Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=blogs.jta.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://blogs.jta.org/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: 2b0af.kd3d.com
Result:
GET / HTTP/1.1
Host: 2b0af.kd3d.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: 2b0af.kd3d.com
Referer: http://www.google.com/search?q=2b0af.kd3d.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: 2b0af.kd3d.com
Referer: http://www.google.com/search?q=2b0af.kd3d.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://blogs.jta.org/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=432000 Connection: close Date: Fri, 26 Sep 2014 13:35:29 GMT Via: 1.1 varnish Age: 27514 Location: http://www.jta.org/ Server: Apache/2.2.22 (Ubuntu) Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Expires: Wed, 01 Oct 2014 05:56:55 GMT X-Cache: HIT X-Varnish: 1032893170 1032625449 | malicious |
http://www.jta.org/ | 200 OK Content-Length: 116401 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> | ||
http://www.jta.org/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/plugins/mailchimp/js/scrollTo.js?ver=1.4.1 | 200 OK Content-Length: 2262 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/jquery/jquery.form.min.js?ver=3.37.0 | 200 OK Content-Length: 14720 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/plugins/mailchimp/js/mailchimp.js?ver=1.4.1 | 200 OK Content-Length: 1054 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/jquery/ui/jquery.ui.core.min.js?ver=1.10.4 | 200 OK Content-Length: 4289 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/plugins/mailchimp//js/datepicker.js?ver=4.0 | 200 OK Content-Length: 75876 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/tinymce/tinymce.min.js?ver=4.0 | 200 OK Content-Length: 301201 Content-Type: application/x-javascript | clean |
http://blogs.jta.org//code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=432000 Connection: close Date: Fri, 26 Sep 2014 13:35:35 GMT Via: 1.1 varnish Age: 0 Location: http://www.jta.org/?ver=4.0/ Server: Apache/2.2.22 (Ubuntu) Vary: Accept-Encoding Content-Type: text/html; charset=iso-8859-1 Expires: Wed, 01 Oct 2014 13:35:35 GMT X-Cache: MISS X-Varnish: 1032893306 | malicious |
http://www.jta.org/?ver=4.0/ | 200 OK Content-Length: 116365 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> | ||
http://www.jta.org//code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 26 Sep 2014 13:35:37 GMT Pragma: no-cache Via: 1.1 varnish Age: 174 Location: http://www.jta.org/code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ Server: nginx/1.1.19 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Cache: HIT X-Pingback: http://www.jta.org/xmlrpc.php X-Powered-By: PHP/5.3.10-1ubuntu3.6 X-Varnish: 1032893327 1032891322 | clean |
http://www.jta.org/code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ | 404 Not Found Content-Length: 76075 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> | ||
http://www.jta.org/wp-content/themes/jta/static/js/picturefill.js?ver=4.0 | 200 OK Content-Length: 1771 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/themes/jta/static/js/jquery.easing.1.3.js?ver=4.0 | 200 OK Content-Length: 8097 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/themes/jta/static/js/slides.min.jquery.js?ver=4.0 | 200 OK Content-Length: 6739 Content-Type: application/x-javascript | clean |
http://www.jta.org//s7.addthis.com/js/300/addthis_widget.js?ver=4.0/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 26 Sep 2014 13:35:39 GMT Pragma: no-cache Via: 1.1 varnish Age: 172 Location: http://www.jta.org/s7.addthis.com/js/300/addthis_widget.js?ver=4.0/ Server: nginx/1.1.19 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Cache: HIT X-Pingback: http://www.jta.org/xmlrpc.php X-Powered-By: PHP/5.3.10-1ubuntu3.6 X-Varnish: 1032893338 1032891351 | clean |
http://www.jta.org/s7.addthis.com/js/300/addthis_widget.js?ver=4.0/ | 404 Not Found Content-Length: 76075 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> |