Scanned pages/files
Request | Server response | Status |
http://aledrusservices.com/ | 200 OK Content-Length: 2689 Content-Type: text/html | clean |
http://aledrusservices.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Tue, 30 Sep 2014 12:55:50 GMT Location: http://bizpartner.com.my/error404.php Server: Apache Content-Length: 221 Content-Type: text/html; charset=iso-8859-1 | clean |
http://bizpartner.com.my/error404.php | 200 OK Content-Length: 31314 Content-Type: text/html | clean |
http://w.sharethis.com/button/buttons.js | 200 OK Content-Length: 145774 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) if(typeof(stlib)=="undefined"){var stlib={}}if(!stlib.functions){stlib.functions=[];stlib.functionCount=0}stlib.global={};stlib.global.hash=document.location.href.split("#");stlib.global.hash.shift();stlib.global.hash=stlib.global.hash.join("#");stlib.dynamicOn=true;stlib.debugOn=false;stlib.debug={count:0,messages:[],debug:function(b,a){if(a&&(typeof console)!="undefined"){console.log(b)}stlib.debug.messages.push(b)},show:function(a){for(message in stlib.debug.messages){if((typeof conso Antivirus reports:
| ||
http://bizpartner.com.my/common.js | 200 OK Content-Length: 2793 Content-Type: application/javascript | clean |
http://bizpartner.com.my/prototype.js | 200 OK Content-Length: 47445 Content-Type: application/javascript | clean |
http://sm3.sitemeter.com/js/counter.js?site=sm3bizpartner | HTTP/1.1 302 Redirect Date: Tue, 30 Sep 2014 12:56:02 GMT Location: http://sm3.sitemeter.com/js/counter.asp?site=sm3bizpartner Server: Microsoft-IIS/6.0 Content-Length: 181 Content-Type: text/html X-Powered-By: ASP.NET | clean |
http://sm3.sitemeter.com/js/counter.asp?site=sm3bizpartner | 200 OK Content-Length: 7561 Content-Type: application/x-javascript | clean |
http://aledrusservices.com/testimonies | HTTP/1.1 302 Found Connection: close Date: Tue, 30 Sep 2014 12:56:02 GMT Location: http://bizpartner.com.my/error404.php Server: Apache Content-Length: 221 Content-Type: text/html; charset=iso-8859-1 | clean |
http://bizpartner.com.my/test404page.js | HTTP/1.1 302 Found Connection: close Date: Tue, 30 Sep 2014 12:55:57 GMT Location: http://bizpartner.com.my/error404.php Server: Apache Content-Length: 221 Content-Type: text/html; charset=iso-8859-1 | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: aledrusservices.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 30 Sep 2014 12:55:45 GMT
Server: Apache
Content-Length: 46350
Content-Type: text/html; charset=UTF-8
X-Died: timeout at scan.pm line 1546.
X-Pingback: http://aledrusservices.com/xmlrpc.php
X-Powered-By: PHP/5.3.29
...46350 bytes of data.
GET / HTTP/1.1
Host: aledrusservices.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 30 Sep 2014 12:55:45 GMT
Server: Apache
Content-Length: 46350
Content-Type: text/html; charset=UTF-8
X-Died: timeout at scan.pm line 1546.
X-Pingback: http://aledrusservices.com/xmlrpc.php
X-Powered-By: PHP/5.3.29
...46350 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: aledrusservices.com
Referer: http://www.google.com/search?q=aledrusservices.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: aledrusservices.com
Referer: http://www.google.com/search?q=aledrusservices.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=aledrusservices.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://aledrusservices.com/
Result: aledrusservices.com is not infected or malware details are not published yet.
Result: aledrusservices.com is not infected or malware details are not published yet.