Scanned pages/files
Request | Server response | Status |
http://columbiasportswear.com.tw/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache,no-store,must-revalidate Connection: close Date: Tue, 17 Jun 2014 05:25:08 GMT Pragma: no-cache Accept-Ranges: bytes Location: http://www.columbia.com Server: Demandware eCommerce Server Vary: Accept-Encoding Content-Length: 1 Content-Type: text/html;charset=UTF-8 Expires: Thu, 01 Dec 1994 16:00:00 GMT Set-Cookie: dwac_bcTzIiaagStlAaaacFPtt5neAG=VgNiZpeFcOdVFUPo78euValRlfMp6fGIrOc%3D|demandaacwcolumbiaus|||USD|false|US%2FPacific|true; Path=/ Set-Cookie: sid=VgNiZpeFcOdVFUPo78euValRlfMp6fGIrOc; Path=/ Set-Cookie: dwpersonalization_6148ff3835e27262c32d6dc123dc430d=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: dwanonymous_6148ff3835e27262c32d6dc123dc430d=bdeOEDAXNiCYLyaWIAtwwW7bZW; Expires=Sun, 14-Dec-2014 05:25:08 GMT; Path=/ Set-Cookie: dwsid=79iBj349qP7JyxmAslMH5xCKdhrAUSmRMDlbqMaCo7Wr2H7LbIVeX_U1wOmNQYm6SwrsW5YpwjGbZS5TQxWnLg==; path=/; HttpOnly | clean |
http://www.columbia.com/ | HTTP/1.1 302 Found Cache-Control: no-cache,no-store,must-revalidate Connection: close Date: Tue, 17 Jun 2014 05:25:09 GMT Pragma: no-cache Accept-Ranges: bytes Location: http://www.columbia.com/on/demandware.store/Sites-Columbia_US-Site/default/Home-SelectCountry Server: Demandware eCommerce Server Vary: Accept-Encoding Content-Length: 178832 Content-Type: text/html;charset=UTF-8 Expires: Thu, 01 Dec 1994 16:00:00 GMT Set-Cookie: dwac_bcTzIiaagStlAaaacFPtt5neAG=YqguLFFJRr5VqE6UDik52BZ6YfwE8cvEx8U%3D|demandaacwcolumbiaus|||USD|false|US%2FPacific|true; Path=/ Set-Cookie: sid=YqguLFFJRr5VqE6UDik52BZ6YfwE8cvEx8U; Path=/ Set-Cookie: dwpersonalization_6148ff3835e27262c32d6dc123dc430d=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: dwanonymous_6148ff3835e27262c32d6dc123dc430d=aecjaniY8bRBzLd58PQ0I2H2MD; Expires=Sun, 14-Dec-2014 05:25:09 GMT; Path=/ Set-Cookie: dwsid=8-IJQmJpvZiazXJn2jkMdIcwRpI30TDiCKCHtTQD-2GV3RRqAU32NEL1IUEmSgmfHVzGDDTwJElVETg71K-Xpw==; path=/; HttpOnly | clean |
http://www.columbia.com/on/demandware.store/sites-columbia_us-site/default/home-selectcountry | 404 Not Found Content-Length: 400 Content-Type: text/html | clean |
http://www.columbia.com/test404page.js | 410 Gone Content-Length: 128775 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://fls.doubleclick.net/activityi;src=3831845;type=remar803;cat=c olum353;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
| ||
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery-1.3.1.min.js | 200 OK Content-Length: 55272 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/date.js | 200 OK Content-Length: 12057 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery.datePicker.min-2.1.2.js | 200 OK Content-Length: 13254 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery.autocomplete.js | 200 OK Content-Length: 14176 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery.mousewheel.js | 200 OK Content-Length: 2496 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery.em.js | 200 OK Content-Length: 5515 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery.jscrollpane.js | 200 OK Content-Length: 17399 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery.bgiframe.js | 200 OK Content-Length: 4881 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/jquery.ui.personalized.1.6rc5.min.js | 200 OK Content-Length: 165027 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/lib/swfobject.js | 200 OK Content-Length: 9821 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/lib/js/swfobject_source.js | 200 OK Content-Length: 9321 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/lib/js/jquery.validate.js | 200 OK Content-Length: 35434 Content-Type: text/javascript | clean |
http://demandware.edgesuite.net/aacw_prd/on/demandware.static/Sites-Columbia_US-Site/-/default/v1402959541765/js/rf.js | 200 OK Content-Length: 80701 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: columbiasportswear.com.tw
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache,no-store,must-revalidate
Connection: close
Date: Tue, 17 Jun 2014 05:25:08 GMT
Pragma: no-cache
Accept-Ranges: bytes
Location: http://www.columbia.com
Server: Demandware eCommerce Server
Vary: Accept-Encoding
Content-Length: 1
Content-Type: text/html;charset=UTF-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: dwac_bcTzIiaagStlAaaacFPtt5neAG=VgNiZpeFcOdVFUPo78euValRlfMp6fGIrOc%3D|demandaacwcolumbiaus|||USD|false|US%2FPacific|true; Path=/
Set-Cookie: sid=VgNiZpeFcOdVFUPo78euValRlfMp6fGIrOc; Path=/
Set-Cookie: dwpersonalization_6148ff3835e27262c32d6dc123dc430d=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: dwanonymous_6148ff3835e27262c32d6dc123dc430d=bdeOEDAXNiCYLyaWIAtwwW7bZW; Expires=Sun, 14-Dec-2014 05:25:08 GMT; Path=/
Set-Cookie: dwsid=79iBj349qP7JyxmAslMH5xCKdhrAUSmRMDlbqMaCo7Wr2H7LbIVeX_U1wOmNQYm6SwrsW5YpwjGbZS5TQxWnLg==; path=/; HttpOnly
...1 bytes of data.
GET / HTTP/1.1
Host: columbiasportswear.com.tw
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache,no-store,must-revalidate
Connection: close
Date: Tue, 17 Jun 2014 05:25:08 GMT
Pragma: no-cache
Accept-Ranges: bytes
Location: http://www.columbia.com
Server: Demandware eCommerce Server
Vary: Accept-Encoding
Content-Length: 1
Content-Type: text/html;charset=UTF-8
Expires: Thu, 01 Dec 1994 16:00:00 GMT
Set-Cookie: dwac_bcTzIiaagStlAaaacFPtt5neAG=VgNiZpeFcOdVFUPo78euValRlfMp6fGIrOc%3D|demandaacwcolumbiaus|||USD|false|US%2FPacific|true; Path=/
Set-Cookie: sid=VgNiZpeFcOdVFUPo78euValRlfMp6fGIrOc; Path=/
Set-Cookie: dwpersonalization_6148ff3835e27262c32d6dc123dc430d=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/
Set-Cookie: dwanonymous_6148ff3835e27262c32d6dc123dc430d=bdeOEDAXNiCYLyaWIAtwwW7bZW; Expires=Sun, 14-Dec-2014 05:25:08 GMT; Path=/
Set-Cookie: dwsid=79iBj349qP7JyxmAslMH5xCKdhrAUSmRMDlbqMaCo7Wr2H7LbIVeX_U1wOmNQYm6SwrsW5YpwjGbZS5TQxWnLg==; path=/; HttpOnly
...1 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: columbiasportswear.com.tw
Referer: http://www.google.com/search?q=columbiasportswear.com.tw
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: columbiasportswear.com.tw
Referer: http://www.google.com/search?q=columbiasportswear.com.tw
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=columbiasportswear.com.tw
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://columbiasportswear.com.tw/
Result: columbiasportswear.com.tw is not infected or malware details are not published yet.
Result: columbiasportswear.com.tw is not infected or malware details are not published yet.