Scanned pages/files
Request | Server response | Status |
http://dunnhogerty.unitedcp.com/ | HTTP/1.1 302 Found Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Date: Sat, 04 Oct 2014 05:05:28 GMT Location: http://ftcollins.unitedcp.com/ Server: Apache/2.2.25 (Amazon) Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 04 Oct 2014 05:05:28 GMT Set-Cookie: SESS832a2d7e1bdefd53fe857533dcf9ff95=fr0df68a619s8u79r0kpknu716; expires=Mon, 27-Oct-2014 08:38:48 GMT; path=/; domain=.unitedcp.com X-Powered-By: PHP/5.3.27 | clean |
http://ftcollins.unitedcp.com/ | 200 OK Content-Length: 17699 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/sites/default/files/js/js_641a0481f6ab043b94872b1493636177.js | 200 OK Content-Length: 300812 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){var l=this,g,y=l.jQuery,p=l.$,o=l.jQuery=l.$=function(E,F){return new o.fn.init(E,F)},D=/^[^<]*(<(.|\s)+>)[^>]*$|^#([\w-]+)$/,f=/^.[^:#\[\.,]*$/;o.fn=o.prototype={init:function(E,H){E=E||document;if(E.nodeType){this[0]=E;this.length=1;this.context=E;return this}if(typeof E==="string"){var G=D.exec(E);if(G&&(G[1]||!H)){if(G[1]){E=o.clean([G[1]],H)}else{var I=document.getElementById(G[3]);if(I&&I.id!=G[3]){return o().find(E)}var F=o(I||[]);F.context=document tl=term.length; if (match<0) { markup.push(escapeMarkup(text)); return; } markup.push(escapeMarkup(text.substring(0, match))); markup.push("<span class='select2-match'>"); markup.push(escapeMarkup(text.substring(match, match + tl))); markup.push("</span>"); markup.push(escapeMarkup(text.substring(match + tl, text.length))); } Antivirus reports:
| ||
http://dunnhogerty.unitedcp.com/news | HTTP/1.1 302 Found Cache-Control: store, no-cache, must-revalidate Cache-Control: post-check=0, pre-check=0 Connection: close Date: Sat, 04 Oct 2014 05:05:37 GMT Location: http://ftcollins.unitedcp.com/news Server: Apache/2.2.25 (Amazon) Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=utf-8 Expires: Sun, 19 Nov 1978 05:00:00 GMT Last-Modified: Sat, 04 Oct 2014 05:05:38 GMT Set-Cookie: SESS832a2d7e1bdefd53fe857533dcf9ff95=6qkdd24hqcn0aitqjr6svomjd7; expires=Mon, 27-Oct-2014 08:38:58 GMT; path=/; domain=.unitedcp.com X-Powered-By: PHP/5.3.27 | clean |
http://ftcollins.unitedcp.com/news | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://ftcollins.unitedcp.com/test404page.js | 404 Not Found Content-Length: 8731 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/contact | 200 OK Content-Length: 13857 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/honest-conversations | 403 Forbidden Content-Length: 9110 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/what-we-do | 200 OK Content-Length: 18427 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/sites/all/themes/ucp_rd/js/Flowchart_Banner_edgePreload.js | 200 OK Content-Length: 18466 Content-Type: text/javascript | clean |
http://ftcollins.unitedcp.com/about-us | 200 OK Content-Length: 12777 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/personnel | 200 OK Content-Length: 19967 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/signature-services | 200 OK Content-Length: 12243 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/disclosures | 200 OK Content-Length: 11793 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/thad.dunn@unitedcp.com | 404 Not Found Content-Length: 8737 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/quinn.mcelwee@unitedcp.com | 404 Not Found Content-Length: 8741 Content-Type: text/html | clean |
http://ftcollins.unitedcp.com/kristin.howe@unitedcp.com | 404 Not Found Content-Length: 8740 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: dunnhogerty.unitedcp.com
Result:
HTTP/1.1 302 Found
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 05:05:28 GMT
Location: http://ftcollins.unitedcp.com/
Server: Apache/2.2.25 (Amazon)
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Content-Type: text/html; charset=utf-8
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Sat, 04 Oct 2014 05:05:28 GMT
Set-Cookie: SESS832a2d7e1bdefd53fe857533dcf9ff95=fr0df68a619s8u79r0kpknu716; expires=Mon, 27-Oct-2014 08:38:48 GMT; path=/; domain=.unitedcp.com
X-Powered-By: PHP/5.3.27
...0 bytes of data.
GET / HTTP/1.1
Host: dunnhogerty.unitedcp.com
Result:
HTTP/1.1 302 Found
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Sat, 04 Oct 2014 05:05:28 GMT
Location: http://ftcollins.unitedcp.com/
Server: Apache/2.2.25 (Amazon)
Vary: Accept-Encoding,User-Agent
Content-Length: 0
Content-Type: text/html; charset=utf-8
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Sat, 04 Oct 2014 05:05:28 GMT
Set-Cookie: SESS832a2d7e1bdefd53fe857533dcf9ff95=fr0df68a619s8u79r0kpknu716; expires=Mon, 27-Oct-2014 08:38:48 GMT; path=/; domain=.unitedcp.com
X-Powered-By: PHP/5.3.27
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: dunnhogerty.unitedcp.com
Referer: http://www.google.com/search?q=dunnhogerty.unitedcp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: dunnhogerty.unitedcp.com
Referer: http://www.google.com/search?q=dunnhogerty.unitedcp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=dunnhogerty.unitedcp.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://dunnhogerty.unitedcp.com/
Result: dunnhogerty.unitedcp.com is not infected or malware details are not published yet.
Result: dunnhogerty.unitedcp.com is not infected or malware details are not published yet.