Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=devolutionclub.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.devolutionclub.com/ | 200 OK Content-Length: 44187 Content-Type: text/html | clean |
http://www.devolutionclub.it/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7199 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/admin/jquery.cookie.js?ver=1.0 | 200 OK Content-Length: 3655 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/jquery.floating_popup.1.3.min.js?ver=1.0 | 200 OK Content-Length: 5020 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/orange-themes-responsive.js?ver=1.4 | 200 OK Content-Length: 1220 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/jquery.isotope.min.js?ver=1.5.19 | 200 OK Content-Length: 15876 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/lightbox.js?ver=1.0 | 200 OK Content-Length: 4585 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/jquery.sexyslider.min.js?ver=1.0 | 200 OK Content-Length: 6720 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/jquery.infinitescroll.min.js?ver=3.6.1 | 200 OK Content-Length: 20962 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-includes/js/comment-reply.min.js?ver=3.6.1 | 200 OK Content-Length: 786 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/ot_gallery.js?ver=1.0 | 200 OK Content-Length: 14038 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/scripts.php?ver=1.0 | 200 OK Content-Length: 1749 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function validateName(fld) { var error = ""; if (fld.value === '' || fld.value === 'Nickname' || fld.value === 'Enter Your Name..' || fld.value === 'Your Name..') { error = "You didn't enter Your First Name.\n"; } else if ((fld.value.length < 2) || (fld.value.length > 50)) { error = "First Name is the wrong length.\n"; } return error; } function validateEmail(fld) { var error=""; var illegalChars = / jQuery("#sidebar-panel-comments").hide(); jQuery("#sidebar-panel-popular").fadeIn('fast'); }else if(parseid == "sidebar-icon-comments"){ jQuery(this).parent().parent().parent().children().eq(0).html("Recent Comments"); jQuery(this).addClass("active"); jQuery("#sidebar-icon-popular").removeClass("active"); jQuery("#sidebar-panel-popular").hide(); jQuery("#sidebar-panel-comments").fadeIn('fast'); } }); }); Antivirus reports:
| ||
http://www.devolutionclub.it/wp-content/plugins/itro-popup/scripts/itro-scripts.js?ver=3.6.1 | 200 OK Content-Length: 2492 Content-Type: application/javascript | clean |
http://www.devolutionclub.it/wp-content/themes/bulteno-theme/js/scripts.js?ver=1.0 | 200 OK Content-Length: 21467 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: devolutionclub.com
Result:
GET / HTTP/1.1
Host: devolutionclub.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: devolutionclub.com
Referer: http://www.google.com/search?q=devolutionclub.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: devolutionclub.com
Referer: http://www.google.com/search?q=devolutionclub.com
Result:
The result is similar to the first query. There are no suspicious redirects found.