Scanned pages/files
Request | Server response | Status |
http://drugslawsuit.com/ | 200 OK Content-Length: 32203 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: tovlietgar.co.il <div onmousemove="this.style.display='block'" id=faa style="DISPLAY: none" onmouseout="this.style.display='none'"><a href="http://openmarkets.com.au/wp-content/xml/">http://openmarkets.com.au/wp-content/xml/</a><br><a href="http://tovlietgar.co.il/wp-content/xml/">http://tovlietgar.co.il/wp-content/xml/</a><br><a href="http://waldenway.co.uk/wp-content/xml/">http://waldenway.co.uk/wp-content/xml/</a><br><a href="http://reefnews.info/wp-content/xml/">http://reefnews.info/wp-content/xml/</a><br><a href="http://myupdatenews.info/wp-content/xml/">http://myupdatenews.info/wp-content/xml/</a><br><a href="http://stay ...[4070 bytes skipped]... | ||
http://drugslawsuit.com/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 96402 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/ajax/static/ajax.js?ver=3.9.3 | 200 OK Content-Length: 33 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/lightbox/static/lightbox_context.js?ver=3.9.3 | 200 OK Content-Length: 890 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.plugins.min.js?ver=3.9.3 | 200 OK Content-Length: 16203 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.revolution.min.js?ver=3.9.3 | 200 OK Content-Length: 53302 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/themes/Archive/js/jquery.themepunch.plugins.min.js?ver=3.9.3 | 200 OK Content-Length: 14034 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/themes/Archive/js/jquery.themepunch.punchtip.js?ver=3.9.3 | 200 OK Content-Length: 2961 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/themes/Archive/js/jquery.themepunch.TwitterReader.js?ver=3.9.3 | 200 OK Content-Length: 3287 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function($){ $.fn.extend({ twitterReader: function(options) { var defaults = { user:'themepunch', count:4 } var options = $.extend(defaults, options); var o = options; var url = "https://api.twitter.com/1/statuses/user_timeline.json?screen_name="+o.user+"&count="+o.count+"&callback=?"; var holder=$(this); $.getJSON(ur if (diff < day * 365) { return Math.floor(diff / day) + " days ago"; } else { return "over a year ago"; } } function recallTillGotAll(count) { if (count>$('body').find('.twitter_reader_list li').length) { setTimeout(function() {recallTillGotAll(count)},1000); } else { } } })(jQuery); Antivirus reports:
| ||
http://drugslawsuit.com/wp-content/themes/Archive/js/jquery.themepunch.tpbackground.js?ver=3.9.3 | 200 OK Content-Length: 5824 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/themes/Archive/js/averis_forms.php?ver=3.9.3 | 200 OK Content-Length: 2290 Content-Type: text/javascript | clean |
http://drugslawsuit.com/wp-content/themes/Archive/js/colorpicker.js?ver=3.9.3 | 200 OK Content-Length: 16692 Content-Type: application/javascript | clean |
http://drugslawsuit.com/wp-content/themes/Archive/js/screen.php?dir=http%3A%2F%2Fdrugslawsuit.com%2Fwp-content%2Fthemes%2FArchive&ver=3.9.3 | 200 OK Content-Length: 24536 Content-Type: text/html | clean |
http://drugslawsuit.com/wp-content/themes/Archive/js/'+a.attr('href')+' | 200 OK Content-Length: 1211 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: drugslawsuit.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 08 Mar 2015 05:37:32 GMT
Server: nginx/1.6.2
Content-Type: text/html
GET / HTTP/1.1
Host: drugslawsuit.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 08 Mar 2015 05:37:32 GMT
Server: nginx/1.6.2
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: drugslawsuit.com
Referer: http://www.google.com/search?q=drugslawsuit.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: drugslawsuit.com
Referer: http://www.google.com/search?q=drugslawsuit.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=drugslawsuit.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://drugslawsuit.com/
Result: drugslawsuit.com is not infected or malware details are not published yet.
Result: drugslawsuit.com is not infected or malware details are not published yet.