Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=spyz.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://spyz.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 27 Dec 2014 19:46:12 GMT Location: http://khuong.com Server: Apache Content-Length: 283 Content-Type: text/html; charset=iso-8859-1 | clean |
http://khuong.com/ | HTTP/1.1 200 OK Connection: close Date: Sat, 27 Dec 2014 19:46:12 GMT Accept-Ranges: bytes Age: 0 Server: ATS/5.0.1 Content-Length: 483 Content-Type: text/html Last-Modified: Wed, 22 Mar 2006 16:34:23 GMT P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV" Set-Cookie: BX=32ebl4la9u344&b=3&s=tj; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.khuong.com X-Host: p9w4.geo.bf1.yahoo.com X-INKT-SITE: http://www.khuong.com X-INKT-URI: http://www.khuong.com//index.html | clean |
http://khuong.com/journal/index.php | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 27 Dec 2014 19:46:13 GMT Age: 4 Location: http://khuong.com/journal/ Server: ATS/5.0.1 Content-Type: text/html; charset=utf-8 P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV" Set-Cookie: BX=34aputda9u345&b=3&s=lv; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.khuong.com X-Pingback: http://khuong.com/journal/xmlrpc.php | clean |
http://khuong.com/journal/ | 200 OK Content-Length: 52643 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. ...[254 bytes skipped]... ]:"",b[e]?"&"+e+"="+b[e]:"","'\"></",i,">"].join("")} var f=window,a=f.Meebo=f.Meebo||function(){(a._=a._||[]).push(arguments)},d=document, i="body",m=d[i],r;if(!m){r=arguments.callee;return setTimeout(function(){r(b)}, 100)}a.$={0:+new Date};a.T=function(u){a.$[u]=new Date-a.$[0]};a.v=4;var j="appendChild", h="createElement",k="src",l="lang",q="network",e="domain",n=d[h]("div"),v=n[j](d[h]("m")), c=d[h]("iframe"),g="document",o,s=function(){a.T("load");a("load")};f.addEventListener? f.addEventListener("load",s,false):f.attachEvent("onload",s);n.style.display="none"; m.insertBefore(n,m.firstChild).id="meebo";c.frameBorder="0";c.id="meebo-iframe"; c.allowTransparency="true";v[j](c);try{c.contentWindow[g].open()}catch(w){b[e]= d[e];o="javascript:var d="+g+".open();d.domain='"+d.domain+"';";c[k]=o+"void(0);"}try{var t= c.contentWindow[g];t.write(p());t.close()}catch(x){c ...[109 bytes skipped]... Decoded script: function () { a.T("load"); a("load"); } | ||
http://khuong.com/journal | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 27 Dec 2014 19:46:18 GMT Age: 0 Location: http://khuong.com/journal/ Server: ATS/5.0.1 Content-Type: text/html P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HEA PRE LOC GOV" Set-Cookie: BX=0fpkvula9u34a&b=3&s=q6; expires=Tue, 02-Jun-2037 20:00:00 GMT; path=/; domain=.khuong.com | clean |
http://khuong.com/test404page.js | 404 Not Found Content-Length: 73 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: spyz.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 27 Dec 2014 19:46:12 GMT
Location: http://khuong.com
Server: Apache
Content-Length: 283
Content-Type: text/html; charset=iso-8859-1
...283 bytes of data.
GET / HTTP/1.1
Host: spyz.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 27 Dec 2014 19:46:12 GMT
Location: http://khuong.com
Server: Apache
Content-Length: 283
Content-Type: text/html; charset=iso-8859-1
...283 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: spyz.com
Referer: http://www.google.com/search?q=spyz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: spyz.com
Referer: http://www.google.com/search?q=spyz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.