Help
RSS
API
Feed
Maltego
Contact
Domain > gccrc.csrc91.cn
×
More information on this domain is in
AlienVault OTX
Is this malicious?
Yes
No
DNS Resolutions
Date
IP Address
2021-12-08
27.221.108.52
(
ClassC
)
2024-11-20
119.188.15.231
(
ClassC
)
Port 80
HTTP/1.1 420 Bad RequestContent-Type: text/html !DOCTYPE html>html langzh-CN>head> meta charsetUTF-8> meta nameviewport contentwidthdevice-width,minimum-scale1.0,maximum-scale1.0,user-scalableno/> meta http-equivX-UA-Compatible contentieedge> title>黑名单页面/title> style> html, body { margin: 0; padding: 0; background: #f7f7f7; } .wrap{ width: 100%; position: relative; margin: auto; text-align: center; margin-top: 6.5%; } .wrap img{ max-width: 1000px; } .content{ margin-top: -5%; margin-bottom: 43px; } .content p.title{ font-size: 25px; color: #444; } .content .center{ text-align: center; color: #999; } .content .reason{ font: 16px; color: #999; line-height: 12px; text-align: left; margin-left: 43%; } span.line{ display: inline-block; content: ; } .footer{ width: 55%; border-top: 2px solid #e3e3e3; margin: auto; } .footer p{ font: 16px; color: #999; line-height: 15px; text-align: left; padding: 0 20px; } .footer p span{ line-height:20px; white-space: normal; } /style>/head>body> div classwrap styledisplay: none;> img srchttps://error.websaas.cn/img/420s.png > div classcontent> p classtitle>您的IP地址最近有可疑的攻击行为,已被列入黑名单/p> /div> div classfooter> p styletext-align: center;>我是网站管理员,span idcallBack stylecolor: #1e80ff;cursor: pointer;>我要处理此异常/span>/p> /div> /div>script srchttps://custompages.websaas.cn/sha1.min.js typetext/javascript charsetutf-8>/script>script typetext/javascript> let wrap document.getElementsByClassName(wrap)0 let host window.location.href var demoFlag false var imgFlag false var timeOut 2000 function requestConfig() { const xhr1 new XMLHttpRequest() xhr1.open(get,https://custompages.websaas.cn/7bef9456-a3a9-4306-a9ca-5cadc03f6879.js,true) xhr1.setRequestHeader(XWD-Token, waduxawe124asdx); xhr1.onreadystatechange function(){ if(xhr1.readyState 4){ demoFlag true if((xhr1.status>200&&xhr1.status300)||xhr1.status0){ if(xhr1.responseText.length>0){ eval(xhr1.responseText) if(jsonData420.length 0){ showDefault() }else{ for (let i 0,num0; i jsonData420.length; i++) { const element jsonData420i; if(elementtarget&&host.includes(elementhost)){ CheckStatus(elementtarget) xhr1.onreadystatechange null; return } if(jsonData420.length-1 num){ showDefault() } num++ } } }else{ showDefault(); } }else{ showDefault(); } } } xhr1.send() timeOutFn(xhr1) } requestConfig(); function CheckStatus(target){ let link target const xhr2 new XMLHttpRequest() xhr2.onreadystatechange function() { if (xhr2.readyState 4) { imgFlag true if (xhr2.status 200) { window.location.href target xhr2.onreadystatechange null; } else { showDefault(); } } }; xhr2.open(HEAD,link,true) xhr2.send() timeOutFn(xhr2,true) } function showDefault() { setTimeout(()>{ wrap.style.displayblock },500) } function timeOutFn(xhr,second){ if(demoTime){clearTimeout(demoTime)} var demoTime setTimeout(()>{ if(!demoFlag||(second&&!imgFlag)){ xhr.onreadystatechange null; xhr.abort() showDefault() } },timeOut) }/script>script srchttps://custompages.websaas.cn/udesk.jstypetext/javascript charsetutf-8>/script>/body>/html>
View on OTX
|
View on ThreatMiner
Please enable JavaScript to view the
comments powered by Disqus.
Data with thanks to
AlienVault OTX
,
VirusTotal
,
Malwr
and
others
. [
Sitemap
]