Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=2dayjok.ir
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://2dayjok.ir/ | 200 OK Content-Length: 216940 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) document.write ('<center><iframe width="120" height="240" src="http://ads.rzb.ir/image.php?size_id=7" border="0" scrolling="no" frameborder="0" marginheight="0" marginwidth="0" vspace="0" hspace="0"></iframe>'); Decoded script: <style>iframe{display:block;}</style> Antivirus reports:
| ||
http://2dayjok.ir/js/site.js | 200 OK Content-Length: 19046 Content-Type: application/javascript | clean |
http://rozblog.com/temp/skin/taktadownload/jquery.js | 200 OK Content-Length: 58135 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){var l=this,g,y=l.jQuery,p=l.$,o=l.jQuery=l.$=function(E,F){return new o.fn.init(E,F)},D=/^[^<]*(<(.|\s)+>)[^>]*$|^#([\w-]+)$/,f=/^.[^:#\[\.,]*$/;o.fn=o.prototype={init:function(E,H){E=E||document;if(E.nodeType){this[0]=E;this.length=1;this.context=E;return this}if(typeof E==="string"){var G=D.exec(E);if(G&&(G[1]||!H)){if(G[1]){E=o.clean([G[1]],H)}else{var I=document.getElementById(G[3]);if(I&&I.id!=G[3]){return o().find(E)}var F=o(I||[]);F.context=document Antivirus reports:
| ||
http://rozblog.com/temp/skin/taktadownload/preloader.js | 200 OK Content-Length: 2619 Content-Type: application/javascript | clean |
http://rozblog.com/temp/skin/taktadownload/script.js | 200 OK Content-Length: 5190 Content-Type: application/javascript | clean |
http://rozblog.com/temp/skin/taktadownload/tick.js | 200 OK Content-Length: 1557 Content-Type: application/javascript | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.9.0/jquery.min.js | 200 OK Content-Length: 93068 Content-Type: text/javascript | clean |
http://up.2dayjok.ir/up/2dayjok/Documents/Scripts/jquery.flip.min.js | 200 OK Content-Length: 4217 Content-Type: application/javascript | clean |
http:///show.php?user=10827&type=1 | 500 No Host option provided Content-Length: 73 Content-Type: text/plain | clean |
http:///test404page.js | 500 No Host option provided Content-Length: 73 Content-Type: text/plain | clean |
http://tabligheirani.com/showads.php?webid=1a4a5f89e71e4bb9973355c964a950b4&s=3 | 200 OK Content-Length: 1123 Content-Type: text/html | clean |
http://www.webgozar.ir/c.aspx?Code=2504326&t=counter | 200 OK Content-Length: 973 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 0x0 src: http://engine.webgozar.ir/counter/xstat.aspx?t=stat6&code=2504326&rnd= <iframe scrolling=no width=0 height=0 border=0 frameborder=0 allowtransparency="true" src="http://engine.webgozar.ir/counter/xstat.aspx?t=stat6&code=2504326&rnd=' + math.round(math.random()*50000) + '&s=' + screensize + '&c=' + colors + '&ref=' + escape(document.referrer) + '&title=' + escape(document.title) + '" > | ||
http://www.persianstat.com/service/stat.js | 200 OK Content-Length: 6631 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 2dayjok.ir
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 13 Oct 2014 16:37:29 GMT
Pragma: no-cache
Server: LiteSpeed
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=6e2256cf51ca13a480db71e910a80c4f; path=/
Set-Cookie: ban_ip=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: 2dayjok.ir
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 13 Oct 2014 16:37:29 GMT
Pragma: no-cache
Server: LiteSpeed
Content-Type: text/html; charset=utf-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=6e2256cf51ca13a480db71e910a80c4f; path=/
Set-Cookie: ban_ip=deleted; expires=Thu, 01-Jan-1970 00:00:01 GMT
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: 2dayjok.ir
Referer: http://www.google.com/search?q=2dayjok.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 2dayjok.ir
Referer: http://www.google.com/search?q=2dayjok.ir
Result:
The result is similar to the first query. There are no suspicious redirects found.