See: This is a suspicious page - N.B. Not for minors: Dr.Web: adult content/social networks
Result for 2015-03-10 21:53:34 UTC
Website: htxp://amisteyengelsin.blogspot.ru
Checked URL: htxp://amisteyengelsin.blogspot.ru/p/hizmetci-kiza-zorla-tecavuz.html
Trojans detected:
Object: htxp://amisteyengelsin.blogspot.ru/p/hizmetci-kiza-zorla-tecavuz.html
SHA1: fc19d434b1de024f1c6e08f555b3815ed12a42fb
Name: TrojWare.JS.Faceliker.ES aka JS:Clickjack-AA [Trj] that Avast detects.
Sucuri misses this infection: http://sitecheck.sucuri.net/results/amisteyengelsin.blogspot.ru
Quttera flags:
-www.blogger.com/static/v1/widgets/4143030425-widgets.js
Severity: Potentially Suspicious
Reason: Detected procedure that is commonly used in suspicious activity.
Details: Too low entropy detected in string [[‘%26tran=%26npn=1%26=%26=%26=%26=%26#false160=%26=%26=%26true=%26=%26=%26=%26ha=%26true=%26=%26=%26=%26=%26ha=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26=%26,=%26=%26=%26=%26h’]] of length 102 which may point to obfuscation or shellcode.
Threat dump: https://www.uploady.com/download/~UbOvlOQ7r6/~n9VVd~nW0f~MVnM
Threat dump MD5: 2D6191B8DF859037D344B474247362DF
File size[byte]: 90344
File type: ASCII
Page/File MD5: 7B523C7E7BC93B3D9B4CC561A856BB6B
Scan duration[sec]: 8.979000 (Adobe Analytics code - pol)
See jsunpack analysis: http://jsunpack.jeek.org/?report=032709e18d1372bbaf6a8df028f6cad536341c50
For security researchers only, open up in browser with NoScript and RequestPolicy extensions active and inside a VM/sandbox.
See: http://www.scumware.org/report/173.194.112.138.html
The tracker tracker report see attached. Do not open links given there inside a browser - for security research purposes only. - pol
pol