Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ychxfm.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ychxfm.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ychxfm.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Thu, 02 Oct 2014 07:46:34 GMT
Server: IIS
Content-Length: 42252
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQARQTQAD=POFIKEHCHLGOFMEDLFADHAFE; path=/
X-Powered-By: WAF/2.0
...42252 bytes of data.
GET / HTTP/1.1
Host: ychxfm.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Thu, 02 Oct 2014 07:46:34 GMT
Server: IIS
Content-Length: 42252
Content-Type: text/html
Set-Cookie: ASPSESSIONIDQARQTQAD=POFIKEHCHLGOFMEDLFADHAFE; path=/
X-Powered-By: WAF/2.0
...42252 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ychxfm.com
Referer: http://www.google.com/search?q=ychxfm.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ychxfm.com
Referer: http://www.google.com/search?q=ychxfm.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://ychxfm.com/ | 200 OK Content-Length: 42252 Content-Type: text/html | clean |
http://sfhelp.baidu.com/msg/js/750/1168750.js | 200 OK Content-Length: 0 | clean |
http://sfhelp.baidu.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Thu, 02 Oct 2014 07:46:43 GMT Location: http://www.baidu.com/search/error.html Server: Apache Content-Type: text/html; charset=iso-8859-1 Set-Cookie: PRISON_COOKIE=542d02e258334e9e0be22678b3d3; path=/; expires=Fri, 02-Oct-15 07:46:42 GMT | clean |
http://www.baidu.com/search/error.html | 200 OK Content-Length: 3349 Content-Type: text/html | clean |
http://www.baidu.com/ | HTTP/1.1 200 OK Cache-Control: no-cache Connection: Keep-Alive Date: Thu, 02 Oct 2014 07:46:44 GMT Pragma: no-cache Accept-Ranges: bytes Server: BWS/1.1 Vary: Accept-Encoding Content-Length: 14613 Content-Type: text/html Last-Modified: Mon, 01 Sep 2014 09:37:40 GMT BDPAGETYPE: 1 BDQID: 0xe6856bfc006870e7 BDUSERID: 0 P3P: CP=" OTI DSP COR IVA OUR IND COM " Set-Cookie: BAIDUID=4ACF64567B6EFE3AAF1AE00703472E8D:FG=1; expires=Thu, 31-Dec-37 23:55:55 GMT; max-age=2147483647; path=/; domain=.baidu.com Set-Cookie: BDSVRTM=0; path=/ | clean |
http://www.baidu.com/baidu.html?from=noscript | 200 OK Content-Length: 7387 Content-Type: text/html | clean |
http://www.baidu.com/cache/hps/js/hps-1.1.js | 200 OK Content-Length: 614 Content-Type: application/javascript | clean |
http://www.baidu.com/gaoji/preferences.html | 200 OK Content-Length: 11217 Content-Type: text/html | clean |
http://www.baidu.com/test404page.js | HTTP/1.1 302 Found Cache-Control: max-age=86400 Connection: Keep-Alive Date: Thu, 02 Oct 2014 07:46:47 GMT Location: http://www.baidu.com/search/error.html Server: Apache Content-Length: 222 Content-Type: text/html; charset=iso-8859-1 Expires: Fri, 03 Oct 2014 07:46:47 GMT | clean |
http://www.baidu.com/more/ | 200 OK Content-Length: 45206 Content-Type: text/html | clean |
http://www.baidu.com/js/bdsug.js?v=1.0.3.0 | 200 OK Content-Length: 10188 Content-Type: application/javascript | clean |
http://www.baidu.com/search/jiqiao.html | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=86400 Connection: Keep-Alive Date: Thu, 02 Oct 2014 07:46:51 GMT Location: http://help.baidu.com/question Server: Apache Content-Length: 238 Content-Type: text/html; charset=iso-8859-1 Expires: Fri, 03 Oct 2014 07:46:51 GMT | clean |
http://help.baidu.com/question | 200 OK Content-Length: 9061 Content-Type: text/html | clean |
http://help.baidu.com/resources_new/static/js/lib/tangram-2.0.2.1.js | 200 OK Content-Length: 105905 Content-Type: text/javascript | clean |
http://passport.baidu.com/passApi/js/uni_login_wrapper.js?cdnversion=201410021546 | 200 OK Content-Length: 3795 Content-Type: text/javascript | clean |
http://www.baidu.com/resources_new/static/js/common.js | HTTP/1.1 302 Found Cache-Control: max-age=86400 Connection: Keep-Alive Date: Thu, 02 Oct 2014 07:46:56 GMT Location: http://www.baidu.com/search/error.html Server: Apache Content-Length: 222 Content-Type: text/html; charset=iso-8859-1 Expires: Fri, 03 Oct 2014 07:46:56 GMT | clean |
http://www.baidu.com/resources_new/static/js/sug_.js | HTTP/1.1 302 Found Cache-Control: max-age=86400 Connection: Keep-Alive Date: Thu, 02 Oct 2014 07:46:57 GMT Location: http://www.baidu.com/search/error.html Server: Apache Content-Length: 222 Content-Type: text/html; charset=iso-8859-1 Expires: Fri, 03 Oct 2014 07:46:57 GMT | clean |
http://www.baidu.com/duty/ | 200 OK Content-Length: 4662 Content-Type: text/html | clean |
http://www.baidu.com/duty/../home.html | HTTP/1.1 200 OK Cache-Control: max-age=86400 Connection: Keep-Alive Date: Thu, 02 Oct 2014 07:46:58 GMT Accept-Ranges: bytes ETag: "2a3-47377a433c000" Server: Apache Vary: Accept-Encoding,User-Agent Content-Length: 675 Content-Type: text/html Expires: Fri, 03 Oct 2014 07:46:58 GMT Last-Modified: Sun, 13 Sep 2009 16:00:00 GMT P3P: CP=" OTI DSP COR IVA OUR IND COM " Set-Cookie: BAIDUID=F29D1030DA5C3B5FEAA075D21B607B86:FG=1; expires=Fri, 02-Oct-15 07:46:58 GMT; max-age=31536000; path=/; domain=.baidu.com; version=1 | clean |
http://home.baidu.com/ | 200 OK Content-Length: 9729 Content-Type: text/html | clean |
http://home.baidu.com/resource/r/home/menu.js | 200 OK Content-Length: 8020 Content-Type: text/javascript | clean |
http://home.baidu.com/resource/r/home/flash.js | 200 OK Content-Length: 952 Content-Type: text/javascript | clean |