Scanned pages/files
Request | Server response | Status |
http://macahelbal.com/ | 200 OK Content-Length: 15402 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if (0 == 2) { if (!/android|iphone|ipod|series60|symbian|windows ce|blackberry/i.test(navigator.userAgent)) { jQuery(function($) { $("a[rel^='lightbox']").slimbox({ loop: true, overlayOpacity: 0.8, overlayFadeDuration: 400, resizeDuration: 400, resizeEasing: "jswing", initialWidth: 250, initialHeight: 250, imageFadeDuration: 400, captionAnimationDuration: 400, counterText: "Image {x} of {y}", speed: 1000, speedIn: null, speedOut: null, next: '#slideshowboxnext', prev: '#slideshowboxprev', pager: '#slideshowboxnav', pagerEvent: 'click', before: null, after: null, shuffle: null, random: 0, fit: 0, containerResize: 1, pause: 1, pauseOnPagerHover: 0, autostop: 0, delay: 0, nowrap: 0, randomizeEffects: 1, rev: 0 }); }; }); Antivirus reports:
| ||
http://macahelbal.com/plugins/system/cdscriptegrator/libraries/highslide/js/highslide-full.min.js | 200 OK Content-Length: 70768 Content-Type: application/javascript | clean |
http://macahelbal.com/plugins/system/cdscriptegrator/libraries/jquery/js/jquery-1.4.4.min.js | 200 OK Content-Length: 78601 Content-Type: application/javascript | clean |
http://macahelbal.com/plugins/system/cdscriptegrator/libraries/jquery/js/jquery-noconflict.js | 200 OK Content-Length: 20 Content-Type: application/javascript | clean |
http://macahelbal.com/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/javascript | clean |
http://macahelbal.com/plugins/system/rokbox/rokbox.js | 200 OK Content-Length: 21583 Content-Type: application/javascript | clean |
http://macahelbal.com/plugins/system/rokbox/themes/light/rokbox-config.js | 200 OK Content-Length: 2598 Content-Type: application/javascript | clean |
http://macahelbal.com/modules/mod_jt_slideshow/scripts/jquery.js | 200 OK Content-Length: 77746 Content-Type: application/javascript | clean |
http://macahelbal.com/modules/mod_jt_slideshow/scripts/jquery.cycle.all.min.js | 200 OK Content-Length: 32046 Content-Type: application/javascript | clean |
http://macahelbal.com/modules/mod_jt_slideshow/scripts/jquery.easing.1.3.js | 200 OK Content-Length: 8097 Content-Type: application/javascript | clean |
http://macahelbal.com/modules/mod_jt_slideshow/scripts/jquery.easing.compatibility.js | 200 OK Content-Length: 1726 Content-Type: application/javascript | clean |
http://macahelbal.com/urunlerimiz.html | 200 OK Content-Length: 14123 Content-Type: text/html | clean |
http://www.macahelbal.com/test/components/com_virtuemart/fetchscript.php?gzip=0&subdir[0]=/themes/default&file[0]=theme.js&subdir[1]=/js&file[1]=sleight.js&subdir[2]=/js/mootools&file[2]=mootools-release-1.11.js&subdir[3]=/js/mootools&file[3]=mooPrompt.js | 200 OK Content-Length: 56349 Content-Type: text/javascript | clean |
http://macahelbal.com/hakkimizda.html | 200 OK Content-Length: 6529 Content-Type: text/html | clean |
http://macahelbal.com/galeri.html | 200 OK Content-Length: 9939 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: macahelbal.com
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Wed, 11 Jun 2014 03:09:11 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Wed, 11 Jun 2014 03:09:11 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 3547185efe02ad76413d0196ea93c5b2=d86181f5c12aedc7685c381157c451b0; path=/
X-Powered-By: PHP/5.3.26
GET / HTTP/1.1
Host: macahelbal.com
Result:
HTTP/1.1 200 OK
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Wed, 11 Jun 2014 03:09:11 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html; charset=utf-8
Expires: Mon, 1 Jan 2001 00:00:00 GMT
Last-Modified: Wed, 11 Jun 2014 03:09:11 GMT
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: 3547185efe02ad76413d0196ea93c5b2=d86181f5c12aedc7685c381157c451b0; path=/
X-Powered-By: PHP/5.3.26
Second query (visit from search engine):
GET / HTTP/1.1
Host: macahelbal.com
Referer: http://www.google.com/search?q=macahelbal.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: macahelbal.com
Referer: http://www.google.com/search?q=macahelbal.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=macahelbal.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://macahelbal.com/
Result: macahelbal.com is not infected or malware details are not published yet.
Result: macahelbal.com is not infected or malware details are not published yet.