Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=winhone.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.winhone.net/ | HTTP/1.1 200 OK Date: Thu, 08 Jan 2015 15:36:32 GMT Accept-Ranges: bytes ETag: "fc9b2b23ba14d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 18194 Content-Location: http://www.winhone.net/index.html Content-Type: text/html Last-Modified: Wed, 10 Dec 2014 20:44:48 GMT X-Powered-By: ASP.NET | clean |
http://www.winhone.net/index.html | 200 OK Content-Length: 18194 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: ntyoukai.com ...[2249 bytes skipped]... 02:10</span></li> </ul> <ul> <li><a href="http://winhone.net/3r6ru67036110/" title="ÔÐÇ°Ìå¼ì´ó¸Å¶àÉÙÇ®-ÔѵÀÊÇʲôÒâ˼">ÔÐÇ°Ìå¼ì´ó¸Å¶àÉÙÐÏÞ¹«Ë¾</a> <a href="http://tph-gion.com" target="_blank">³£Öݶ¦ºÀÍøÂç¿Æ¼¼ÓÐÏÞ¹«Ë¾</a> <a href="http://huaxing-dg.com.cn/show/" target="_blank">66ÈËÌå´óµ¨</a> <a href="http://ntyoukai.com/info/" target="_blank">ed2kÂéÉúÏ£star371</a> <a href="http://dlthj.com/introduce/" target="_blank">sex8_cc - powered by</a> <a href="http://pinjian.net.cn/Article/" target="_blank">»ÆÉ«×ö°®µÄͼƬ</a> <a href="http://runrong88.com/down/" target="_blank">ÃÀÉÙÅ®ÍâÒõ˽ÅÄ</a> <a href="http://dlslyjs.cn/Feedback/" target="_blank">°®¿´ÌìµÄС˵ÏÂÔØ</a> <a href="http://xcjsky.com/web/" target="_blank">ÁÖÓ ...[1715 bytes skipped]... | ||
http://Js.lwtzdec.com/huishou.js | 200 OK Content-Length: 405 Content-Type: application/x-javascript | clean |
http://winhone.net/tj.js | 200 OK Content-Length: 0 Content-Type: application/x-javascript | clean |
http://www.winhone.net/test404page.js | HTTP/1.1 200 OK Date: Thu, 08 Jan 2015 15:36:36 GMT Accept-Ranges: bytes ETag: "c2bdb215d60d01:33a" Server: Microsoft-IIS/6.0 Content-Length: 1565 Content-Location: http://www.winhone.net/404.html?404;http://www.winhone.net:80/test404page.js Content-Type: text/html Last-Modified: Sat, 15 Nov 2014 13:14:28 GMT X-Powered-By: ASP.NET | clean |
http://www.winhone.net/404.html?404;http://www.winhone.net:80/test404page.js | 200 OK Content-Length: 1565 Content-Type: text/html | clean |
http://www.qq.com/404/search_children.js | 200 OK Content-Length: 295 Content-Type: application/javascript | clean |
http://js.users.51.la/17453581.js | 200 OK Content-Length: 1930 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: winhone.net
Result:
GET / HTTP/1.1
Host: winhone.net
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: winhone.net
Referer: http://www.google.com/search?q=winhone.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: winhone.net
Referer: http://www.google.com/search?q=winhone.net
Result:
The result is similar to the first query. There are no suspicious redirects found.