Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=fairlifeshop.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://fairlifeshop.com/ | 200 OK Content-Length: 4105 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://prohostinc.com/suspended.page/c2xpw6yw.php?id=46630675"></script> | ||
http://fairlifeshop.com/_module/js/script.js?l=0,t=default08,f=g,fs=m,c=034a | 200 OK Content-Length: 15030 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var fsURL = 'http://module.bindsite.jp/'; var fsModule = '_module110809-0500'; var bindobj = new Object(); bindobj.ua = navigator.userAgent.toLowerCase(); bindobj.win = bindobj.ua.indexOf('windows')>-1 || bindobj.ua.indexOf('win32')>-1 ? true : false; bindobj.win7 = bindobj.win && bindobj.ua.indexOf('nt 6.1')>-1 ? true : false; bindobj.vista = bindobj.win && bindobj.ua.indexOf('nt 6.0')>-1 ? true : false; bindobj.xp = bindobj.win && 39810*/9810*/ Antivirus reports:
| ||
http://fairlifeshop.com/pg203.html | 200 OK Content-Length: 52744 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://prohostinc.com/suspended.page/c2xpw6yw.php?id=46630677"></script> | ||
http://fairlifeshop.com/index.html | 200 OK Content-Length: 4105 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://prohostinc.com/suspended.page/c2xpw6yw.php?id=46630675"></script> | ||
http://fairlifeshop.com/pg221.html | 200 OK Content-Length: 45314 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://prohostinc.com/suspended.page/c2xpw6yw.php?id=46630678"></script> | ||
http://fairlifeshop.com/pg202.html | 200 OK Content-Length: 44246 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://prohostinc.com/suspended.page/c2xpw6yw.php?id=46630676"></script> | ||
http://fairlifeshop.com/pg222.html | 200 OK Content-Length: 4132 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://prohostinc.com/suspended.page/c2xpw6yw.php?id=46630679"></script> | ||
http://fairlifeshop.com/pg242.html | 200 OK Content-Length: 16488 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://prohostinc.com/suspended.page/c2xpw6yw.php?id=46630680"></script> | ||
http://fairlifeshop.com/pg262.html | 404 Not Found Content-Length: 2275 Content-Type: text/html | clean |
http://fairlifeshop.com/test404page.js | 404 Not Found Content-Length: 2275 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: fairlifeshop.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 15 Jul 2014 05:32:11 GMT
Accept-Ranges: bytes
ETag: "63813e4-1009-4f836ba474d00"
Server: Apache
Content-Length: 4105
Content-Type: text/html
Last-Modified: Tue, 29 Apr 2014 23:24:04 GMT
...4105 bytes of data.
GET / HTTP/1.1
Host: fairlifeshop.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 15 Jul 2014 05:32:11 GMT
Accept-Ranges: bytes
ETag: "63813e4-1009-4f836ba474d00"
Server: Apache
Content-Length: 4105
Content-Type: text/html
Last-Modified: Tue, 29 Apr 2014 23:24:04 GMT
...4105 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: fairlifeshop.com
Referer: http://www.google.com/search?q=fairlifeshop.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: fairlifeshop.com
Referer: http://www.google.com/search?q=fairlifeshop.com
Result:
The result is similar to the first query. There are no suspicious redirects found.