New scan:

Malware Scanner report for api.getcandid.com

Malicious/Suspicious/Total urls checked
0/2/19
2 pages have suspicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/0
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://api.getcandid.com/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 30 Sep 2015 17:53:12 GMT
Location: http://www.getcandid.com/
Server: NetDNA-cache/2.2
Content-Length: 148
Content-Type: text/html; charset=UTF-8
X-Cache: MISS
clean
http://www.getcandid.com/
200 OK
Content-Length: 25927
Content-Type: text/html
suspicious
Suspicious code. Script contains iFrame.

...[857 bytes skipped]...
hd = "head"; return ["<", hd, "></", hd, "><", i, ' onl' + 'oad="var d=', g, ";d.getElementsByTagName('head')[0].", j, "(d.", h, "('script')).", k, "='", l, "//", a.l, "'", '"', "></", i, ">"].join("")
} var i = "body", m = d[i]; if (!m) {
return setTimeout(ld, 100)
} a.P(1); var j = "appendChild", h = "createElement", k = "src", n = d[h]("div"), v = n[j](d[h](z)), b = d[h]("iframe"), g = "document", e = "domain", o; n.style.display = "none"; m.insertBefore(n, m.firstChild).id = z; b.frameBorder = "0"; b.id = z + "-loader"; if (/MSIE[ ]+6/.test(navigator.userAgent)) {
b.src = "javascript:false"
} b.allowTransparency = "true"; v[j](b); try {
b.contentWindow[g].open()
} catch (w) {
c[e] = d[e]; o = "javascript:var d=" + g + ".open();d.domain='" + d.domain + "';"; b[k] = o + "void(0);" ...[552 bytes skipped]...

Decoded script:


function s() {
a.P(r);
f[z](r);
}

http://www.getcandid.com//ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js/
404 Not Found
Content-Length: 1245
Content-Type: text/html
clean
http://www.getcandid.com/test404page.js
HTTP/1.1 301 Moved Permanently
Date: Wed, 30 Sep 2015 17:53:13 GMT
Location: http://www.getcandid.com/test404page.js/
Content-Length: 163
Content-Type: text/html; charset=UTF-8
clean
http://www.getcandid.com/test404page.js/
404 Not Found
Content-Length: 1245
Content-Type: text/html
clean
http://api.getcandid.com/content/assets/js/modernizr.custom.87724.js
200 OK
Content-Length: 6486
Content-Type: application/javascript
clean
http://api.getcandid.com/scripts/account.setup.js?v=1.0.5750.36472
200 OK
Content-Length: 1628
Content-Type: application/javascript
clean
http://api.getcandid.com//api.getcandid.com/scripts/widget.js/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 30 Sep 2015 17:53:15 GMT
Location: http://www.getcandid.com/api.getcandid.com/scripts/widget.js/
Server: NetDNA-cache/2.2
Content-Length: 184
Content-Type: text/html; charset=UTF-8
X-Cache: MISS
clean
http://www.getcandid.com/api.getcandid.com/scripts/widget.js/
HTTP/1.1 302 Found
Date: Wed, 30 Sep 2015 17:53:14 GMT
Location: /error/404/?aspxerrorpath=/api.getcandid.com/scripts/widget.js/
Content-Length: 180
clean
http://www.getcandid.com/error/404/?aspxerrorpath=/api.getcandid.com/scripts/widget.js/
200 OK
Content-Length: 16459
Content-Type: text/html
suspicious
Suspicious code. Script contains iFrame.

...[857 bytes skipped]...
hd = "head"; return ["<", hd, "></", hd, "><", i, ' onl' + 'oad="var d=', g, ";d.getElementsByTagName('head')[0].", j, "(d.", h, "('script')).", k, "='", l, "//", a.l, "'", '"', "></", i, ">"].join("")
} var i = "body", m = d[i]; if (!m) {
return setTimeout(ld, 100)
} a.P(1); var j = "appendChild", h = "createElement", k = "src", n = d[h]("div"), v = n[j](d[h](z)), b = d[h]("iframe"), g = "document", e = "domain", o; n.style.display = "none"; m.insertBefore(n, m.firstChild).id = z; b.frameBorder = "0"; b.id = z + "-loader"; if (/MSIE[ ]+6/.test(navigator.userAgent)) {
b.src = "javascript:false"
} b.allowTransparency = "true"; v[j](b); try {
b.contentWindow[g].open()
} catch (w) {
c[e] = d[e]; o = "javascript:var d=" + g + ".open();d.domain='" + d.domain + "';"; b[k] = o + "void(0);" ...[552 bytes skipped]...

Decoded script:


function s() {
a.P(r);
f[z](r);
}

http://www.getcandid.com/content/assets/js/modernizr.custom.87724.js
200 OK
Content-Length: 6486
Content-Type: application/javascript
clean
http://api.getcandid.com/scripts/gallery.js?v=1.0.5750.36472
200 OK
Content-Length: 8957
Content-Type: application/javascript
clean
http://api.getcandid.com/scripts/jsRender.js?v=1.0.5750.36472
200 OK
Content-Length: 21788
Content-Type: application/javascript
clean
http://api.getcandid.com/scripts/main.js?v=1.0.5750.36472
200 OK
Content-Length: 50886
Content-Type: application/javascript
clean
http://api.getcandid.com/scripts/fancybox-2.1.5/source/jquery.fancybox.js
200 OK
Content-Length: 50725
Content-Type: application/javascript
clean
http://api.getcandid.com/content/assets/js/bootstrap.min.js?v=3
200 OK
Content-Length: 28762
Content-Type: application/javascript
clean
http://api.getcandid.com/content/assets/js/ddsmoothmenu-min.js
200 OK
Content-Length: 4457
Content-Type: application/javascript
clean
http://api.getcandid.com/content/assets/js/jquery.dcjqaccordion.2.7.min.js
200 OK
Content-Length: 4209
Content-Type: application/javascript
clean
http://api.getcandid.com/content/assets/js/jquery.easytabs.min.js
200 OK
Content-Length: 9835
Content-Type: application/javascript
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: api.getcandid.com

Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Wed, 30 Sep 2015 17:53:12 GMT
Location: http://www.getcandid.com/
Server: NetDNA-cache/2.2
Content-Length: 148
Content-Type: text/html; charset=UTF-8
X-Cache: MISS

...148 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: api.getcandid.com
Referer: http://www.google.com/search?q=api.getcandid.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=api.getcandid.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://api.getcandid.com/

Result: api.getcandid.com is not infected or malware details are not published yet.