Scanned pages/files
Request | Server response | Status |
https://www.getbankingdone.com/ | 200 OK Content-Length: 75079 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="https://2549153.fls.doubleclick.net/activityi;src=2549153;type=entga0;cat=ent_a0;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
| ||
https://www.getbankingdone.com/js/vendor/libraries.min.js | 200 OK Content-Length: 301901 Content-Type: application/x-javascript | clean |
https://www.getbankingdone.com/js/vendor/foundation.min.js | 200 OK Content-Length: 20511 Content-Type: application/x-javascript | clean |
https://www.getbankingdone.com/js/app.min.js | 200 OK Content-Length: 32798 Content-Type: application/x-javascript | clean |
https://www.getbankingdone.com/tel://1-800-956-4442 | 404 Not Found Content-Length: 294 Content-Type: text/html | clean |
http://www.getbankingdone.com/test404page.js | 404 Not Found Content-Length: 288 Content-Type: text/html | clean |
https://www.getbankingdone.com/tel://1-800-869-3557 | 404 Not Found Content-Length: 294 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: getbankingdone.com:443
Result:
GET / HTTP/1.1
Host: getbankingdone.com:443
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: getbankingdone.com:443
Referer: http://www.google.com/search?q=getbankingdone.com:443
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: getbankingdone.com:443
Referer: http://www.google.com/search?q=getbankingdone.com:443
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=getbankingdone.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://getbankingdone.com/
Result: getbankingdone.com:443 is not infected or malware details are not published yet.
Result: getbankingdone.com:443 is not infected or malware details are not published yet.