Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=fadaf.611-construct.de
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://fadaf.611-construct.de/ | 200 OK Content-Length: 21816 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: edtabpharmacy.com <div onclick="(a.style.display=='none')?a.style.display='block':a.style.display='none';"></div>
<div class="a" id="a" style="display:none;"> <a href="http://www.nobisjacket.ca/">Nobis</a> <a href="http://www.windows8keys.co.uk/">windows8keys</a> <a href="http://www.goosedoudounesoldes.fr/">Doudoune Canada Goose</a>Ã <a href="http://www.parajumperspjsno.com">Parajumpe ...[4103 bytes skipped]... | ||
http://fadaf.611-construct.de/media/system/js/mootools-core.js | 200 OK Content-Length: 95132 Content-Type: text/javascript | clean |
http://fadaf.611-construct.de/media/system/js/core.js | 200 OK Content-Length: 4775 Content-Type: text/javascript | clean |
http://fadaf.611-construct.de/media/system/js/caption.js | 200 OK Content-Length: 729 Content-Type: text/javascript | clean |
http://fadaf.611-construct.de/media/system/js/mootools-more.js | 200 OK Content-Length: 238331 Content-Type: text/javascript | clean |
http://fadaf.611-construct.de/templates/beez_20/javascript/hide.js | 200 OK Content-Length: 7735 Content-Type: text/javascript | clean |
http://imobilara.ru/redirect.php?r=http%3A//imobilara.ru/l.php%3Fl%3Dandryskor%26r%3D12010%26a%3D29 | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://imobilara.ru/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://imobilara.ru/redirect.php?r=http%3A//imobilara.ru/l.php%3Fl%3Dantivirus2%26r%3D12091%26a%3D29 | 200 OK Content-Length: 0 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: fadaf.611-construct.de
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Tue, 12 Aug 2014 07:05:16 GMT
Pragma: no-cache
Server: Apache
Content-Language: de
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: e0d376b39c8b5c22ebb209cb392b0da4=h47osq1863t5gaaqi3bd9egn74; path=/
X-Powered-By: PleskLin
GET / HTTP/1.1
Host: fadaf.611-construct.de
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Tue, 12 Aug 2014 07:05:16 GMT
Pragma: no-cache
Server: Apache
Content-Language: de
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: e0d376b39c8b5c22ebb209cb392b0da4=h47osq1863t5gaaqi3bd9egn74; path=/
X-Powered-By: PleskLin
Second query (visit from search engine):
GET / HTTP/1.1
Host: fadaf.611-construct.de
Referer: http://www.google.com/search?q=fadaf.611-construct.de
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: fadaf.611-construct.de
Referer: http://www.google.com/search?q=fadaf.611-construct.de
Result:
The result is similar to the first query. There are no suspicious redirects found.