Scanned pages/files
Request | Server response | Status |
http://hsvstm.at/ | HTTP/1.1 302 Found Connection: close Date: Mon, 02 Jun 2014 22:26:03 GMT Location: http://www.hsvstm.at/ Server: Apache Content-Length: 264 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.hsvstm.at/ | 200 OK Content-Length: 32071 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) (function() { var id = "privacy_W4YPRD_cm4all_com_widgets_FaceBook_2720287"; var width = "180"; var height = "25"; var embed = "http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.hsvstm.at%2FStartseite%2Findex.php%2F&layout=button_count&show_faces=false&font&action=like&colorscheme=light&width=180&height=25"; var verb = "like"; var title = ""; }); window.privacy[id].draw( window.privacy[id].state ); }; Common.loadCss("/.cm4all/widgetres.php/cm4all.com.widgets.FaceBook/res/privacy.css"); Common.requireLibrary( [ "/.cm4all/widgetres.php/cm4all.com.widgets.FaceBook/res/privacy.js" ], libraryLoaded ); })(); Antivirus reports:
| ||
http://web.w4ysites.com/cm4all-beng-proxy/beng-proxy.js | 200 OK Content-Length: 2067 Content-Type: application/x-javascript | clean |
http://web.w4ysites.com/res/generated/beng-editor/aggregation/common@0.2.197.30.js | 200 OK Content-Length: 269402 Content-Type: application/x-javascript | clean |
http://hsvstm.at/.cm4all/widgetres.php/cm4all.com.widgets.FacebookPage/res/helper.js | HTTP/1.1 302 Found Connection: close Date: Mon, 02 Jun 2014 22:26:05 GMT Location: http://www.hsvstm.at/.cm4all/widgetres.php/cm4all.com.widgets.FacebookPage/res/helper.js Server: Apache Content-Length: 331 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.hsvstm.at/.cm4all/widgetres.php/cm4all.com.widgets.facebookpage/res/helper.js | 502 Bad Gateway Content-Length: 25 Content-Type: text/plain | clean |
http://www.hsvstm.at/test404page.js | 404 Not Found Content-Length: 2918 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hsvstm.at
Result:
HTTP/1.1 302 Found
Connection: close
Date: Mon, 02 Jun 2014 22:26:03 GMT
Location: http://www.hsvstm.at/
Server: Apache
Content-Length: 264
Content-Type: text/html; charset=iso-8859-1
...264 bytes of data.
GET / HTTP/1.1
Host: hsvstm.at
Result:
HTTP/1.1 302 Found
Connection: close
Date: Mon, 02 Jun 2014 22:26:03 GMT
Location: http://www.hsvstm.at/
Server: Apache
Content-Length: 264
Content-Type: text/html; charset=iso-8859-1
...264 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: hsvstm.at
Referer: http://www.google.com/search?q=hsvstm.at
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hsvstm.at
Referer: http://www.google.com/search?q=hsvstm.at
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hsvstm.at
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://hsvstm.at/
Result: hsvstm.at is not infected or malware details are not published yet.
Result: hsvstm.at is not infected or malware details are not published yet.