Scanned pages/files
Request | Server response | Status |
http://api.getcandid.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 30 Sep 2015 17:53:12 GMT Location: http://www.getcandid.com/ Server: NetDNA-cache/2.2 Content-Length: 148 Content-Type: text/html; charset=UTF-8 X-Cache: MISS | clean |
http://www.getcandid.com/ | 200 OK Content-Length: 25927 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. ...[857 bytes skipped]... hd = "head"; return ["<", hd, "></", hd, "><", i, ' onl' + 'oad="var d=', g, ";d.getElementsByTagName('head')[0].", j, "(d.", h, "('script')).", k, "='", l, "//", a.l, "'", '"', "></", i, ">"].join("") } var i = "body", m = d[i]; if (!m) { return setTimeout(ld, 100) } a.P(1); var j = "appendChild", h = "createElement", k = "src", n = d[h]("div"), v = n[j](d[h](z)), b = d[h]("iframe"), g = "document", e = "domain", o; n.style.display = "none"; m.insertBefore(n, m.firstChild).id = z; b.frameBorder = "0"; b.id = z + "-loader"; if (/MSIE[ ]+6/.test(navigator.userAgent)) { b.src = "javascript:false" } b.allowTransparency = "true"; v[j](b); try { b.contentWindow[g].open() } catch (w) { c[e] = d[e]; o = "javascript:var d=" + g + ".open();d.domain='" + d.domain + "';"; b[k] = o + "void(0);" ...[552 bytes skipped]... Decoded script: function s() { a.P(r); f[z](r); } | ||
http://www.getcandid.com//ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js/ | 404 Not Found Content-Length: 1245 Content-Type: text/html | clean |
http://www.getcandid.com/test404page.js | HTTP/1.1 301 Moved Permanently Date: Wed, 30 Sep 2015 17:53:13 GMT Location: http://www.getcandid.com/test404page.js/ Content-Length: 163 Content-Type: text/html; charset=UTF-8 | clean |
http://www.getcandid.com/test404page.js/ | 404 Not Found Content-Length: 1245 Content-Type: text/html | clean |
http://api.getcandid.com/content/assets/js/modernizr.custom.87724.js | 200 OK Content-Length: 6486 Content-Type: application/javascript | clean |
http://api.getcandid.com/scripts/account.setup.js?v=1.0.5750.36472 | 200 OK Content-Length: 1628 Content-Type: application/javascript | clean |
http://api.getcandid.com//api.getcandid.com/scripts/widget.js/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Wed, 30 Sep 2015 17:53:15 GMT Location: http://www.getcandid.com/api.getcandid.com/scripts/widget.js/ Server: NetDNA-cache/2.2 Content-Length: 184 Content-Type: text/html; charset=UTF-8 X-Cache: MISS | clean |
http://www.getcandid.com/api.getcandid.com/scripts/widget.js/ | HTTP/1.1 302 Found Date: Wed, 30 Sep 2015 17:53:14 GMT Location: /error/404/?aspxerrorpath=/api.getcandid.com/scripts/widget.js/ Content-Length: 180 | clean |
http://www.getcandid.com/error/404/?aspxerrorpath=/api.getcandid.com/scripts/widget.js/ | 200 OK Content-Length: 16459 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. ...[857 bytes skipped]... hd = "head"; return ["<", hd, "></", hd, "><", i, ' onl' + 'oad="var d=', g, ";d.getElementsByTagName('head')[0].", j, "(d.", h, "('script')).", k, "='", l, "//", a.l, "'", '"', "></", i, ">"].join("") } var i = "body", m = d[i]; if (!m) { return setTimeout(ld, 100) } a.P(1); var j = "appendChild", h = "createElement", k = "src", n = d[h]("div"), v = n[j](d[h](z)), b = d[h]("iframe"), g = "document", e = "domain", o; n.style.display = "none"; m.insertBefore(n, m.firstChild).id = z; b.frameBorder = "0"; b.id = z + "-loader"; if (/MSIE[ ]+6/.test(navigator.userAgent)) { b.src = "javascript:false" } b.allowTransparency = "true"; v[j](b); try { b.contentWindow[g].open() } catch (w) { c[e] = d[e]; o = "javascript:var d=" + g + ".open();d.domain='" + d.domain + "';"; b[k] = o + "void(0);" ...[552 bytes skipped]... Decoded script: function s() { a.P(r); f[z](r); } | ||
http://www.getcandid.com/content/assets/js/modernizr.custom.87724.js | 200 OK Content-Length: 6486 Content-Type: application/javascript | clean |
http://api.getcandid.com/scripts/gallery.js?v=1.0.5750.36472 | 200 OK Content-Length: 8957 Content-Type: application/javascript | clean |
http://api.getcandid.com/scripts/jsRender.js?v=1.0.5750.36472 | 200 OK Content-Length: 21788 Content-Type: application/javascript | clean |
http://api.getcandid.com/scripts/main.js?v=1.0.5750.36472 | 200 OK Content-Length: 50886 Content-Type: application/javascript | clean |
http://api.getcandid.com/scripts/fancybox-2.1.5/source/jquery.fancybox.js | 200 OK Content-Length: 50725 Content-Type: application/javascript | clean |
http://api.getcandid.com/content/assets/js/bootstrap.min.js?v=3 | 200 OK Content-Length: 28762 Content-Type: application/javascript | clean |
http://api.getcandid.com/content/assets/js/ddsmoothmenu-min.js | 200 OK Content-Length: 4457 Content-Type: application/javascript | clean |
http://api.getcandid.com/content/assets/js/jquery.dcjqaccordion.2.7.min.js | 200 OK Content-Length: 4209 Content-Type: application/javascript | clean |
http://api.getcandid.com/content/assets/js/jquery.easytabs.min.js | 200 OK Content-Length: 9835 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: api.getcandid.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 30 Sep 2015 17:53:12 GMT
Location: http://www.getcandid.com/
Server: NetDNA-cache/2.2
Content-Length: 148
Content-Type: text/html; charset=UTF-8
X-Cache: MISS
...148 bytes of data.
GET / HTTP/1.1
Host: api.getcandid.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 30 Sep 2015 17:53:12 GMT
Location: http://www.getcandid.com/
Server: NetDNA-cache/2.2
Content-Length: 148
Content-Type: text/html; charset=UTF-8
X-Cache: MISS
...148 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: api.getcandid.com
Referer: http://www.google.com/search?q=api.getcandid.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: api.getcandid.com
Referer: http://www.google.com/search?q=api.getcandid.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=api.getcandid.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://api.getcandid.com/
Result: api.getcandid.com is not infected or malware details are not published yet.
Result: api.getcandid.com is not infected or malware details are not published yet.