New scan:

Malware Scanner report for 3dsleaks.crabdance.com

Malicious/Suspicious/Total urls checked
0/0/22
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: 3dsleaks.crabdance.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 17 Dec 2014 04:08:06 GMT
Accept-Ranges: bytes
ETag: "f2b-50a5008cad51d"
Server: Apache/2.4.6 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 3883
Content-Type: text/html
Last-Modified: Tue, 16 Dec 2014 07:09:04 GMT

...3883 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: 3dsleaks.crabdance.com
Referer: http://www.google.com/search?q=3dsleaks.crabdance.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Scanned pages/files

RequestServer responseStatus
http://3dsleaks.crabdance.com/
200 OK
Content-Length: 3883
Content-Type: text/html
clean
http://s7.addthis.com/js/250/addthis_widget.js
200 OK
Content-Length: 6909
Content-Type: text/javascript
clean
http://3dsleaks.crabdance.com/terms.html
200 OK
Content-Length: 12789
Content-Type: text/html
clean
http://3dsleaks.crabdance.com/privacy.html
200 OK
Content-Length: 13339
Content-Type: text/html
clean
http://3dsleaks.crabdance.com/test404page.js
HTTP/1.1 302 Found
Connection: close
Date: Wed, 17 Dec 2014 04:08:07 GMT
Location: http://sameid.net/limit.html
Server: Apache/2.4.6 (Ubuntu)
Content-Length: 212
Content-Type: text/html; charset=iso-8859-1
Set-Cookie: uri=%2Ftest404page%2Ejs;Path=/;Max-Age=31536000
Set-Cookie: ref=direct;Path=/;Max-Age=31536000
clean
http://sameid.net/limit.html
200 OK
Content-Length: 5242
Content-Type: text/html
clean
http://sameid.net/
200 OK
Content-Length: 3883
Content-Type: text/html
clean
http://sameid.net/terms.html
200 OK
Content-Length: 12789
Content-Type: text/html
clean
http://sameid.net/privacy.html
200 OK
Content-Length: 13339
Content-Type: text/html
clean
http://sameid.net/test404page.js
404 Not Found
Content-Length: 3296
Content-Type: text/html
clean
http://3dsleaks.crabdance.com/order?plan=pp-oneday
HTTP/1.1 302 Found
Connection: close
Date: Wed, 17 Dec 2014 04:08:11 GMT
Location: https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&business=iiveras.lt%40gmail.com&amount=9.99&no_note=1&custom=-1000-no-1-05646eca&no_shipping=1&return=http%3A%2F%2Fsameid.net%2Fthankyou&rm=2&item_name=SameID%20One%20Day%20Access%20-%201000%20requests
Server: Apache/2.4.6 (Ubuntu)
Content-Length: 467
Content-Type: text/html; charset=iso-8859-1
clean
https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&business=iiveras.lt%40gmail.com&amount=9.99&no_note=1&custom=-1000-no-1-05646eca&no_shipping=1&return=http%3a%2f%2fsameid.net%2fthankyou&rm=2&item_name=sameid%20one%20day%20access%20-%201000%20requests
HTTP/1.1 302 Moved Temporarily
Connection: close
Connection: Transfer-Encoding
Date: Wed, 17 Dec 2014 04:08:16 GMT
Location: https://www.paypal.com/lt/cgi-bin/webscr?cmd=_flow&SESSION=tD3zJkDUiPZ7AYcf3okrpgZYoOx0etiPnEV1ULM6VJka0kYzWZdsCRYFzku&dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198d8562aa8a3da7ac30bbfba73b3e80dcc
Server: Apache
Content-Encoding: gzip
Content-Type: text/html
DC: slc-a-origin-www-2.paypal.com
Set-Cookie: cwrClyrK4LoCV1fydGbAxiNL6iG=yrfIERjXe5RnCA_9qNrcyase3gfW9QQFJFOcucMepi2pPKQ-2YKcxgRvde8eMlrVutxbZ07VIGXEC94IqRHlfF0NS-E6S7HOTBfI_BjTVUItVhhW4UYsvSYKPhrYuMJToxAsF4aC3CpRwBPbSU4tL9JTVytMot1bf-0K1C2MpiHC-Ch0PontZvs0CLT6bxrCvHS9lvuJr7acX5bNuF_rc6WSV3Sn_TlTlzV_TXgGkFlAOV0yIYLcCd9Fak8; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: KHcl0EuY7AKSMgfvHl7J5E7hPtK=pJcth3xqd5jKW7xiz9_iAele8V6ZQge391sUxuUPMVrhuhGC6xlfLnn267W1yxTSa9tMQG2168z985TV; expires=Tue, 12-Dec-2034 04:08:15 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: cookie_check=yes; expires=Sat, 14-Dec-2024 04:08:15 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: navcmd=_xclick; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: abc_switch_cross_paypal=R1190%26WPSG%3da%40500%7c1418875695%7ce%3bv%3bw%3b6%26; expires=Fri, 27-Mar-2015 04:08:15 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: tYO7fcUaay8ZtLdfOSkkxbhU8o0=IC5WJaqhowolQUYB_VxMWWF7ffNJPJuxwss5EaALPYLj5Dstb0uQElaLw8vRQRC1RTHfTW; expires=Sun, 15-Feb-2015 04:08:15 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: pNTcMTtQfrJuaJiwEnWXQ6yNxfq=nTqBOaZSFNMimOSTyRzQSVxMU08W2Fn0xVFaubPklNkfEX053nSKzn1WRi6BfzokUHOBOQajWXw_SZNlpZXR76sQBVDp7Vp3cDtz_R-L5T5ZhhtCBRfCKURJ5kaajYr8V6dDRIjuYBQGYWtWQSMaTo0ckG-Q3YTC0wWM491Hf23UanNr8tHw_isF85rSJBe-xd-Mr-CzxcVcv8vUs86bytt6GAhWzJAUOyS04D9C2esQZUOh_NsErzbRFyx7MJNZmLOIbepXOOklyhTknY_pZWYeJC3OHGI2jSwIwqnyvbgDYlLiyw0aqqDcMDI_ZpaAPlOLLa9oQTZ4u6S-CEWdbAcrs6cZ1YkZH0VNq9J9-RpwrvOi; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: Apache=10.73.8.134.1418789295329887; path=/; expires=Fri, 09-Dec-44 04:08:15 GMT
Set-Cookie: X-PP-SILOVER=name%3DLIVE5.WEB.1%26silo_version%3D880%26app%3Dappdisp%26TIME%3D2936115540; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: X-PP-SILOVER=; Expires=Thu, 01 Jan 1970 00:00:01 GMT
Set-Cookie: Apache=10.73.8.57.1418789295319900; path=/; expires=Fri, 09-Dec-44 04:08:15 GMT
Set-Cookie: AKDC=slc-a-origin-www-2.paypal.com; expires=Wed, 17-Dec-2014 04:38:16 GMT; path=/; secure
Strict-Transport-Security: max-age=63072000
X-Frame-Options: SAMEORIGIN
clean
https://www.paypal.com/lt/cgi-bin/webscr?cmd=_flow&session=td3zjkduipz7aycf3okrpgzyoox0etipnev1ulm6vjka0kyzwzdscryfzku&dispatch=50a222a57771920b6a3d7b606239e4d529b525e0b7e69bf0224adecfb0124e9b61f737ba21b08198d8562aa8a3da7ac30bbfba73b3e80dcc
200 OK
Content-Length: 14355
Content-Type: text/html
clean
https://www.paypalobjects.com/WEBSCR-640-20141004-1/js/lib/min/global.js
200 OK
Content-Length: 61553
Content-Type: application/x-javascript
clean
https://www.paypalobjects.com/WEBSCR-640-20141004-1/js/lib/min/widgets.js
200 OK
Content-Length: 142696
Content-Type: application/x-javascript
clean
https://www.paypalobjects.com/WEBSCR-640-20141004-1/js/site_catalyst/pp_jscode_080706.js
200 OK
Content-Length: 61883
Content-Type: application/x-javascript
clean
http://3dsleaks.crabdance.com/order?plan=pp-premium
HTTP/1.1 302 Found
Connection: close
Date: Wed, 17 Dec 2014 04:08:15 GMT
Location: https://www.paypal.com/cgi-bin/webscr?cmd=_xclick-subscriptions&business=iiveras.lt%40gmail.com&a3=19.99&p3=1&t3=M&src=1&no_note=1&custom=-300-yes-32-8f5af0e9&no_shipping=1&return=http%3A%2F%2Fsameid.net%2Fthankyou&rm=2&item_name=SameID%20Premium%20-%20300%20requests%2Fday
Server: Apache/2.4.6 (Ubuntu)
Content-Length: 501
Content-Type: text/html; charset=iso-8859-1
clean
https://www.paypal.com/cgi-bin/webscr?cmd=_xclick-subscriptions&business=iiveras.lt%40gmail.com&a3=19.99&p3=1&t3=m&src=1&no_note=1&custom=-300-yes-32-8f5af0e9&no_shipping=1&return=http%3a%2f%2fsameid.net%2fthankyou&rm=2&item_name=sameid%20premium%20-%20300%20requests%2fday
HTTP/1.1 302 Moved Temporarily
Connection: close
Connection: Transfer-Encoding
Date: Wed, 17 Dec 2014 04:08:19 GMT
Location: https://www.paypal.com/lt/cgi-bin/webscr?cmd=_flow&SESSION=BoMDUA3LbqCIOvpFXSW_-tlusOWJ8i7wzthdyAk-4Vtqq-hgyXr0_hDUxoe&dispatch=5885d80a13c0db1f8e263663d3faee8d66f31424b43e9a70645c907a6cbd8fb4
Server: Apache
Content-Encoding: gzip
Content-Type: text/html
DC: slc-a-origin-www-2.paypal.com
Set-Cookie: cwrClyrK4LoCV1fydGbAxiNL6iG=tKNiLmSeB6pox3MJ9jpn2ZbhJxFGS0AUxPh3klOu46g-GltvXxufiUv3G9hxTWAFNSprDYDX-SHxdT9aO5SHUsyKjYeRNrGV0ML1qDymlCIsfXX04DULxiSnKI8ZYJ5gbxu3tKsCH7VfUsa30XY_z8jIcJG4G3w5jkLnRW2BsOznR6Z_Hgl7I_COHK7sy_oGWcMYEfr1PsliSWMz5A6AXdVENU81TR7VcHUb-J2AJLeJ7qxcYzXaCxgBrDcNyz638WKUx0W6SWobH81WO7Ht276U95d357OfnLCK6iVi8TLl1M-1z4LTnzyV4llT6PK3ONsahXFBCQg22QnYgRR4OSjQ-xwmVP56Ujh8-GSNxhC4Ll97UDn4ly3HHvHGmiOqlAqepggUHBSu8eklfPFofFMNp_7C8hs7SSkzu9DVD41bDMnkpwiHyDJeco4; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: KHcl0EuY7AKSMgfvHl7J5E7hPtK=8pNT31QIBhuUmvfJVZVnRNRPvpf4ahGp5oSPbGnNCStPmb2jnfJc9uukT4i55H6nkDI79CdxapAtqdrr; expires=Tue, 12-Dec-2034 04:08:19 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: cookie_check=yes; expires=Sat, 14-Dec-2024 04:08:19 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: navcmd=_xclick-subscriptions; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: pNTcMTtQfrJuaJiwEnWXQ6yNxfq=06uZGvOFtgMWLvef6WtfxGhEXvAp3hu-vrlamKn9pABcd_anopXo0ijXu1M_ILVmjkpDKTOuc-I4_O83UxfCbpWswvoZeoFEp3o9wBWfNNfgjkxTZEvqIvTYYQKJr4obAcwSzF73hKgB_kv-e_UxT8EAGdJcN3zCGfqqIJ98DEm7zgVUU8HFkmYo6dBKJ68VZ2ujFCu6ERhrInB6AePwDX67Lver1eYQqVEcoh4V3aR0bqyO_bo1GV4VK0Zabd2FGswee_eRkRp1N5thQTXJ1A8u8ClgkNMPNE9rlYL-MnDLid9QFY7BlHZaiI84smWq98SECO1s7vGNSyRQAk_L2S5l0DQ8UBS_Biqjco4_3QUCt5ep; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: navlns=0.0; expires=Fri, 16-Dec-2016 04:08:19 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: Apache=10.73.8.137.1418789299151867; path=/; expires=Fri, 09-Dec-44 04:08:19 GMT
Set-Cookie: X-PP-SILOVER=name%3DLIVE5.WEB.1%26silo_version%3D880%26app%3Dslingshot%26TIME%3D3003224404; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: X-PP-SILOVER=; Expires=Thu, 01 Jan 1970 00:00:01 GMT
Set-Cookie: Apache=10.73.8.68.1418789299141584; path=/; expires=Fri, 09-Dec-44 04:08:19 GMT
Set-Cookie: AKDC=slc-a-origin-www-2.paypal.com; expires=Wed, 17-Dec-2014 04:38:19 GMT; path=/; secure
Strict-Transport-Security: max-age=63072000
X-Frame-Options: SAMEORIGIN
clean
https://www.paypal.com/lt/cgi-bin/webscr?cmd=_flow&session=bomdua3lbqciovpfxsw_-tlusowj8i7wzthdyak-4vtqq-hgyxr0_hduxoe&dispatch=5885d80a13c0db1f8e263663d3faee8d66f31424b43e9a70645c907a6cbd8fb4
200 OK
Content-Length: 54
Content-Type: text/html
clean
http://3dsleaks.crabdance.com/order?plan=pp-business
HTTP/1.1 302 Found
Connection: close
Date: Wed, 17 Dec 2014 04:08:16 GMT
Location: https://www.paypal.com/cgi-bin/webscr?cmd=_xclick-subscriptions&business=iiveras.lt%40gmail.com&a3=59.99&p3=1&t3=M&src=1&no_note=1&custom=-3000-yes-32-31faf08b&no_shipping=1&return=http%3A%2F%2Fsameid.net%2Fthankyou&rm=2&item_name=SameID%20Business%20-%203000%20requests%2Fday
Server: Apache/2.4.6 (Ubuntu)
Content-Length: 504
Content-Type: text/html; charset=iso-8859-1
clean
https://www.paypal.com/cgi-bin/webscr?cmd=_xclick-subscriptions&business=iiveras.lt%40gmail.com&a3=59.99&p3=1&t3=m&src=1&no_note=1&custom=-3000-yes-32-31faf08b&no_shipping=1&return=http%3a%2f%2fsameid.net%2fthankyou&rm=2&item_name=sameid%20business%20-%203000%20requests%2fday
HTTP/1.1 302 Moved Temporarily
Connection: close
Connection: Transfer-Encoding
Date: Wed, 17 Dec 2014 04:08:21 GMT
Location: https://www.paypal.com/lt/cgi-bin/webscr?cmd=_flow&SESSION=ICfuPAMitxeP-c9a70vRucXprBpuYKVQeNP0fqVCTK77RiUxq80dQL6uzly&dispatch=5885d80a13c0db1f8e263663d3faee8d66f31424b43e9a70645c907a6cbd8fb4
Server: Apache
Content-Encoding: gzip
Content-Type: text/html
DC: slc-a-origin-www-2.paypal.com
Set-Cookie: cwrClyrK4LoCV1fydGbAxiNL6iG=xJdr6F9RaK42KM8Hzjq4ORcx2UZx66oMVtE3YzNS4jT5IuOmRfKMbEof94CuGZUZmYAje9oDmS_VJyLoIPnce8cdfnxyvLAt_e1orqX35R14oYMz4GCfv4VUWL-vZX7YAu9F5eWEN-ZTqSf_COjWXWFAaBBytLYryY_YfusPzfXrxaplLMQPDY-dVtmRZINPMHxQeVKQipmM8cjWcxjf6DeT-way72b2_d37yNHacwU3Vx7XMqDZUkTPB8ZLp4NcR1oo6nMXokYP7BwAx-FPBvpfp-44vAp7TVgAjH_iP-4O6kRwiKfQDpHM-r_dFoNEQ854I7F41jZvCqYmONACHgQjAmrGQIz2mTsJsjOoigLVGndZ7Vtat6bSVqA_a9pVZRuLWjbabGSLagPM6v2TnEHJqUCp408qrhauyVYglA-1UpGHsElLw422oAC; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: KHcl0EuY7AKSMgfvHl7J5E7hPtK=32vvi9LsBwOrwznwE8QcC726T_I6NVjnT7dzMyYVYi7PjlnbJLQgkC1LZDW2snVJAa074q6F1ueKeWi2; expires=Tue, 12-Dec-2034 04:08:21 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: cookie_check=yes; expires=Sat, 14-Dec-2024 04:08:21 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: navcmd=_xclick-subscriptions; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: pNTcMTtQfrJuaJiwEnWXQ6yNxfq=62wQ1bDWoliMba13Xo1mJiOYXGnVhPHS-2Iwjc42MvHKEGS0ErsWjZOYcpW-gOCzN8xVlsR_45zv1QO0utZhuKbj0LXKCB5WQ2wy4IDPciDrKhoZpRsz7MVdvcAcZgykicV5IoSfXw_thY1xcg8QilCNcn9xAu_WnFAwezuk6El0nWagVR3K5HsupUxGc3tbQZvhnuOdkUY2AiYFus5N--jH4riPuuelYLuQpqSt6B31Prha2-BE2yyMnCOeEiawWcfOuocD-KxuHACCq-VW8dx82Oy3nNesv1-NX6NWdNnuUah10x7P8PbuskfFNAtwxCZRRxIR6fUYjThD6Gr4s0LF3W3Ojp4e34yhGT3EDXN2c7kk; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: navlns=0.0; expires=Fri, 16-Dec-2016 04:08:21 GMT; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: Apache=10.73.8.137.1418789300666997; path=/; expires=Fri, 09-Dec-44 04:08:20 GMT
Set-Cookie: X-PP-SILOVER=name%3DLIVE5.WEB.1%26silo_version%3D880%26app%3Dslingshot%26TIME%3D3020001620; domain=.paypal.com; path=/; Secure; HttpOnly
Set-Cookie: X-PP-SILOVER=; Expires=Thu, 01 Jan 1970 00:00:01 GMT
Set-Cookie: Apache=10.73.8.57.1418789300656689; path=/; expires=Fri, 09-Dec-44 04:08:20 GMT
Set-Cookie: AKDC=slc-a-origin-www-2.paypal.com; expires=Wed, 17-Dec-2014 04:38:21 GMT; path=/; secure
Strict-Transport-Security: max-age=63072000
X-Frame-Options: SAMEORIGIN
clean
https://www.paypal.com/lt/cgi-bin/webscr?cmd=_flow&session=icfupamitxep-c9a70vrucxprbpuykvqenp0fqvctk77riuxq80dql6uzly&dispatch=5885d80a13c0db1f8e263663d3faee8d66f31424b43e9a70645c907a6cbd8fb4
200 OK
Content-Length: 54
Content-Type: text/html
clean

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=3dsleaks.crabdance.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://3dsleaks.crabdance.com/

Result: 3dsleaks.crabdance.com is not infected or malware details are not published yet.