lunpan28.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://lunpan28.com/ | 200 OK Content-Length: 240 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: d687ef1ed80f97de.0075.cdn.78302.com <meta http-equiv="Content-Type" content="text/html; charset=gb2312" />
<script language="javascript" type="text/javascript" src="http://d687ef1ed80f97de.0075.cdn.78302.com/nipaiyi/cdn/js/20150212015602001.js?d=www.lunpan28.com"></script> | ||
http://d687ef1ed80f97de.0075.cdn.78302.com/nipaiyi/cdn/js/20150212015602001.js?d=www.lunpan28.com | 200 OK Content-Length: 10579 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: www.lunpan28.com ...[1872 bytes skipped]... ackground:url(http://www.baidu.com/img/i-1.0.0.png) no-repeat -202px 0;_top:1px;*position:relative}"); document.writeln("#bd_snap_ln{height:1px;border-top:1px solid #ACA899;background:#ECE9D8;overflow:hidden}"); document.writeln·þQQ189993015Ë÷Òª£©</p>"); document.writeln(" <p class=\"STYLE2\"></p>"); document.writeln(" <p><img src=\"http://d687ef1ed80f97de.0075.cdn.78302.com/58.jpg?d=www.lunpan28.com\" width=\"346\" height=\"263\" /></p></td>"); document.writeln(" <td><p><span class=\"STYLE2\"><a href=\"chengxu.rar\">Æ¡¾ÆÀÖÔ°ºǫ́ÏÂÔØ</a> </span></p>"); document.writeln(" <p class=\"STYLE2\"><a href=\"chengxu.rar\"><a href=\"chengxu.rar\">Æ¡¾ÆÀÖÔ°¿Í»§¶ËÏÂÔØ</a></p>"); document.writeln(" <p class=\"STYLE2\"><a href=\"chengxu.rar\"></a><a href=\" ...[1726 bytes skipped]... Decoded script: ...[1602 bytes skipped]... ACA899;background:#ECE9D8;overflow:hidden} #bd_snap_txt span a{text-decoration:none} </style> <div id="bd_snap"> <div id="bd_snap_head"> <a href="http://www.baidu.com/" id="bd_snap_logo" title="µ½°Ù¶ÈÊ×Ò³"></a> </div> <div id="bd_snap_ln"></div> <div style="position:relative"> <SCRIPT type=text/javascript>kfguin="189993015";ws="www.lunpan28.com"; companyname="ÂÖÅÌÓéÀÖ³ÌÐò"; welcomeword="ÄúºÃ,ÈçÐ蹺ÂòÂÖÅÌÓéÀÖ³ÌÐò<brT>²¦´òµç»°13526417626"; type="1";</SCRIPT> <SCRIPT src="http://d687ef1ed80f97de.0075.cdn.78302.com/js/kf.js?d=www.lunpan28.com" type=text/javascript></SCRIPT> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>ÂÖÅÌÈí¼þ¹Ù·½ÏÂÔØÍøÕ¾ ÁªÏµQQ£º189993015 ¹«Ë¾µç»°13526417626</title> <style type="text/css"> # ...[7111 bytes skipped]... | ||
http://lunpan28.com/test404page.js | 404 Not Found Content-Length: 5218 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: lunpan28.com
Result:
HTTP/1.1 200 OK
Cache-Control: 604800
Connection: close
Date: Sat, 07 Mar 2015 02:26:34 GMT
Accept-Ranges: bytes
ETag: "d915bcff2346d01:0"
Server: nginx/1.6.2
Content-Length: 240
Content-Type: text/html
Last-Modified: Wed, 11 Feb 2015 17:56:02 GMT
X-Powered-By: ASP.NET
...240 bytes of data.
GET / HTTP/1.1
Host: lunpan28.com
Result:
HTTP/1.1 200 OK
Cache-Control: 604800
Connection: close
Date: Sat, 07 Mar 2015 02:26:34 GMT
Accept-Ranges: bytes
ETag: "d915bcff2346d01:0"
Server: nginx/1.6.2
Content-Length: 240
Content-Type: text/html
Last-Modified: Wed, 11 Feb 2015 17:56:02 GMT
X-Powered-By: ASP.NET
...240 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: lunpan28.com
Referer: http://www.google.com/search?q=lunpan28.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: lunpan28.com
Referer: http://www.google.com/search?q=lunpan28.com
Result:
The result is similar to the first query. There are no suspicious redirects found.