Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=city-hotel-bremen.info
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://city-hotel-bremen.info/ | HTTP/1.1 200 OK Connection: close Date: Sat, 27 Dec 2014 00:52:34 GMT Accept-Ranges: bytes ETag: "9f139c5-217e-47fc6f63685b8" Server: Apache Content-Length: 8574 Content-Type: text/html Last-Modified: Wed, 17 Feb 2010 07:40:17 GMT | clean |
http://city-hotel-bremen.info/index2.html | 200 OK Content-Length: 9480 Content-Type: text/html | clean |
http://city-hotel-bremen.info/./include/url.js | 200 OK Content-Length: 26329 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var CM_SESSION_KEY_KEY = "cmSessionKeyKey";
function getSessionPair(loc) { return URL.getSessionPair(loc); } function getSessionHref() { return URL.getSessionHref(); } function processLinkz(doc) { URL.processLinkz(doc); } function getSessionString() { return URL.getSessionString(); } function jdecode(s) { return URL.jdecode(s); } function jencode(s) { return URL.jencode( Antivirus reports:
| ||
http://city-hotel-bremen.info/./include/sitetree.js | 200 OK Content-Length: 18300 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function jdecode(s) { s = s.replace(/\+/g, "%20") return unescape(s); } var POS_NODENAME=0; var POS_ID=1; var POS_NAME=2; var POS_NAVIGATIONTEXT=3; var POS_HREF=4; var POS_ISNAVIGATION=5; var POS_CHILDS=6; var POS_TEMPLATENAME=7; var theSitetree=[ ['PAGE','1110',jdecode('Home'),jdecode(''),'/1110.html','true',[],''], ['PAGE','15820',jdecode('%DCber+uns'),jdecode(''),'/15820.html','true',[],''], Antivirus reports:
| ||
http://city-hotel-bremen.info/test404page.js | 404 Not Found Content-Length: 1363 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: city-hotel-bremen.info
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Dec 2014 00:52:34 GMT
Accept-Ranges: bytes
ETag: "9f139c5-217e-47fc6f63685b8"
Server: Apache
Content-Length: 8574
Content-Type: text/html
Last-Modified: Wed, 17 Feb 2010 07:40:17 GMT
...8574 bytes of data.
GET / HTTP/1.1
Host: city-hotel-bremen.info
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Dec 2014 00:52:34 GMT
Accept-Ranges: bytes
ETag: "9f139c5-217e-47fc6f63685b8"
Server: Apache
Content-Length: 8574
Content-Type: text/html
Last-Modified: Wed, 17 Feb 2010 07:40:17 GMT
...8574 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: city-hotel-bremen.info
Referer: http://www.google.com/search?q=city-hotel-bremen.info
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: city-hotel-bremen.info
Referer: http://www.google.com/search?q=city-hotel-bremen.info
Result:
The result is similar to the first query. There are no suspicious redirects found.