Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=shanxi.159.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://shanxi.159.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://shanxi.159.com/ | 200 OK Content-Length: 36131 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: sms.159.com ...[963 bytes skipped]... > var name = window.document.admin.name.value password = window.document.admin.password.value if (name == "") {alert("请填åæ¨çç¨æ·å") document.admin.name.focus(); return false; } if (password == "") {alert("请填åæ¨çå¯ç ") document.admin.password.focus(); return false } } </script> <form name='admin' method='post' action='http://sms.159.com/login.aspx?sms=xin' id='admin' onSubmit='return Check()'> <div class='top'> <div class='top1'><a href='http://sms.159.com' target='_blank' title='æºå®¢åå¡çä¿¡å¹³å°'><img src='/img/top1.gif' /></a></div> <div class='top2'> <div class='top2_1 wxh_hei'> <a href='http://game.159.com' target='_blank' title='ææºæ¸¸æ'>ææºæ¸¸æ</a&g ...[42207 bytes skipped]... | ||
http://shanxi.159.com/kefu/kefu.js | 200 OK Content-Length: 706 Content-Type: application/x-javascript | clean |
http://code.54kefu.net/kefu/js/49/328049.js | 200 OK Content-Length: 533 Content-Type: application/x-javascript | clean |
http://shanxi.159.com/js/count.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://shanxi.159.com/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: shanxi.159.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Mon, 07 Apr 2014 09:15:18 GMT
Server: Microsoft-IIS/6.0
Content-Length: 36131
Content-Type: text/html; charset=utf-8
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
...36131 bytes of data.
GET / HTTP/1.1
Host: shanxi.159.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Mon, 07 Apr 2014 09:15:18 GMT
Server: Microsoft-IIS/6.0
Content-Length: 36131
Content-Type: text/html; charset=utf-8
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
...36131 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: shanxi.159.com
Referer: http://www.google.com/search?q=shanxi.159.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: shanxi.159.com
Referer: http://www.google.com/search?q=shanxi.159.com
Result:
The result is similar to the first query. There are no suspicious redirects found.