Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=vb-p.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kvkthoubal.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 13 Sep 2015 00:23:22 GMT
Server: nginx
Content-Type: text/html; charset=UTF-7
X-Pingback: http://kvkthoubal.org/site/xmlrpc.php
GET / HTTP/1.1
Host: kvkthoubal.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 13 Sep 2015 00:23:22 GMT
Server: nginx
Content-Type: text/html; charset=UTF-7
X-Pingback: http://kvkthoubal.org/site/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: kvkthoubal.org
Referer: http://www.google.com/search?q=kvkthoubal.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kvkthoubal.org
Referer: http://www.google.com/search?q=kvkthoubal.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://vb-p.com/ | HTTP/1.1 302 Found Connection: close Date: Mon, 26 Jan 2015 23:55:34 GMT Location: http://ww15.vb-p.com/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.3-7+squeeze23 | malicious |
http://ww15.vb-p.com/ | 200 OK Content-Length: 12833 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: vb-p.com ...[659 bytes skipped]... /> .add_link li a{width: 105px; color:#0098c8; font:normal 16px/32px "å®ä½"; height:32px; overflow:hidden; display:inline-block; margin: 0 0 0 12px;} .add_link li a:hover{ text-decoration:underline;} .boxbg { background-color: #000; border: 1px solid #303030; } </style> <script type="text/javascript">var gl={trackingurl:'http://ww15.vb-p.com/tracking.php',searchurl:'http://ww15.vb-p.com/index.php',relatedsearch:'Related Search',searchbutton:'Search',ckurl:'',cdn:'http://'+document.domain+'/'};var req={ps:["afd","bd3"],adtest:'off',dm:'vb-p.com',fdm:'ww15.vb-p.com',landerid:323,buy:true,adultallowed:true,cusbuy:'<span class="buy"> </span>',contactinfo:'',partner:'afd',dks:['å·¦æè碱åè¥è¶å ','ä¸å© ','注åå ¬å¸','ç§æ¤ç ','ä¸å½ä½è²å½©ç¥¨ ','ä¸å½ç¦å©å½©ç¥¨3dé¢æµ ','ä¸è³ç ','ææå ...[2950 bytes skipped]... | ||
http://www.google.com/adsense/domains/caf.js | 200 OK Content-Length: 207584 Content-Type: text/javascript | clean |
http://vb-p.com/js/parking_caf_281_1409192.js | 404 Not Found Content-Length: 227 Content-Type: text/html | clean |
http://vb-p.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |