Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=xiaosewang.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://xiaosewang.com/ | 200 OK Content-Length: 42740 Content-Type: text/html | clean |
http://xiaosewang.com/views/js/jquery.js | 200 OK Content-Length: 57254 Content-Type: application/x-javascript | clean |
http://xiaosewang.com/views/js/system.js | 200 OK Content-Length: 6989 Content-Type: application/x-javascript | clean |
http://xiaosewang.com/views/js/history.js | 200 OK Content-Length: 4494 Content-Type: application/x-javascript | clean |
http://xiaosewang.com/template/default/template.js | 200 OK Content-Length: 2705 Content-Type: application/x-javascript | clean |
http://c.tukj.net/code/wz_start.asp?pid=262821 | 200 OK Content-Length: 838 Content-Type: text/html | clean |
http://c.tukj.net/test404page.js | 404 Not Found Content-Length: 1308 Content-Type: text/html | clean |
http://xiaosewang.com/temp/Banner/index-96090.js | 200 OK Content-Length: 110 Content-Type: application/x-javascript | clean |
http://js.union.doudouguo.com/cpro.js | 200 OK Content-Length: 4834 Content-Type: application/x-javascript | suspicious |
Hidden iFrame found. size: 0x0 src: http://qiqu.bjjhdz.com/x/app/76_522.htm?uid= <iframe src="http://qiqu.bjjhdz.com/x/app/76_522.htm?uid=' + window.ddgu_uid + '" width="0" height="0" frameborder="0" scrolling="no"> Hidden iFrame found. size: 0x0 src: http://qiqu.bjjhdz.com/x/app/76_522.htm?uid= <iframe src="http://qiqu.bjjhdz.com/x/app/76_522.htm?uid=' + window.ddgu_uid + '&zoneid=' + window.ddgu_zid + '" width="0" height="0" frameborder="0" scrolling="no"> | ||
http://xiaosewang.com/temp/Banner/index-96090-2.js | 200 OK Content-Length: 345 Content-Type: application/x-javascript | clean |
http://f.f8272.com/code/pop_cpf.asp?pid=238207 | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://t.f8272.com/code/popjs.asp?pid=238206 | 200 OK Content-Length: 0 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: xiaosewang.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Connection: close
Date: Sat, 07 Mar 2015 14:15:26 GMT
Pragma: no-cache
Server: nginx/1.3.14
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=53906b5a549d9ec4f29c2f5119d661cf; path=/
X-Powered-By: PHP/5.2.17p1
GET / HTTP/1.1
Host: xiaosewang.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Connection: close
Date: Sat, 07 Mar 2015 14:15:26 GMT
Pragma: no-cache
Server: nginx/1.3.14
Vary: Accept-Encoding
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=53906b5a549d9ec4f29c2f5119d661cf; path=/
X-Powered-By: PHP/5.2.17p1
Second query (visit from search engine):
GET / HTTP/1.1
Host: xiaosewang.com
Referer: http://www.google.com/search?q=xiaosewang.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: xiaosewang.com
Referer: http://www.google.com/search?q=xiaosewang.com
Result:
The result is similar to the first query. There are no suspicious redirects found.