Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=clp.ie
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://clp.ie/ | 200 OK Content-Length: 9369 Content-Type: text/html | clean |
http://clp.ie/scripts/jquery-1.4.1.min.js | 200 OK Content-Length: 70842 Content-Type: application/javascript | clean |
http://clp.ie/scripts/jquery.jcarousel.pack.js | 200 OK Content-Length: 8891 Content-Type: application/javascript | clean |
http://clp.ie/scripts/jquery.jcarousel.setup.js | 200 OK Content-Length: 1205 Content-Type: application/javascript | clean |
http://widgetlocker.info/exitpopup.php?pub=277107&gateid=NjY4NDc1 | 200 OK Content-Length: 2613 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var PreventExitSplash = false; function addLoadEvent(func){ var oldonload = window.onload; if (typeof window.onload != 'function') { window.onload = func; } else { window.onload = function(){ if (oldonload) { oldonload(); } func(); } } } function addClickEvent(a, i, func){ if (typeof a[i].onclick != 'function') { a[i].oncl body_tag.bottomMargin = "0px"; body_tag.leftMargin = "0px"; body_tag.style.overflow = "hidden"; body_tag.appendChild(new_div); return exitsplashmessage; } } function wait_for_body_tag() { body_tag = document.getElementsByTagName("body").item(0); if (body_tag == null) { setTimeout("wait_for_body_tag();", 200); } else { window.onbeforeunload = DisplayExitSplash; } } wait_for_body_tag(); addLoadEvent(load_ett); Antivirus reports:
| ||
http://clp.ie/index.html | 200 OK Content-Length: 9369 Content-Type: text/html | clean |
http://clp.ie/products.html | 200 OK Content-Length: 7159 Content-Type: text/html | clean |
http://clp.ie/brands.html | 200 OK Content-Length: 16189 Content-Type: text/html | clean |
http://clp.ie/dundalk-location.html | 200 OK Content-Length: 7357 Content-Type: text/html | clean |
http://clp.ie/monaghan-location.html | 200 OK Content-Length: 7308 Content-Type: text/html | clean |
http://clp.ie/contact.html | 200 OK Content-Length: 7147 Content-Type: text/html | clean |
http://clp.ie/test404page.js | 404 Not Found Content-Length: 3612 Content-Type: text/html | clean |
http://clp.ie/products/spark_plugs/index.asp?mode=nml | 404 Not Found Content-Length: 3612 Content-Type: text/html | clean |
http://clp.ie/batt.html | 200 OK Content-Length: 7687 Content-Type: text/html | clean |
http://clp.ie/elect.html | 200 OK Content-Length: 7472 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: clp.ie
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 Jan 2015 01:18:26 GMT
Accept-Ranges: bytes
ETag: "3ecab1-2499-4f8fb4242dac0"
Server: Apache
Vary: Accept-Encoding
Content-Length: 9369
Content-Type: text/html
Last-Modified: Fri, 09 May 2014 17:52:19 GMT
...9369 bytes of data.
GET / HTTP/1.1
Host: clp.ie
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 Jan 2015 01:18:26 GMT
Accept-Ranges: bytes
ETag: "3ecab1-2499-4f8fb4242dac0"
Server: Apache
Vary: Accept-Encoding
Content-Length: 9369
Content-Type: text/html
Last-Modified: Fri, 09 May 2014 17:52:19 GMT
...9369 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: clp.ie
Referer: http://www.google.com/search?q=clp.ie
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: clp.ie
Referer: http://www.google.com/search?q=clp.ie
Result:
The result is similar to the first query. There are no suspicious redirects found.