Scanned pages/files
Request | Server response | Status |
http://www.marukoo.com/ | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
http://www.nhk.or.jp/lab-blog/blogtools/script/clock150wood.js | 200 OK Content-Length: 337 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<div align="center">');
document.write('<iframe width="150" height="141" frameborder="0" scrolling="no" src="http://www.nhk.or.jp/lab-blog/blogtools/clock/swf/clock150wood.html" allowtransparency="true" style="margin-bottom:10px;">CCt[ÎÌuEUŲ¾³¢B</iframe>'); document.write('</div>'); Antivirus reports:
| ||
http://www.marukoo.com/index.html | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/sub1425.html | 200 OK Content-Length: 6747 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../index.html | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/sub1425.html | 200 OK Content-Length: 6747 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../index.html | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/sub1425.html | 200 OK Content-Length: 6747 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/../index.html | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/../sub2/sub1425.html | 200 OK Content-Length: 6747 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/../sub2/../index.html | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/../sub2/../sub2/sub1425.html | 200 OK Content-Length: 6747 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/../sub2/../sub2/../index.html | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/../sub2/../sub2/../sub2/sub1425.html | 200 OK Content-Length: 6747 Content-Type: text/html | clean |
http://www.marukoo.com/sub2/../sub2/../sub2/../sub2/../sub2/../sub2/../index.html | 200 OK Content-Length: 34336 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: marukoo.com
Result:
GET / HTTP/1.1
Host: marukoo.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: marukoo.com
Referer: http://www.google.com/search?q=marukoo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: marukoo.com
Referer: http://www.google.com/search?q=marukoo.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=marukoo.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://marukoo.com/
Result: marukoo.com is not infected or malware details are not published yet.
Result: marukoo.com is not infected or malware details are not published yet.