Return-path: <3zdshUgcKBaIPQTGRNaIQQING.EQOCFOKPgZRKRU.PGV@malware.bounces.google.com>
Envelope-to: admin@4xpips.net
Delivery-date: Sat, 31 Aug 2013 08:04:39 -0400
Received: from mail-pa0-f69.google.com ([209.85.220.69]:55090)
	by host.silverbacklabs.net with esmtps (TLSv1:RC4-SHA:128)
	(Exim 4.80.1)
	(envelope-from <3zdshUgcKBaIPQTGRNaIQQING.EQOCFOKPgZRKRU.PGV@malware.bounces.google.com>)
	id 1VFjuw-0007Po-Mg
	for admin@4xpips.net; Sat, 31 Aug 2013 08:04:38 -0400
Received: by mail-pa0-f69.google.com with SMTP id kq13so4359915pab.8
        for <admin@4xpips.net>; Sat, 31 Aug 2013 05:04:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=google.com; s=20120113;
        h=mime-version:auto-submitted:message-id:date:subject:from:to
         :content-type;
        bh=6XB0cvNxDrdLcCATdgRyFoTxXFe+mgJZ96hGVi6HUpY=;
        b=LWwl0lyLc+3G6EO/9cZgSua9g7dYuBVASSBAIHXr2SkHpBJx0hIaIvJFhRxpGOdIE3
         AnlX33dAfW2+W8iBDyFSbA+2AViCDg6Ad8dkedQ/b9ucBWqEeFxM3zfTQewxzII1eGXa
         hHD4saDzr3AsaiO0TjfY00lmI1bqO6L0/tlmVBPikmW8tynhYjXL45e1W/cjjjDsruzj
         cUET80KL5O+01GsYuzZbzjzUkQvM20PCbpoL0j7wFPjlnvxAEcd+M7H/h48UW42P4Ts5
         VrBGfoUgKatb4L2oLemB/9PTgE1+K4oeUlwZhgzUBuy0uw1LkSq3f8TsQtRWTUxAVT1D
         T/2Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20130820;
        h=x-gm-message-state:mime-version:auto-submitted:message-id:date
         :subject:from:to:content-type;
        bh=6XB0cvNxDrdLcCATdgRyFoTxXFe+mgJZ96hGVi6HUpY=;
        b=eG4XC0X1QopQ1BjXBsGdntw4oJnlhG1INPHuVtNJNscrQ349lZdBHLgc1/lA981cgR
         HOO81lh78el0xPvbIiKf5QS57Dfyi4l/p4tXwPsn+snveT06UhUrWmcMhsVJ3ZlEAxvs
         uVrLLPomy4qOReJrMY+ibKD2TwZs7Gt9n5oJN7hAQ9xNP7FI9HrhHYVmqRbJfKNeJu1g
         jICHBuz9A4tnJhCeU0XZ88w9lA8W8naKMvHtHZbDS/caV0KnN4LhTasnD8UHjTu51ySg
         Ac5T/0AvN5SPbooGsk1eDaEnbLtpuVr1dIpNaID+33fgn0+rbVGGSx1gFKOD9aDwNWf5
         7lVw==
X-Gm-Message-State: ALoCoQmSjoRryuoQl+IG3YoDvSkzr8oddkVmYCVpJQK8uHE1fb0X4zOYF4kI9n7zeLWvA2WBy6+psDLknj+sKtuS7ROe3iPmlwc0DJatsq9HDxazE92380PbidMVn15vCTwOPqN3YXZrNCaB1/Glf9CP2I3MkBBPwpXqgxuoXxXRKRAfWuGwj5AjPDEeZJpKm12D6cIrJTX9
MIME-Version: 1.0
X-Received: by 10.66.252.170 with SMTP id zt10mr4384560pac.34.1377950669125;
 Sat, 31 Aug 2013 05:04:29 -0700 (PDT)
Auto-Submitted: auto-generated
Message-ID: <047d7b15ac6d26cd5804e53d245a@google.com>
Date: Sat, 31 Aug 2013 12:04:29 +0000
Subject: Malware notification regarding 4xpips.net
From: noreply@google.com
To: abuse@4xpips.net, admin@4xpips.net, administrator@4xpips.net, 
	contact@4xpips.net, info@4xpips.net, postmaster@4xpips.net, 
	support@4xpips.net, webmaster@4xpips.net
Content-Type: multipart/alternative; boundary=047d7b15ac6d26cd4c04e53d2457

--047d7b15ac6d26cd4c04e53d2457
Content-Type: text/plain; charset=ISO-8859-1; format=flowed; delsp=yes

Dear site owner or webmaster of 4xpips.net,

We recently discovered that some of your pages can cause users to be  
infected with malicious software. We have begun showing a warning page to  
users who visit these pages by clicking a search result on Google.com.

Below are some example URLs on your site which can cause users to be  
infected (space inserted to prevent accidental clicking in case your mail  
client auto-links URLs):

http://4xpips .net/
http://www.4xpips .net/
http://www.4xpips .net/?hop=0

Here is a link to a sample warning page:
http://www.google.com/interstitial?url=http%3A//4xpips.net/

We strongly encourage you to investigate this immediately to protect your  
visitors. Although some sites intentionally distribute malicious software,  
in many cases the webmaster is unaware because:

1) the site was compromised
2) the site doesn't monitor for malicious user-contributed content
3) the site displays content from an ad network that has a malicious  
advertiser

If your site was compromised, it's important to not only remove the  
malicious (and usually hidden) content from your pages, but to also  
identify and fix the vulnerability. We suggest contacting your hosting  
provider if you are unsure of how to proceed. StopBadware also has a  
resource page for securing compromised sites:
http://www.stopbadware.org/home/security

Once you've secured your site, you can request that the warning be removed  
by visiting
http://www.google.com/support/webmasters/bin/answer.py?answer=45432
and requesting a review. If your site is no longer harmful to users, we  
will remove the warning.

Sincerely,
Google Search Quality Team

Note: if you have an account in Google's Webmaster Tools, you can verify  
the authenticity of this message by logging into  
https://www.google.com/webmasters/tools/siteoverview and going to the  
Message Center, where a warning will appear shortly.

--047d7b15ac6d26cd4c04e53d2457
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<p>Dear site owner or webmaster of 4xpips.net,<br />

<p>We recently discovered that some of your pages can cause users to be inf=
ected with malicious software. We have begun showing a warning page to user=
s who visit these pages by clicking a search result on Google.com.</p>

<p>Below are some example URLs on your site which can cause users to be inf=
ected (space inserted to prevent accidental clicking in case your mail clie=
nt auto-links URLs):</p>

<p>http://4xpips .net/<br/>
http://www.4xpips .net/<br/>
http://www.4xpips .net/?hop=3D0</p>

<p>Here is a link to a sample warning page:<br />
http://www.google.com/interstitial?url=3Dhttp%3A//4xpips.net/</p>

<p>We strongly encourage you to investigate this immediately to protect you=
r visitors. Although some sites intentionally distribute malicious software=
, in many cases the webmaster is unaware because:</p>

<p>1) the site was compromised<br />
2) the site doesn't monitor for malicious user-contributed content<br />
3) the site displays content from an ad network that has a malicious advert=
iser<br />

<p>If your site was compromised, it's important to not only remove the mali=
cious (and usually hidden) content from your pages, but to also identify an=
d fix the vulnerability. We suggest contacting your hosting provider if you=
 are unsure of how to proceed. StopBadware also has a resource page for sec=
uring compromised sites:<br />
http://www.stopbadware.org/home/security</p>

<p>Once you've secured your site, you can request that the warning be remov=
ed by visiting <br />http://www.google.com/support/webmasters/bin/answer.py=
?answer=3D45432<br /> and requesting a review. If your site is no longer ha=
rmful to users, we will remove the warning.</p>

<p>Sincerely,<br />
Google Search Quality Team</p>

<p>Note: if you have an account in Google's Webmaster Tools, you can verify=
 the authenticity of this message by logging into https://www.google.com/we=
bmasters/tools/siteoverview and going to the Message Center, where a warnin=
g will appear shortly.</p>

--047d7b15ac6d26cd4c04e53d2457--
