Scanned pages/files
Request | Server response | Status |
http://katy-perry.org/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 01 Jun 2014 15:24:03 GMT Location: http://www.katy-perry.org/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.katy-perry.org/xmlrpc.php X-Powered-By: PHP/5.4.23 | clean |
http://www.katy-perry.org/ | 200 OK Content-Length: 26614 Content-Type: text/html | clean |
http://fansites.hollywood.com/toolbar.js | 200 OK Content-Length: 2517 Content-Type: text/javascript | clean |
http://fansites.hollywood.com/ads_300.js | 200 OK Content-Length: 243 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<div style="width:100%; text-align:center;">'); document.write('<iframe width="300" height="250" src="http://fansites.hollywood.com/fansite_ad_300x250.html" scrolling="NO" frameborder="0"></iframe>'); document.write('</div>'); Antivirus reports:
| ||
http://bebicasal.com.ar/f.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sun, 01 Jun 2014 15:24:10 GMT Pragma: no-cache Accept-Ranges: bytes Age: 0 Location: http://www.bebicasal.com.ar/f.js/ Server: Apache/2 Content-Length: 368 Content-Type: text/html; charset=iso-8859-1 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://www.bebicasal.com.ar/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://www.bebicasal.com.ar/f.js/ | 404 Not Found Content-Length: 10124 Content-Type: text/html | clean |
http://www.bebicasal.com.ar/wp-includes/js/jquery/jquery.js?ver=1.8.3 | 200 OK Content-Length: 93658 Content-Type: application/x-javascript | clean |
http://www.bebicasal.com.ar/wp-content/themes/PhotopurePress/js/jquery.easing.1.3.js?ver=3.5.1 | 200 OK Content-Length: 8097 Content-Type: application/x-javascript | clean |
http://www.bebicasal.com.ar/wp-content/themes/PhotopurePress/js/jquery.nivo.slider.pack.js?ver=3.5.1 | 200 OK Content-Length: 15855 Content-Type: application/x-javascript | clean |
http://www.bebicasal.com.ar/wp-content/themes/PhotopurePress/js/custom.js?ver=3.5.1 | 200 OK Content-Length: 9362 Content-Type: application/x-javascript | clean |
http://www.bebicasal.com.ar/wp-content/themes/PhotopurePress/js/jquery.scrollTo-1.4.2-min.js?ver=3.5.1 | 200 OK Content-Length: 2252 Content-Type: application/x-javascript | clean |
http://www.bebicasal.com.ar/wp-content/themes/PhotopurePress/js/single-horizontal.js?ver=3.5.1 | 200 OK Content-Length: 4617 Content-Type: application/x-javascript | clean |
http://www.bebicasal.com.ar/wp-content/plugins/contact-form-7/jquery.form.js?ver=2.52 | 200 OK Content-Length: 26755 Content-Type: application/x-javascript | clean |
http://www.bebicasal.com.ar/wp-content/plugins/contact-form-7/scripts.js?ver=2.4.6 | 200 OK Content-Length: 5802 Content-Type: application/x-javascript | clean |
http://bebicasal.com.ar/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sun, 01 Jun 2014 15:24:19 GMT Pragma: no-cache Accept-Ranges: bytes Age: 0 Location: http://www.bebicasal.com.ar/test404page.js Server: Apache/2 Content-Length: 377 Content-Type: text/html; charset=iso-8859-1 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://www.bebicasal.com.ar/xmlrpc.php X-Powered-By: PHP/5.2.17 | clean |
http://www.bebicasal.com.ar/test404page.js | 404 Not Found Content-Length: 10124 Content-Type: text/html | clean |
http://www.bebicasal.com.ar/ | 200 OK Content-Length: 22075 Content-Type: text/html | clean |
http://minutebill.com/.install/video.php?ahsus=123 | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 01 Jun 2014 15:24:22 GMT Location: http://www.piwidesign.de/.install/video.php?ahsus=123 Server: Apache Content-Length: 261 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.piwidesign.de/.install/video.php?ahsus=123 | 403 Forbidden Content-Length: 2903 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: katy-perry.org
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 01 Jun 2014 15:24:03 GMT
Location: http://www.katy-perry.org/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.katy-perry.org/xmlrpc.php
X-Powered-By: PHP/5.4.23
...0 bytes of data.
GET / HTTP/1.1
Host: katy-perry.org
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Sun, 01 Jun 2014 15:24:03 GMT
Location: http://www.katy-perry.org/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.katy-perry.org/xmlrpc.php
X-Powered-By: PHP/5.4.23
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: katy-perry.org
Referer: http://www.google.com/search?q=katy-perry.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: katy-perry.org
Referer: http://www.google.com/search?q=katy-perry.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=katy-perry.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://katy-perry.org/
Result: katy-perry.org is not infected or malware details are not published yet.
Result: katy-perry.org is not infected or malware details are not published yet.