I found this at “4399 xiao you xi” as well 9669.com (a game market for android)
see: http://killmalware.com/a.4399.cn/
(here you can see a lot of
ã5.15ä¸å¨æ¸¸æç²¾éã4399ææºæ¸¸æä¸ºä½ æ¨èæ¯å¨ææ°æå¥½ç©æç²¾å½©çä¸å¨ç²¾éææ¸¸ï¼...
, which I belive is the discription of the ad content. Also,
“bdPic”:“htxp://f1.img4399.com/ma~29_20150515145436_5555982c7c6f4.jpeg”
This one actually load a image for the content successfully!)
and http://killmalware.com/www.9669.com/ (This is the short one you get) appearently removed NOT when I scan again, this time with 2 instead of 1
This look like it is somewhere in the banner ad
Might have been taken down I get htxp://www.baidu.com/search/error.html
You always have to consider that in normal browsing, you are not allow to access some ad directly. What I mean is that some ads content load only within a website. If you access it directly, you will usually get a "403 Forbidden" page or the error page.
[b]So it have not been taken down.[/b]
http://labs.sucuri.net/db/malware/malware-entry-mwanomalysp8
I also get this usually when scanning Chinese site that look suspicious to me. What does this mean?
Edit:
This should be the script of a share content (using something) button. The file name [b]share.js[/b] proof this fact.