Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=elections.jta.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://elections.jta.org/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: subscribepaullina.paullinatimes.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 31 Dec 2013 04:18:19 GMT
Server: Apache
Vary: *
Content-Type: text/html
GET / HTTP/1.1
Host: subscribepaullina.paullinatimes.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 31 Dec 2013 04:18:19 GMT
Server: Apache
Vary: *
Content-Type: text/html
Second query (visit from search engine):
GET / HTTP/1.1
Host: subscribepaullina.paullinatimes.com
Referer: http://www.google.com/search?q=subscribepaullina.paullinatimes.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: subscribepaullina.paullinatimes.com
Referer: http://www.google.com/search?q=subscribepaullina.paullinatimes.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://elections.jta.org/ | HTTP/1.1 302 Found Connection: close Date: Fri, 26 Sep 2014 14:01:38 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://www.jta.org/ Server: Varnish X-Cache: dynamic X-Varnish: 1032913643 | malicious |
http://www.jta.org/ | 200 OK Content-Length: 116401 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> | ||
http://www.jta.org/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/plugins/mailchimp/js/scrollTo.js?ver=1.4.1 | 200 OK Content-Length: 2262 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/jquery/jquery.form.min.js?ver=3.37.0 | 200 OK Content-Length: 14720 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/plugins/mailchimp/js/mailchimp.js?ver=1.4.1 | 200 OK Content-Length: 1054 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/jquery/ui/jquery.ui.core.min.js?ver=1.10.4 | 200 OK Content-Length: 4289 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/plugins/mailchimp//js/datepicker.js?ver=4.0 | 200 OK Content-Length: 75876 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-includes/js/tinymce/tinymce.min.js?ver=4.0 | 200 OK Content-Length: 301201 Content-Type: application/x-javascript | clean |
http://elections.jta.org//code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ | HTTP/1.1 302 Found Connection: close Date: Fri, 26 Sep 2014 14:01:44 GMT Via: 1.1 varnish Accept-Ranges: bytes Age: 0 Location: http://www.jta.org/ Server: Varnish X-Cache: dynamic X-Varnish: 1032913680 | malicious |
http://www.jta.org/test404page.js | 404 Not Found Content-Length: 76042 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> | ||
http://www.jta.org//code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 26 Sep 2014 14:01:45 GMT Pragma: no-cache Via: 1.1 varnish Age: 1742 Location: http://www.jta.org/code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ Server: nginx/1.1.19 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Cache: HIT X-Pingback: http://www.jta.org/xmlrpc.php X-Powered-By: PHP/5.3.10-1ubuntu3.6 X-Varnish: 1032913684 1032891322 | clean |
http://www.jta.org/code.jquery.com/jquery-migrate-1.2.1.js?ver=4.0/ | 404 Not Found Content-Length: 76075 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> | ||
http://www.jta.org/wp-content/themes/jta/static/js/picturefill.js?ver=4.0 | 200 OK Content-Length: 1771 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/themes/jta/static/js/jquery.easing.1.3.js?ver=4.0 | 200 OK Content-Length: 8097 Content-Type: application/x-javascript | clean |
http://www.jta.org/wp-content/themes/jta/static/js/slides.min.jquery.js?ver=4.0 | 200 OK Content-Length: 6739 Content-Type: application/x-javascript | clean |
http://www.jta.org//s7.addthis.com/js/300/addthis_widget.js?ver=4.0/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 26 Sep 2014 14:01:47 GMT Pragma: no-cache Via: 1.1 varnish Age: 1740 Location: http://www.jta.org/s7.addthis.com/js/300/addthis_widget.js?ver=4.0/ Server: nginx/1.1.19 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Cache: HIT X-Pingback: http://www.jta.org/xmlrpc.php X-Powered-By: PHP/5.3.10-1ubuntu3.6 X-Varnish: 1032913702 1032891351 | clean |
http://www.jta.org/s7.addthis.com/js/300/addthis_widget.js?ver=4.0/ | 404 Not Found Content-Length: 76075 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord= <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1? <iframe src="http://4351288.fls.doubleclick.net/activityi;src=4351288;type=invmedia;cat=bj9aw2ri;ord=1?" width="1" height="1" frameborder="0" style="display:none"> |