Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: qjrb.cn
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=86400
Date: Thu, 08 Jan 2015 11:06:34 GMT
Accept-Ranges: bytes
ETag: "6c86cb74202bd01:1ac6"
Server: Microsoft-IIS/6.0
Content-Length: 85180
Content-Location: http://qjrb.cn/index.htm
Content-Type: text/html
Last-Modified: Thu, 08 Jan 2015 08:52:39 GMT
X-Powered-By: ASP.NET
...85180 bytes of data.
GET / HTTP/1.1
Host: qjrb.cn
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=86400
Date: Thu, 08 Jan 2015 11:06:34 GMT
Accept-Ranges: bytes
ETag: "6c86cb74202bd01:1ac6"
Server: Microsoft-IIS/6.0
Content-Length: 85180
Content-Location: http://qjrb.cn/index.htm
Content-Type: text/html
Last-Modified: Thu, 08 Jan 2015 08:52:39 GMT
X-Powered-By: ASP.NET
...85180 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: qjrb.cn
Referer: http://www.google.com/search?q=qjrb.cn
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: qjrb.cn
Referer: http://www.google.com/search?q=qjrb.cn
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://qjrb.cn/ | HTTP/1.1 200 OK Cache-Control: max-age=86400 Date: Thu, 08 Jan 2015 11:06:34 GMT Accept-Ranges: bytes ETag: "6c86cb74202bd01:1ac6" Server: Microsoft-IIS/6.0 Content-Length: 85180 Content-Location: http://qjrb.cn/index.htm Content-Type: text/html Last-Modified: Thu, 08 Jan 2015 08:52:39 GMT X-Powered-By: ASP.NET | clean |
http://qjrb.cn/index.htm | 200 OK Content-Length: 85180 Content-Type: text/html | clean |
http://s13.cnzz.com/stat.php?id=3794026&web_id=3794026&show=pic | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://s13.cnzz.com/test404page.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 08 Jan 2015 11:13:28 GMT Via: cache8.de1[982,302-0,M], cache6.de1[983,0] Location: http://www.cnzz.com/404.html Server: Tengine Content-Length: 260 Content-Type: text/html X-Cache: MISS TCP_MISS dirn:-2:-2 X-Swift-CacheTime: 0 X-Swift-SaveTime: Thu, 08 Jan 2015 11:13:28 GMT | clean |
http://www.cnzz.com/404.html | 200 OK Content-Length: 3617 Content-Type: text/html | clean |
http://w.cnzz.com/c.php?id=30028303 | 200 OK Content-Length: 10073 Content-Type: application/javascript | clean |
http://qjrb.cn/1033.files/jquery.min.js | 200 OK Content-Length: 77084 Content-Type: application/x-javascript | clean |
http://qjrb.cn/1033.files/base-min.js | 200 OK Content-Length: 9004 Content-Type: application/x-javascript | clean |
http://qjrb.cn/1033.files/topimg.js | 200 OK Content-Length: 20159 Content-Type: application/x-javascript | clean |
http://qjrb.cn/1033.files/scroll.js | 200 OK Content-Length: 1597 Content-Type: application/x-javascript | clean |
http://qjrb.cn/1033.files/SpryTabbedPanels.js | 200 OK Content-Length: 11663 Content-Type: application/x-javascript | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=qjrb.cn
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://qjrb.cn/
Result: qjrb.cn is not infected or malware details are not published yet.
Result: qjrb.cn is not infected or malware details are not published yet.