New scan:

Malware Scanner report for johnbaronsblog.com

Malicious/Suspicious/Total urls checked
0/0/12
Blacklists
OK
Malicious Redirects
OK
Malicious/Hidden/Total iFrames
0/4/4
4 suspicious iframes found. See details below
Deface / Content modification
Found
Probably the website is defaced. The following signature was found:

! Hacked by Peyman Siyahi !  (20 websites defaced)

See details below

Free periodic scanning and alerting: setup
(requires eVuln badge or a link to eVuln.com)

Malware & Hack Repair

  • Malware Removal
  • Blacklists Removal
  • Reason Eliminating
  • 1 Month Hack Insurance

More details

Website Hack Insurance

  • Files & DB Monitoring
  • Daily Backups
  • Malware & Hack Detection
  • Unlimited Hack Repairs

More details

Scanned pages/files

RequestServer responseStatus
http://www.johnbaronsblog.com/
200 OK
Content-Length: 1281
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://go.ad2up.com/afu.php?id=299977

<iframe src="http://go.ad2up.com/afu.php?id=299977" height="2" width="2">

Hidden iFrame found.
size: 2x2     
src: http://onclickads.net/afu.php?zoneid=299976&var=299976

<iframe src="http://onclickads.net/afu.php?zoneid=299976&var=299976" height="2" width="2">

Deface/Content modification. The following signature was found: ! Hacked by Peyman Siyahi !


<title>! Hacked by Peyman Siyahi !</title>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<iframe src="http://go.ad2up.com/afu.php?id=299977" height="2" width="2"></iframe>
<iframe src="http://onclickads.net/afu.php?zoneid=299976&var=299976" height="2" width="2"><
...[1194 bytes skipped]...


http://www.johnbaronsblog.com//go.mobisla.com/notice.php?p=299981&interactive=1&pushup=1/
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, must-revalidate, max-age=0
Connection: close
Date: Fri, 18 Sep 2015 19:27:33 GMT
Pragma: no-cache
Location: http://johnbaronsblog.com/go.mobisla.com/notice.php?p=299981&interactive=1&pushup=1/
Server: nginx/1.8.0
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
X-Pingback: http://johnbaronsblog.com/xmlrpc.php
clean
http://johnbaronsblog.com/go.mobisla.com/notice.php?p=299981&interactive=1&pushup=1/
404 Not Found
Content-Length: 51268
Content-Type: text/html
clean
http://johnbaronsblog.com/wp-includes/js/jquery/jquery.js?ver=1.11.3
200 OK
Content-Length: 95977
Content-Type: application/javascript
clean
http://johnbaronsblog.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1
200 OK
Content-Length: 7200
Content-Type: application/javascript
clean
http://platform.twitter.com/widgets.js?ver=1.1
200 OK
Content-Length: 134898
Content-Type: application/javascript
clean
http://johnbaronsblog.com/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.51.0-2014.06.20
200 OK
Content-Length: 15248
Content-Type: application/javascript
clean
http://johnbaronsblog.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=4.2.2
200 OK
Content-Length: 11200
Content-Type: application/javascript
clean
http://www.johnbaronsblog.com/test404page.js
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, must-revalidate, max-age=0
Connection: close
Date: Fri, 18 Sep 2015 19:27:39 GMT
Pragma: no-cache
Location: http://johnbaronsblog.com/test404page.js
Server: nginx/1.8.0
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
X-Pingback: http://johnbaronsblog.com/xmlrpc.php
clean
http://johnbaronsblog.com/test404page.js
404 Not Found
Content-Length: 51218
Content-Type: text/html
clean
http://johnbaronsblog.com/
200 OK
Content-Length: 1281
Content-Type: text/html
suspicious
Hidden iFrame found.
size: 2x2     
src: http://onclickads.net/afu.php?zoneid=299976&var=299976

<iframe src="http://onclickads.net/afu.php?zoneid=299976&var=299976" height="2" width="2">

Hidden iFrame found.
size: 2x2     
src: http://go.ad2up.com/afu.php?id=299977

<iframe src="http://go.ad2up.com/afu.php?id=299977" height="2" width="2">

http://johnbaronsblog.com//go.mobisla.com/notice.php?p=299981&interactive=1&pushup=1/
HTTP/1.1 301 Moved Permanently
Cache-Control: no-cache, must-revalidate, max-age=0
Connection: close
Date: Fri, 18 Sep 2015 19:27:42 GMT
Pragma: no-cache
Location: http://johnbaronsblog.com/go.mobisla.com/notice.php?p=299981&interactive=1&pushup=1/
Server: nginx/1.8.0
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Wed, 11 Jan 1984 05:00:00 GMT
X-Pingback: http://johnbaronsblog.com/xmlrpc.php
clean

Malicious Redirects

First query (normal visit):
GET / HTTP/1.1
Host: johnbaronsblog.com

Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 18 Sep 2015 19:27:41 GMT
Accept-Ranges: bytes
Server: nginx/1.8.0
Content-Length: 1281
Content-Type: text/html
Last-Modified: Fri, 04 Sep 2015 21:44:30 GMT

...1281 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: johnbaronsblog.com
Referer: http://www.google.com/search?q=johnbaronsblog.com

Result:
The result is similar to the first query. There are no suspicious redirects found.

Safe Browsing / Blacklists

Query: http://www.google.com/safebrowsing/diagnostic?site=johnbaronsblog.com

Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://johnbaronsblog.com/

Result: johnbaronsblog.com is not infected or malware details are not published yet.