Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=redwel2.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://redwel2.com/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:37:39 GMT Accept-Ranges: bytes ETag: "4a759fe7c814d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 9218 Content-Location: http://redwel2.com/index.html Content-Type: text/html Last-Modified: Wed, 10 Dec 2014 22:30:30 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/index.html | 200 OK Content-Length: 9218 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: pbtlgyp.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>·é»ðͨÐſƼ¼¹É·ÝÓÐÏÞ¹«Ë¾</title> <meta name="keywords" content="·é»ðͨÐſƼ¼¹É·ÝÓÐÏÞ¹«Ë¾" /> <meta name="description" content="· ...[4706 bytes skipped]... | ||
http://Js.lwtzdec.com/huishou.js | 200 OK Content-Length: 405 Content-Type: application/x-javascript | clean |
http://redwel2.com/tj.js | 200 OK Content-Length: 0 Content-Type: application/x-javascript | clean |
http://redwel2.com/mgju4643928/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:37:42 GMT Accept-Ranges: bytes ETag: "60a46152e35d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 5985 Content-Location: http://redwel2.com/mgju4643928/index.html Content-Type: text/html Last-Modified: Fri, 21 Nov 2014 23:31:49 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/mgju4643928/index.html | 200 OK Content-Length: 5985 Content-Type: text/html | clean |
http://redwel2.com/x0ypo393905/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:37:44 GMT Accept-Ranges: bytes ETag: "2c04542e35d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 4609 Content-Location: http://redwel2.com/x0ypo393905/index.html Content-Type: text/html Last-Modified: Fri, 21 Nov 2014 23:31:22 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/x0ypo393905/index.html | 200 OK Content-Length: 4609 Content-Type: text/html | clean |
http://redwel2.com/x0ypo393905/article_url | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:37:45 GMT Accept-Ranges: bytes ETag: "9ad56a8311d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 1561 Content-Location: http://redwel2.com/404.html?404;http://redwel2.com:80/x0ypo393905/article_url Content-Type: text/html Last-Modified: Sat, 15 Nov 2014 18:25:20 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/404.html?404;http://redwel2.com:80/x0ypo393905/article_url | 200 OK Content-Length: 1561 Content-Type: text/html | clean |
http://www.qq.com/404/search_children.js | 200 OK Content-Length: 295 Content-Type: application/javascript | clean |
http://js.users.51.la/17453581.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://js.users.51.la/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://redwel2.com/558t491/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:37:56 GMT Accept-Ranges: bytes ETag: "28b7965e973d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 11464 Content-Location: http://redwel2.com/558t491/index.html Content-Type: text/html Last-Modified: Wed, 19 Nov 2014 01:23:05 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/558t491/index.html | 200 OK Content-Length: 11464 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: gygdgs.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>ÕÒ±¾Ð£Ô°ÐÞÕæС˵-¾íëÌìóÃÊó</title> <meta name="keywords" content="ÕÒ±¾Ð£Ô°ÐÞÕæС˵" /> <meta name="description" content="ÕÒ±¾Ð£ ...[4313 bytes skipped]... | ||
http://redwel2.com/qd4l5g052997/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:37:58 GMT Accept-Ranges: bytes ETag: "ba2e8da08c3d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 11089 Content-Location: http://redwel2.com/qd4l5g052997/index.html Content-Type: text/html Last-Modified: Wed, 19 Nov 2014 00:06:11 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/qd4l5g052997/index.html | 200 OK Content-Length: 11089 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: sylyhj.com ...[2601 bytes skipped]... ÀÊ®´Î</a>Ò»²¿·Ö±øÁ¦×赲ס½ð¾üÆï±ø̽³öů²Ð¿áËðʧ²ÒÖØÒ»¿´Ö®Ï¡£</p> <p>Ò»ÄÐһŮÁ½ÃûÒÂÉÀÑ©°×¶¼²»Ëæ,ËýÊǸߵȼ¶<a href="http://redwel2.com/tkoht081880/"><img src="http://redwel2.com/meinv/2.jpg" alt="¼ÞâýÍþͼƬÃ÷ÐÇ"/></a>ÑÏÀ÷,¶àлÁÖµÀÓѺÃÒ⾸ºãÇع«×ÓËä²¢²»ÊǽÌÊÚ¡£<a href="http://hdjycm.com/oczod782430/">ÖØÉúµÚÈýµÛ¹ú¿ñÏë</a></p> <p>Îâ³ÇÀäºßÒ»ÉùÒòΪËÄÊ®ÍòÏá¾ü¡£<a href="http://sylyhj.com/2nia32777/">ŵ»ùÑÇe71pcÌ×</a></p> <p><img src="http://redwel2.com/meinv/10432JM0-0-lp.jpg" alt="·Ç³£¸ãЦµÄ¹ú²úµçÓ°"></p> </div> <div class="prevnext"> <span>ÉÏһƪ£º<a href='http://redwel2.com/ct59252996/'>Ö¸ÔÀòÄËʼþ-¶¡ÏãÉçÇø¶¡ÏãÉçÇø</a> </span> <span>ÏÂһƪ£º<a href='#'>ûÓÐÁË</a> </span> </div> </div> </div> ...[1270 bytes skipped]... | ||
http://redwel2.com/ct59252996/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:38:00 GMT Accept-Ranges: bytes ETag: "3cfc7da18c3d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 10166 Content-Location: http://redwel2.com/ct59252996/index.html Content-Type: text/html Last-Modified: Wed, 19 Nov 2014 00:06:13 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/ct59252996/index.html | 200 OK Content-Length: 10166 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: csjdzl.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>Ö¸ÔÀòÄËʼþ-¶¡ÏãÉçÇø¶¡ÏãÉçÇø</title> <meta name="keywords" content="Ö¸ÔÀòÄËʼþ" /> <meta name="description" content="Ö¸ÔÀòÄË ...[4612 bytes skipped]... | ||
http://redwel2.com/f6b4302995/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:38:01 GMT Accept-Ranges: bytes ETag: "324327a28c3d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 10929 Content-Location: http://redwel2.com/f6b4302995/index.html Content-Type: text/html Last-Modified: Wed, 19 Nov 2014 00:06:14 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/f6b4302995/index.html | 200 OK Content-Length: 10929 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: zgjxkj.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>ÐùÔ¯´«ÆæÄĸöÖ°Òµ×îÀ÷º¦-ÓÀºãÓ°Ôº¾Å¿áÔ¾Á¿ÉÙ³ÔʲôÖÐÒ©µ÷Àí</title> <meta name="keywords" content="ÐùÔ¯´«ÆæÄĸöÖ°Òµ×îÀ÷º¦" /> <met ...[4733 bytes skipped]... | ||
http://redwel2.com/rcob0l502994/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:38:03 GMT Accept-Ranges: bytes ETag: "9e3ae1a28c3d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 10712 Content-Location: http://redwel2.com/rcob0l502994/index.html Content-Type: text/html Last-Modified: Wed, 19 Nov 2014 00:06:15 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/rcob0l502994/index.html | 200 OK Content-Length: 10712 Content-Type: text/html | clean |
http://redwel2.com/vqj1v182993/ | HTTP/1.1 200 OK Date: Sat, 10 Jan 2015 13:38:05 GMT Accept-Ranges: bytes ETag: "cc1da7a38c3d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 10614 Content-Location: http://redwel2.com/vqj1v182993/index.html Content-Type: text/html Last-Modified: Wed, 19 Nov 2014 00:06:16 GMT X-Powered-By: ASP.NET | clean |
http://redwel2.com/vqj1v182993/index.html | 200 OK Content-Length: 10614 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: 021dzr.com <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>½èÖÖÂÒÂ×|ˮĻµçӰƽÃæͼ|Ïë×öÄÐÅäÆäʵҲ²»ÈÝÒ×ÀÖÎÄ</title> <meta name="keywords" content="½èÖÖÂÒÂ×" /> <meta name="description" co ...[4381 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: redwel2.com
Result:
HTTP/1.1 200 OK
Date: Sat, 10 Jan 2015 13:37:39 GMT
Accept-Ranges: bytes
ETag: "4a759fe7c814d01:33a"
Server: Microsoft-IIS/6.0
Content-Length: 9218
Content-Location: http://redwel2.com/index.html
Content-Type: text/html
Last-Modified: Wed, 10 Dec 2014 22:30:30 GMT
X-Powered-By: ASP.NET
...9218 bytes of data.
GET / HTTP/1.1
Host: redwel2.com
Result:
HTTP/1.1 200 OK
Date: Sat, 10 Jan 2015 13:37:39 GMT
Accept-Ranges: bytes
ETag: "4a759fe7c814d01:33a"
Server: Microsoft-IIS/6.0
Content-Length: 9218
Content-Location: http://redwel2.com/index.html
Content-Type: text/html
Last-Modified: Wed, 10 Dec 2014 22:30:30 GMT
X-Powered-By: ASP.NET
...9218 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: redwel2.com
Referer: http://www.google.com/search?q=redwel2.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: redwel2.com
Referer: http://www.google.com/search?q=redwel2.com
Result:
The result is similar to the first query. There are no suspicious redirects found.