Malware Signatures

  1. Home
  2. Malware Signatures
  3. js.spam-seo.iframe-doorway.002


This script can be found on doorway pages created by hackers. It creates a full window size iframe that loads a third party site (e.g. some e-commerce site that spammers promote). On some sites, this script can be in standalone .js files, included by .html doorway files.
Variant of iframe-doorways.


Any type of site.


You should remove the doorway files and .js files with the malicious code. Usually there is also some infected PHP files that make doorways work differently for bots and human visitors. You can contact Sucuri to help you with the infection removal.


var _$=["x3Cx64x69x76x20x73x74x79x6Cx65x3Dx27x7...this part may vary... x3Ex3Cx2Fx64x69x76x3E"];document.writeln(_$[0]);