Scanned pages/files
Request | Server response | Status |
http://www.qiqv.cn/content/ | 404 Not Found Content-Length: 9122 Content-Type: text/html | clean |
http://mat1.gtimg.com/www/js/mininav/mininavjs1.3_min.js | 200 OK Content-Length: 9352 Content-Type: application/x-javascript | clean |
http://qzonestyle.gtimg.cn/qzone_v6/lostchild/data.js | 200 OK Content-Length: 10186 Content-Type: application/x-javascript | clean |
http://mat1.gtimg.com/www/austin/xr/babygh_v1.0.2.js | 200 OK Content-Length: 1967 Content-Type: application/x-javascript | clean |
http://mat1.gtimg.com/www/austin/xr/babygh_iShare_v1.0.1.js | 200 OK Content-Length: 16073 Content-Type: application/x-javascript | clean |
http://pingjs.qq.com/pingV3_1_2.js | 200 OK Content-Length: 15162 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/index.php | 200 OK Content-Length: 72213 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) window._bd_share_config={"common":{"bdSnsKey":{},"bdText":"","bdMini":"2","bdMiniList":false,"bdPic":"","bdStyle":"0","bdSize":"16"},"slide":{"type":"slide","bdImg":"5","bdPos":"right","bdTop":"100"},"image":{"viewList":["qzone","tsina","tqq","renren","weixin"],"viewText":"·ÖÏíµ½£º","viewSize":"16"}};with(document)0[(getElementsByTagName('head')[0]||body).appendChild(createElement('script')).src='http://bdimg.share.baidu.com/static/api/js/share.js?v=89860593.js?cdnversion='+~(-new Date()/36e5)]; Antivirus reports:
| ||
http://www.qiqv.cn/static/js/common.js?FrL | 200 OK Content-Length: 69459 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/template/win8mi_metro_windows/src/js/jquery.1.4.2.min.js | 200 OK Content-Length: 72326 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/template/win8mi_metro_windows/src/js/msclass.js | 200 OK Content-Length: 16534 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/static/js/portal.js?FrL | 200 OK Content-Length: 11314 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/static/js/logging.js?FrL | 200 OK Content-Length: 603 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/template/win8mi_metro_windows/src/js/superslide.2.1.js | 200 OK Content-Length: 11270 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/template/win8mi_metro_windows/src/fancybox/jquery.mousewheel-3.0.4.pack.js | 200 OK Content-Length: 1279 Content-Type: application/x-javascript | clean |
http://www.qiqv.cn/template/win8mi_metro_windows/src/fancybox/jquery.fancybox-1.3.4.pack.js | 200 OK Content-Length: 15624 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: qiqv.cn
Result:
GET / HTTP/1.1
Host: qiqv.cn
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: qiqv.cn
Referer: http://www.google.com/search?q=qiqv.cn
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: qiqv.cn
Referer: http://www.google.com/search?q=qiqv.cn
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=qiqv.cn
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://qiqv.cn/
Result: qiqv.cn is not infected or malware details are not published yet.
Result: qiqv.cn is not infected or malware details are not published yet.