Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=qdhx.org
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: qdhx.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 12 Jan 2015 09:09:28 GMT
Server: kangle/3.4.3
Content-Type: text/html
X-Powered-By: PHP/5.3.29
GET / HTTP/1.1
Host: qdhx.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 12 Jan 2015 09:09:28 GMT
Server: kangle/3.4.3
Content-Type: text/html
X-Powered-By: PHP/5.3.29
Second query (visit from search engine):
GET / HTTP/1.1
Host: qdhx.org
Referer: http://www.google.com/search?q=qdhx.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: qdhx.org
Referer: http://www.google.com/search?q=qdhx.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://qdhx.org/ | 200 OK Content-Length: 9263 Content-Type: text/html | clean |
http://qdhx.org/u.php?act=phpinfo | 200 OK Content-Length: 77708 Content-Type: text/html | clean |
http://qdhx.org/u.php?=PHPB8B5F2A0-3C92-11d3-A3A9-4C7B08C10000 | 200 OK Content-Length: 14077 Content-Type: text/html | clean |
http://qdhx.org/test404page.js | 404 Not Found Content-Length: 1519 Content-Type: text/html | clean |
http://qdhx.org/pmd/ | 200 OK Content-Length: 5525 Content-Type: text/html | clean |
http://qdhx.org/pmd/js/get_scripts.js.php?scripts[]=jquery/jquery-1.8.3.min.js&scripts[]=ajax.js&scripts[]=keyhandler.js&scripts[]=jquery/jquery-ui-1.9.2.custom.min.js&scripts[]=jquery/jquery.sprintf.js&scripts[]=jquery/jquery.cookie.js&scripts[]=jquery/jquery.mousewheel.js&scripts[]=jquery/jquery.event.drag-2.2.js&scripts[]=jquery/jquery-ui-timepicker-addon.js&scripts[]=jquery/jquery.ba-hashchang <span>...316 symbols skipped</span> | 200 OK Content-Length: 220938 Content-Type: text/javascript | clean |
http://qdhx.org/pmd/js/messages.php?lang=en&db=&server=0&token=e42de868136cea63b738bbc5de36304a | 200 OK Content-Length: 16672 Content-Type: text/javascript | clean |
http://qdhx.org/pmd/js/get_image.js.php?theme=pmahomme | 200 OK Content-Length: 6263 Content-Type: text/javascript | clean |
http://qdhx.org/pmd/./url.php?url=http%3A%2F%2Fwww.phpmyadmin.net%2F&lang=en&token=ee805a8e20475e071bcc9870c8b64eed | 200 OK Content-Length: 5523 Content-Type: text/html | clean |
http://qdhx.org/pmd/./js/get_scripts.js.php?scripts[]=jquery/jquery-1.8.3.min.js&scripts[]=ajax.js&scripts[]=keyhandler.js&scripts[]=jquery/jquery-ui-1.9.2.custom.min.js&scripts[]=jquery/jquery.sprintf.js&scripts[]=jquery/jquery.cookie.js&scripts[]=jquery/jquery.mousewheel.js&scripts[]=jquery/jquery.event.drag-2.2.js&scripts[]=jquery/jquery-ui-timepicker-addon.js&scripts[]=jquery/jquery.ba-hashcha <span>...318 symbols skipped</span> | 200 OK Content-Length: 300300 Content-Type: text/javascript | clean |
http://qdhx.org/pmd/./js/messages.php?lang=en&db=&server=0&token=697b4257e0bc77b400154bc924ad32c9 | 200 OK Content-Length: 16672 Content-Type: text/javascript | clean |
http://qdhx.org/pmd/./js/get_image.js.php?theme=pmahomme | 200 OK Content-Length: 6263 Content-Type: text/javascript | clean |
http://qdhx.org/pmd/././url.php?url=http%3A%2F%2Fwww.phpmyadmin.net%2F&lang=en&token=8540601cc79275f3d8eae03104f038b2 | 200 OK Content-Length: 5523 Content-Type: text/html | clean |
http://qdhx.org/pmd/././js/get_scripts.js.php?scripts[]=jquery/jquery-1.8.3.min.js&scripts[]=ajax.js&scripts[]=keyhandler.js&scripts[]=jquery/jquery-ui-1.9.2.custom.min.js&scripts[]=jquery/jquery.sprintf.js&scripts[]=jquery/jquery.cookie.js&scripts[]=jquery/jquery.mousewheel.js&scripts[]=jquery/jquery.event.drag-2.2.js&scripts[]=jquery/jquery-ui-timepicker-addon.js&scripts[]=jquery/jquery.ba-hashc <span>...320 symbols skipped</span> | 200 OK Content-Length: 301648 Content-Type: text/javascript | clean |
http://qdhx.org/pmd/././js/messages.php?lang=en&db=&server=0&token=196166f1c58caae782d24a9d15ad3c75 | 200 OK Content-Length: 16672 Content-Type: text/javascript | clean |