New scan:

Malware Scanner report for qaididai.taobao.com

Malicious/Suspicious/Total urls checked
11/0/15
11 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://qaididai.taobao.com/
200 OK
Content-Length: 171002
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 626 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://g.tbcdn.cn/??kissy/k/1.3.2/kissy-min.js,tb/global/2.6.13/global-min.js
200 OK
Content-Length: 182057
Content-Type: application/x-javascript
clean
http://a.tbcdn.cn/apps/taesite/platinum/scripts/wangpu/init-async-min.js?t=20140404.js
200 OK
Content-Length: 4959
Content-Type: application/x-javascript
clean
http://qaididai.taobao.com/cuxiao.htm?signin=true
200 OK
Content-Length: 217462
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://a.tbcdn.cn/apps/taesite/platinum/scripts/wangpu/init-min.js?t=20140404.js
200 OK
Content-Length: 4773
Content-Type: application/x-javascript
clean
http://qaididai.taobao.com/?scene=taobao_shop
200 OK
Content-Length: 170996
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 626 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://qaididai.taobao.com/search.htm?search=y
200 OK
Content-Length: 242705
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://uaction.aliyuncdn.com/js/ua.js
200 OK
Content-Length: 57138
Content-Type: application/x-javascript
clean
http://qaididai.taobao.com/search.htm?search=y&orderType=hotsell_desc
200 OK
Content-Length: 243715
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://qaididai.taobao.com/search.htm?search=y&orderType=newOn_desc
200 OK
Content-Length: 245848
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://qaididai.taobao.com/search.htm?search=y&orderType=price_asc
200 OK
Content-Length: 244404
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://qaididai.taobao.com/category-798767287.htm?search=y&catName=%D5%DB%BF%DB%D7%A8%C7%F8
200 OK
Content-Length: 223164
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://qaididai.taobao.com/category-798767288.htm?search=y&parentCatId=798767287&parentCatName=%D5%DB%BF%DB%D7%A8%C7%F8&catName=%C7%E9%C8%A4%D3%C3%C6%B7%D5%DB%BF%DB
200 OK
Content-Length: 244452
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://qaididai.taobao.com/category-863444274.htm?search=y&parentCatId=798767287&parentCatName=%D5%DB%BF%DB%D7%A8%C7%F8&catName=%C7%E9%C8%A4%C4%DA%D2%C2%D5%DB%BF%DB
200 OK
Content-Length: 201405
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)

http://qaididai.taobao.com/category-863444275.htm?search=y&parentCatId=798767287&parentCatName=%D5%DB%BF%DB%D7%A8%C7%F8&catName=%CC%D7%CC%D7%D5%DB%BF%DB
200 OK
Content-Length: 242404
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


window.g_hb_monitor_st = +new Date();
window.g_config = {appId:2, assetsHost:"http://a.tbcdn.cn",toolbar:false, pageType:"wangpu"};
window.shop_config = {
"hasImpress":true,
"shopId":"104654647",
"siteId":"4",
"userId":"833036394",
"user_nick": "%E9%82%B4%E5%85%B4%E6%A2%85",
"shopCategoryId":"27",
... 435 bytes are skipped ...
shopId:'104654647',
siteId:'4',
siteCategoryId:'2',
itemId:'',
shopStats:'',
validatorUrl:'http://store.taobao.com/tadget/shop_stats.htm',
templateId:'206531',
templateName:''
};
window._poc = window._poc || [];
window._poc.push(["_trackCustom", "tpl", "new_shop"]);

Antivirus reports:

Emsisoft
Gen:Variant.Adware.NaviPromo.16 (B)


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: qaididai.taobao.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 08 Apr 2014 05:31:16 GMT
Via: 1.1 varnish
Age: 0
Server: Tengine
Vary: Accept-Encoding
Content-Language: zh-CN
Content-Type: text/html;charset=GBK
At_isb: 0
At_shoptype: 4_104654647
Atp_isdpp: 4v104654647
P3P: CP='CURa ADMa DEVa PSAo PSDo OUR BUS UNI PUR INT DEM STA PRE COM NAV OTC NOI DSP COR'
X-Cache: MISS
X-CacheHits: 0
X-Varnish: 1599691562
X-Varnish-Cache: 1
Second query (visit from search engine):
GET / HTTP/1.1
Host: qaididai.taobao.com
Referer: http://www.google.com/search?q=qaididai.taobao.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=qaididai.taobao.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://qaididai.taobao.com/

Result: qaididai.taobao.com is not infected or malware details are not published yet.