Scanned pages/files
Request | Server response | Status |
http://goindependentwithrj.com/ | HTTP/1.1 302 Object moved Cache-Control: private Connection: close Date: Mon, 31 Mar 2014 10:51:10 GMT Location: http://www.raymondjames.com/advisorchoice/independent_contractor/?utm_source=Advisor1_Indy_Rectangle&utm_medium=web_ad&utm_content=gone_far&utm_campaign=Indy2012 Server: Microsoft-IIS/6.0 Content-Length: 282 Content-Type: text/html X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET X-Server: sjl03 | clean |
http://www.raymondjames.com/advisorchoice/independent_contractor/?utm_source=advisor1_indy_rectangle&utm_medium=web_ad&utm_content=gone_far&utm_campaign=indy2012 | 200 OK Content-Length: 6093 Content-Type: text/html | clean |
http://www.raymondjames.com/advisorchoice/independent_contractor/top.js | 200 OK Content-Length: 4022 Content-Type: application/x-javascript | clean |
http://goindependentwithrj.com/bottom.js | HTTP/1.1 302 Object moved Cache-Control: private Connection: close Date: Mon, 31 Mar 2014 10:51:12 GMT Location: http://www.raymondjames.com/advisorchoice/independent_contractor/?utm_source=Advisor1_Indy_Rectangle&utm_medium=web_ad&utm_content=gone_far&utm_campaign=Indy2012/bottom.js Server: Microsoft-IIS/6.0 Content-Length: 292 Content-Type: text/html X-AspNet-Version: 2.0.50727 X-Powered-By: ASP.NET X-Server: sjl04 | clean |
http://www.raymondjames.com/advisorchoice/independent_contractor/?utm_source=advisor1_indy_rectangle&utm_medium=web_ad&utm_content=gone_far&utm_campaign=indy2012/bottom.js | 200 OK Content-Length: 6093 Content-Type: text/html | clean |
http://www.raymondjames.com/advisorchoice/independent_contractor/?utm_source=advisor1_indy_rectangle&utm_medium=web_ad&utm_content=gone_far&utm_campaign=indy2012/top.js | 200 OK Content-Length: 6093 Content-Type: text/html | clean |
http://www.raymondjames.com/ | 200 OK Content-Length: 15784 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="http://2593890.fls.doubleclick.net/activityi;src=2593890;type=raymo614;cat=raymo401;ord=1;num=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
Hidden iFrame found. size: 1x1 style: hidden src: http://2593890.fls.doubleclick.net/activityi;src=2593890;type=raymo614;cat=raymo401;ord=1;num=1? <iframe src="http://2593890.fls.doubleclick.net/activityi;src=2593890;type=raymo614;cat=raymo401;ord=1;num=1?" width="1" height="1" frameborder="0" style="display:none"> Hidden iFrame found. size: 1x1 style: hidden src: http://2593890.fls.doubleclick.net/activityi;src=2593890;type=raymo614;cat=raymo401;ord=1;num= <iframe src="http://2593890.fls.doubleclick.net/activityi;src=2593890;type=raymo614;cat=raymo401;ord=1;num=' + a + '?" width="1" height="1" frameborder="0" style="display:none"> | ||
http://www.raymondjames.com/m/js/mobile.js | 200 OK Content-Length: 12978 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/front/top.js | 200 OK Content-Length: 2730 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/script/jquery/jquery.min.js | 200 OK Content-Length: 91342 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/about/colorbox/jquery.colorbox.js | 200 OK Content-Length: 24441 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/front/bottom.js | 200 OK Content-Length: 590 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/front/borders.js | 200 OK Content-Length: 884 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/script/flexslider/jquery.flexslider.js | 200 OK Content-Length: 40487 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/about/ | 200 OK Content-Length: 7167 Content-Type: text/html | clean |
http://www.raymondjames.com/about/top.js | 200 OK Content-Length: 5965 Content-Type: application/x-javascript | clean |
http://www.raymondjames.com/about/bottom.js | 200 OK Content-Length: 590 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: goindependentwithrj.com
Result:
HTTP/1.1 302 Object moved
Cache-Control: private
Connection: close
Date: Mon, 31 Mar 2014 10:51:10 GMT
Location: http://www.raymondjames.com/advisorchoice/independent_contractor/?utm_source=Advisor1_Indy_Rectangle&utm_medium=web_ad&utm_content=gone_far&utm_campaign=Indy2012
Server: Microsoft-IIS/6.0
Content-Length: 282
Content-Type: text/html
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Server: sjl03
...282 bytes of data.
GET / HTTP/1.1
Host: goindependentwithrj.com
Result:
HTTP/1.1 302 Object moved
Cache-Control: private
Connection: close
Date: Mon, 31 Mar 2014 10:51:10 GMT
Location: http://www.raymondjames.com/advisorchoice/independent_contractor/?utm_source=Advisor1_Indy_Rectangle&utm_medium=web_ad&utm_content=gone_far&utm_campaign=Indy2012
Server: Microsoft-IIS/6.0
Content-Length: 282
Content-Type: text/html
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Server: sjl03
...282 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: goindependentwithrj.com
Referer: http://www.google.com/search?q=goindependentwithrj.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: goindependentwithrj.com
Referer: http://www.google.com/search?q=goindependentwithrj.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=goindependentwithrj.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://goindependentwithrj.com/
Result: goindependentwithrj.com is not infected or malware details are not published yet.
Result: goindependentwithrj.com is not infected or malware details are not published yet.