Request | Server response | Status |
http://reabcenter.at.ua/forum/6 | 200 OK Content-Length: 16815 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://s48.ucoz.net/src/jquery-1.7.2.js | 200 OK Content-Length: 94840 Content-Type: text/javascript | clean |
http://s48.ucoz.net/src/ulightbox/ulightbox.js | 200 OK Content-Length: 22097 Content-Type: text/javascript | clean |
http://s48.ucoz.net/src/uwnd.js?2 | 200 OK Content-Length: 228554 Content-Type: text/javascript | clean |
http://reabcenter.at.ua/forum/0-0-1-34 | 404 Not Found Content-Length: 6869 Content-Type: text/html | clean |
http://reabcenter.at.ua/ | 200 OK Content-Length: 52534 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/otdelenija_centra/0-2 | 200 OK Content-Length: 59215 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/opkt/0-4 | 200 OK Content-Length: 38620 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/sto/0-5 | 200 OK Content-Length: 40003 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/orv/0-6 | 200 OK Content-Length: 41220 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/osr/0-7 | 200 OK Content-Length: 39991 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/opritv_i_podi/0-8 | 200 OK Content-Length: 47964 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/osms/0-9 | 200 OK Content-Length: 39001 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/oafk/0-10 | 200 OK Content-Length: 59472 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|
http://reabcenter.at.ua/index/viktorija/0-11 | 200 OK Content-Length: 42313 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var temp="",i,c=0,out=""; var str="32!60!116!97!98!108!101!32!99!101!108!108!112!97!100!100!105!110!103!61!34!48!34!32!99!101!108!108!115!112!97!99!105!110!103!61!34!48!34!32!98!111!114!100!101!114!61!34!48!34!32!119!105!100!116!104!61!34!57!53!48!34!32!97!108!105!103!110!61!34!99!101!110!116!101!114!34!62!13!10!32!60!116!114!62!13!10!32!60!116!100!32!99!111!108!115!112!97!110!61!34!50!34!32!104!101!105!103!104!116!61!34!52!54!34!32!115!116!121!108!101!61!34!98!97!99!107!103!114!111!117!110!100!
... 183 bytes are skipped ...14!59!99!111!108!111!114!58!35!97!57!97!57!97!57!59!34!62!60!33!45!45!32!60!99!111!112!121!62!32!45!45!62!60!97!32!104!114!101!102!61!34!104!116!116!112!58!47!47!97!114!116!99!114!101!119!46!110!101!116!46!114!117!47!34!62!68!69!83!73!78!71!32!66!89!32!65!82!84!32!67!82!69!87!60!47!97!62!60!33!45!45!32!60!47!99!111!112!121!62!32!45!45!62!";l=str.length;while(c<=str.length-1){while(str.charAt(c)!='!')temp=temp+str.charAt(c++);c++; out=out+String.fromCharCode(temp);temp="";}document.write(out);Antivirus reports:- AntiVir
- JS/Decdec.psc
- Avast
- JS:Redirector-KP [Trj]
- Ikarus
- Exploit.HTML.IframeRef
- nProtect
- Trojan.JS.QLT
- K7AntiVirus
- Riskware
- TrendMicro-HouseCall
- TROJ_GEN.F47V0122
- Emsisoft
- Trojan.JS.QLT (B)
- Comodo
- TrojWare.JS.Redirect.crk
- McAfee-GW-Edition
- JS/Exploit-Blacole.hv
- DrWeb
- JS.IFrame.180
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- VirTool:JS/Obfuscator.CC
- MicroWorld-eScan
- Trojan.JS.QLT
- Fortinet
- JS/Kryptik.BP!tr
- PCTools
- Trojan.Malscript
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.hv
- NANO-Antivirus
- Trojan.Script.Packed.iagb
- F-Secure
- Trojan.JS.QLT
- VIPRE
- Malware.JS.Generic (JS)
- F-Prot
- JS/Crypted.AT.gen
- eSafe
- JS.Agent.ia
- AVG
- JS/Redir
- Norman
- Redir.GS
- Sophos
- Mal/Iframe-F
- GData
- Trojan.JS.QLT
- Symantec
- Trojan.Malscript!JS
- Commtouch
- JS/Crypted.AT.gen
- Agnitum
- JS.Cored.A
- ESET-NOD32
- JS/Kryptik.BP
- BitDefender
- Trojan.JS.QLT
|