Scanned pages/files
Request | Server response | Status |
http://www.freightnet.com.co/ | 200 OK Content-Length: 39498 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if (1 == 2) { if (!/android|iphone|ipod|series60|symbian|windows ce|blackberry/i.test(navigator.userAgent)) { jQuery(function($) { $("a[rel^='lightbox']").slimbox({ loop: true, overlayOpacity: 0.8, overlayFadeDuration: 400, resizeDuration: 400, resizeEasing: "jswing", initialWidth: 250, initialHeight: 250, imageFadeDuration: 400, captionAnimationDuration: 400, counter speedIn: null, speedOut: null, next: '#slideshowboxnext', prev: '#slideshowboxprev', pager: '#slideshowboxnav', pagerEvent: 'click', before: null, after: null, shuffle: null, random: 0, fit: 0, containerResize: 1, pause: 1, pauseOnPagerHover: 0, autostop: 0, delay: 0, nowrap: 0, randomizeEffects: 1, rev: 0 }); }; }); Antivirus reports:
| ||
http://www.freightnet.com.co/media/system/js/caption.js | 200 OK Content-Length: 1776 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/modules/mod_jt_slideshow/scripts/jquery.js | 200 OK Content-Length: 77746 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/modules/mod_jt_slideshow/scripts/jquery.cycle.all.min.js | 200 OK Content-Length: 32046 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/modules/mod_jt_slideshow/scripts/jquery.easing.1.3.js | 200 OK Content-Length: 8097 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/modules/mod_jt_slideshow/scripts/jquery.easing.compatibility.js | 200 OK Content-Length: 1726 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/templates/navesoft/js/AC_RunActiveContent.js | 200 OK Content-Length: 8321 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/includes/js/functions.js | 200 OK Content-Length: 2227 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/includes/js/overlib_mini.js | 200 OK Content-Length: 36831 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/includes/js/overlib_hideform_mini.js | 200 OK Content-Length: 3328 Content-Type: application/x-javascript | clean |
http://www.freightnet.com.co/index.php | 200 OK Content-Length: 39519 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if (1 == 2) { if (!/android|iphone|ipod|series60|symbian|windows ce|blackberry/i.test(navigator.userAgent)) { jQuery(function($) { $("a[rel^='lightbox']").slimbox({ loop: true, overlayOpacity: 0.8, overlayFadeDuration: 400, resizeDuration: 400, resizeEasing: "jswing", initialWidth: 250, initialHeight: 250, imageFadeDuration: 400, captionAnimationDuration: 400, counter speedIn: null, speedOut: null, next: '#slideshowboxnext', prev: '#slideshowboxprev', pager: '#slideshowboxnav', pagerEvent: 'click', before: null, after: null, shuffle: null, random: 0, fit: 0, containerResize: 1, pause: 1, pauseOnPagerHover: 0, autostop: 0, delay: 0, nowrap: 0, randomizeEffects: 1, rev: 0 }); }; }); Antivirus reports:
| ||
http://www.freightnet.com.co/../../transpacific_en/ | 400 Bad Request Content-Length: 404 Content-Type: text/html | clean |
http://www.freightnet.com.co/test404page.js | 404 Not Found Content-Length: 334 Content-Type: text/html | clean |
http://www.freightnet.com.co/index.php/online-services/tasa-cambio | 200 OK Content-Length: 37589 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if (1 == 2) { if (!/android|iphone|ipod|series60|symbian|windows ce|blackberry/i.test(navigator.userAgent)) { jQuery(function($) { $("a[rel^='lightbox']").slimbox({ loop: true, overlayOpacity: 0.8, overlayFadeDuration: 400, resizeDuration: 400, resizeEasing: "jswing", initialWidth: 250, initialHeight: 250, imageFadeDuration: 400, captionAnimationDuration: 400, counter speedIn: null, speedOut: null, next: '#slideshowboxnext', prev: '#slideshowboxprev', pager: '#slideshowboxnav', pagerEvent: 'click', before: null, after: null, shuffle: null, random: 0, fit: 0, containerResize: 1, pause: 1, pauseOnPagerHover: 0, autostop: 0, delay: 0, nowrap: 0, randomizeEffects: 1, rev: 0 }); }; }); Antivirus reports:
| ||
http://www.freightnet.com.co/index.php/online-services/tracking | 200 OK Content-Length: 37606 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if (1 == 2) { if (!/android|iphone|ipod|series60|symbian|windows ce|blackberry/i.test(navigator.userAgent)) { jQuery(function($) { $("a[rel^='lightbox']").slimbox({ loop: true, overlayOpacity: 0.8, overlayFadeDuration: 400, resizeDuration: 400, resizeEasing: "jswing", initialWidth: 250, initialHeight: 250, imageFadeDuration: 400, captionAnimationDuration: 400, counter speedIn: null, speedOut: null, next: '#slideshowboxnext', prev: '#slideshowboxprev', pager: '#slideshowboxnav', pagerEvent: 'click', before: null, after: null, shuffle: null, random: 0, fit: 0, containerResize: 1, pause: 1, pauseOnPagerHover: 0, autostop: 0, delay: 0, nowrap: 0, randomizeEffects: 1, rev: 0 }); }; }); Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: freightnet.com.co
Result:
GET / HTTP/1.1
Host: freightnet.com.co
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: freightnet.com.co
Referer: http://www.google.com/search?q=freightnet.com.co
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: freightnet.com.co
Referer: http://www.google.com/search?q=freightnet.com.co
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=freightnet.com.co
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://freightnet.com.co/
Result: freightnet.com.co is not infected or malware details are not published yet.
Result: freightnet.com.co is not infected or malware details are not published yet.