Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=doctor-ivy.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://doctor-ivy.com/ | 200 OK Content-Length: 9358 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!-- function Etc_Popup(myurl,name,width,height,top,left) { window.open (myurl,name, "width="+ width +", height="+ height +", scrollbars=no, resizable=no") } function getCookie( name ){ var nameOfCookie = name + "="; var x = 0; while ( x <= document.cookie.length ) { var y = (x+nameOfCookie.length); if ( document.cookie.substring( x, y ) == nameOfCookie ) { } x = document.cookie.indexOf( " ", x ) + 1; if ( x == 0 ) break; } return ""; } if ( getCookie( "Notice" ) != "done" ) { noticeWindow = window.open('/popup/20080624.htm','notice','left=0, top=0, width=500,height=665'); noticeWindow.opener = self; } Antivirus reports:
| ||
http://www.opencom.com/js/mobileLocation.js | 200 OK Content-Length: 428 Content-Type: application/javascript | clean |
http://doctor-ivy.com/js/flush.js | 200 OK Content-Length: 3824 Content-Type: application/javascript | clean |
http://doctor-ivy.com/board/board.html?bn=notice | 200 OK Content-Length: 20949 Content-Type: text/html | clean |
http://doctor-ivy.com/__JS/global.js | 200 OK Content-Length: 3362 Content-Type: application/javascript | clean |
http://doctor-ivy.com/__JS/board.js | 200 OK Content-Length: 1659 Content-Type: application/javascript | clean |
http://doctor-ivy.com/board/../../html/intro/intro.php | 400 Bad Request Content-Length: 174 Content-Type: text/html | clean |
http://doctor-ivy.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Mon, 22 Dec 2014 05:15:56 GMT Location: http://html.innopl.net/404.html Server: Apache Content-Type: text/html; charset=iso-8859-1 | clean |
http://html.innopl.net/404.html | 200 OK Content-Length: 2958 Content-Type: text/html | clean |
http://html.innopl.net/test404page.js | HTTP/1.1 302 Found Connection: close Date: Mon, 22 Dec 2014 05:15:57 GMT Location: http://html.gethompy.com/error/error_request.php Server: nginx/1.4.3p1 Content-Length: 297 Content-Type: text/html; charset=iso-8859-1 | clean |
http://html.gethompy.com/error/error_request.php | 200 OK Content-Length: 211 Content-Type: text/html | clean |
http://html.gethompy.com/test404page.js | HTTP/1.1 302 Found Connection: close Date: Mon, 22 Dec 2014 05:15:59 GMT Location: http://html.gethompy.com/error/error_request.php Server: nginx/1.4.3p1 Content-Length: 299 Content-Type: text/html; charset=iso-8859-1 | clean |
http://doctor-ivy.com/board/../../html/intro/intro2.php | 400 Bad Request Content-Length: 174 Content-Type: text/html | clean |
http://doctor-ivy.com/board/board.html?bn=movie | 200 OK Content-Length: 18049 Content-Type: text/html | clean |
http://doctor-ivy.com/board/../../html/intro/intro3.php | 400 Bad Request Content-Length: 174 Content-Type: text/html | clean |
http://doctor-ivy.com/board/board.html?bn=movie&keyfield=&key=&page=&p=v&p2=v&number=53 | 200 OK Content-Length: 18199 Content-Type: text/html | clean |
http://doctor-ivy.com/board/board.html?bn=movie&keyfield=&key=&page=&p=v&number=52 | 200 OK Content-Length: 14988 Content-Type: text/html | clean |
http://doctor-ivy.com/board/board.html?bn=movie&keyfield=&key=&page=&p=v&number=32 | 200 OK Content-Length: 13027 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: doctor-ivy.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 22 Dec 2014 05:15:49 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
X-Powered-By: PHP/4.4.7p2
GET / HTTP/1.1
Host: doctor-ivy.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 22 Dec 2014 05:15:49 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html
X-Powered-By: PHP/4.4.7p2
Second query (visit from search engine):
GET / HTTP/1.1
Host: doctor-ivy.com
Referer: http://www.google.com/search?q=doctor-ivy.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: doctor-ivy.com
Referer: http://www.google.com/search?q=doctor-ivy.com
Result:
The result is similar to the first query. There are no suspicious redirects found.