Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=atoz-hotels.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://atoz-hotels.com/ | 200 OK Content-Length: 38814 Content-Type: text/html | clean |
http://atoz-hotels.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-content/plugins/WeatherSlider/js/jquery-animate-background-position.js?ver=2.4.0 | 200 OK Content-Length: 2101 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function($) { if(!document.defaultView || !document.defaultView.getComputedStyle){ var oldCSS = jQuery.css; jQuery.css = function(elem, name, force){ if(name === 'background-position'){ name = 'backgroundPosition'; } if(name !== 'backgroundPosition' || !elem.currentStyle || elem.currentStyle[ name ]){ return oldCSS.apply(this, arguments); } var style = elem.style; if ( !fo fx.start = [start[0],start[2]]; var end = toArray(fx.end); fx.end = [end[0],end[2]]; fx.unit = [end[1],end[3]]; fx.bgPosReady = true; } var nowPosX = []; nowPosX[0] = ((fx.end[0] - fx.start[0]) * fx.pos) + fx.start[0] + fx.unit[0]; nowPosX[1] = ((fx.end[1] - fx.start[1]) * fx.pos) + fx.start[1] + fx.unit[1]; fx.elem.style.backgroundPosition = nowPosX[0]+' '+nowPosX[1]; }; })(jQuery); Antivirus reports:
| ||
http://atoz-hotels.com/wp-content/plugins/WeatherSlider/js/jquery-easing-1.3.js?ver=1.3.0 | 200 OK Content-Length: 8101 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-content/plugins/WeatherSlider/js/weatherslider.kreaturamedia.jquery.js?ver=2.4.0 | 200 OK Content-Length: 25545 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-content/plugins/responsive-flipbook/js/shortcodes.js?ver=3.7.3 | 200 OK Content-Length: 558 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-includes/js/swfobject.js?ver=2.2-20120417 | 200 OK Content-Length: 10233 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-content/plugins/responsive-flipbook/js/jquery.easing.1.3.js?ver=3.7.3 | 200 OK Content-Length: 8102 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-content/plugins/responsive-flipbook/js/jquery.doubletap.js?ver=3.7.3 | 200 OK Content-Length: 3446 Content-Type: application/javascript | clean |
http://atoz-hotels.com/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.revolution.min.js?ver=3.7.3 | 500 Internal Server Error Content-Length: 17703 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/x-javascript | clean |
http://atoz-hotels.com/wp-content/plugins/revslider/rs-plugin/js/./cgi-sys/js/simple-expand.min.js | 500 Internal Server Error Content-Length: 17703 Content-Type: text/html | clean |
http://atoz-hotels.com/wp-content/plugins/revslider/rs-plugin/js/./cgi-sys/js/./cgi-sys/js/simple-expand.min.js | 500 Internal Server Error Content-Length: 17703 Content-Type: text/html | clean |
http://atoz-hotels.com/wp-content/plugins/revslider/rs-plugin/js/./cgi-sys/js/./cgi-sys/js/./cgi-sys/js/simple-expand.min.js | 500 Internal Server Error Content-Length: 17703 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: atoz-hotels.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3, must-revalidate
Connection: close
Date: Fri, 06 Mar 2015 21:11:09 GMT
Server: nginx/1.6.2
Vary: Accept-Encoding,Cookie
Content-Type: text/html; charset=UTF-8
WP-Super-Cache: Served supercache file from PHP
GET / HTTP/1.1
Host: atoz-hotels.com
Result:
HTTP/1.1 200 OK
Cache-Control: max-age=3, must-revalidate
Connection: close
Date: Fri, 06 Mar 2015 21:11:09 GMT
Server: nginx/1.6.2
Vary: Accept-Encoding,Cookie
Content-Type: text/html; charset=UTF-8
WP-Super-Cache: Served supercache file from PHP
Second query (visit from search engine):
GET / HTTP/1.1
Host: atoz-hotels.com
Referer: http://www.google.com/search?q=atoz-hotels.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: atoz-hotels.com
Referer: http://www.google.com/search?q=atoz-hotels.com
Result:
The result is similar to the first query. There are no suspicious redirects found.