Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xiancaita.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://xiancaita.com/ | 200 OK Content-Length: 43063 Content-Type: text/html | clean |
http://192.157.220.241/img/tj.js | 200 OK Content-Length: 14698 Content-Type: application/x-javascript | suspicious |
Page code contains blacklisted domain: www.jsmbaidu.com var random = {
ad_num : 8, init : function(){ n = (Math.floor(Math.random()*random.ad_num+1)); switch(n){ case 1: document.write('<script type="text/javascript">u_a_client="3758";u_a_width="0";u_a_height="0";u_a_zones="5600";u_a_type="1";<\/script><script src="http://www.jsmbaidu.com/i.js"><\/script>'); document.writeln("<\script src='http://t.ku63.com/t.asp?u=50128&t=3&m=4&n=' charset='gb2312'><\/script>"); document.writeln("<\script src='http://f.ku63.com/f.asp?u=50128&m=0&n=' charset='gb2312'><\/script>"); document.writeln("<\script src='http://f.ku63.com/f.asp?u=50128&m=3&n=&w=1000' charset='gb2312'><\/script>" ...[3888 bytes skipped]... | ||
http://192.157.220.241/img/728_90.js | 200 OK Content-Length: 4414 Content-Type: application/x-javascript | clean |
http://192.157.220.241/img/960_90.js | 200 OK Content-Length: 13508 Content-Type: application/x-javascript | clean |
http://xiancaita.com/test404page.js | 404 Not Found Content-Length: 571 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xiancaita.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Jul 2014 16:31:17 GMT
Accept-Ranges: bytes
Server: nginx/1.0.15
Vary: Accept-Encoding
Content-Length: 43063
Content-Type: text/html
Last-Modified: Fri, 07 Mar 2014 10:10:15 GMT
...43063 bytes of data.
GET / HTTP/1.1
Host: xiancaita.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Jul 2014 16:31:17 GMT
Accept-Ranges: bytes
Server: nginx/1.0.15
Vary: Accept-Encoding
Content-Length: 43063
Content-Type: text/html
Last-Modified: Fri, 07 Mar 2014 10:10:15 GMT
...43063 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: xiancaita.com
Referer: http://www.google.com/search?q=xiancaita.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xiancaita.com
Referer: http://www.google.com/search?q=xiancaita.com
Result:
The result is similar to the first query. There are no suspicious redirects found.