Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=meristation.mx
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://meristation.mx/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=600 Connection: close Date: Thu, 25 Sep 2014 15:30:25 GMT Via: 1.1 varnish Age: 0 Location: http://www.meristation.com.mx/ Server: Apache Content-Length: 238 Content-Type: text/html; charset=iso-8859-1 Edge-Control: max-age=600s X-Varnish: 1200964332 1200964309 | clean |
http://www.meristation.com.mx/ | 200 OK Content-Length: 242254 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var refreshTimer = setInterval( function(){window.location=window.location.href;}, 900000); Antivirus reports:
Hidden iFrame found. size: 0x0 src: http://es.gmads.net/pct?gmtevt=8a8386853f7c657c013f9fc01ba62557&gmtcl=12 <iframe src="http://es.gmads.net/pct?gmtevt=8a8386853f7c657c013f9fc01ba62557&gmtcl=12" style="overflow:hidden" frameborder="0" width="0" height="0"> | ||
http://adserver.meristation.com/www/delivery/spcjs.php?id=1 | 200 OK Content-Length: 2280 Content-Type: application/x-javascript | clean |
http://js.meristation.com.mx/files/js/js_f58e078ad2bb2a7c824a430293ddfa32.js | 200 OK Content-Length: 185097 Content-Type: application/x-javascript | clean |
http://ep00.epimg.net/js/comun/avisopc.js | 200 OK Content-Length: 10565 Content-Type: application/x-javascript | clean |
http://ep00.epimg.net/js/pbs/pbs.slots.js | 200 OK Content-Length: 19408 Content-Type: application/x-javascript | clean |
http://meristation.player-top.prisasd.com/psdmedia/media/simple/js/SimpleMediaPlayer.min.js | 200 OK Content-Length: 68053 Content-Type: application/x-javascript | clean |
http://js.meristation.com.mx/files/js/js_b8a2ba32d879349365ff2fec409b6003.js | 200 OK Content-Length: 1092 Content-Type: application/x-javascript | clean |
http://connect.facebook.net/en_US/all.js | 200 OK Content-Length: 163644 Content-Type: application/x-javascript | clean |
http://meristation.mx//www.googleadservices.com/pagead/conversion.js/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=600 Connection: close Date: Thu, 25 Sep 2014 15:30:35 GMT Via: 1.1 varnish Age: 0 Location: http://www.meristation.com.mx/www.googleadservices.com/pagead/conversion.js/ Server: Apache Content-Length: 284 Content-Type: text/html; charset=iso-8859-1 Edge-Control: max-age=600s X-Varnish: 1200965028 | clean |
http://www.meristation.com.mx/www.googleadservices.com/pagead/conversion.js/ | 404 Not Found Content-Length: 5902 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var refreshTimer = setInterval( function(){window.location=window.location.href;}, 900000); Antivirus reports:
| ||
http://js.meristation.com.mx/omniture/mx/s_code.js | 200 OK Content-Length: 52386 Content-Type: application/x-javascript | clean |
http://js.meristation.com.mx/omniture/mx/omniture.js | 200 OK Content-Length: 2361 Content-Type: application/x-javascript | clean |
http://meristation.mx/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=600 Connection: close Date: Thu, 25 Sep 2014 15:30:37 GMT Via: 1.1 varnish Age: 0 Location: http://www.meristation.com.mx/test404page.js Server: Apache Content-Length: 252 Content-Type: text/html; charset=iso-8859-1 Edge-Control: max-age=600s X-Varnish: 1200965174 | clean |
http://www.meristation.com.mx/test404page.js | 404 Not Found Content-Length: 5838 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var refreshTimer = setInterval( function(){window.location=window.location.href;}, 900000); Antivirus reports:
| ||
http://www.meristation.com.mx/noticias/448267 | 200 OK Content-Length: 225652 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var refreshTimer = setInterval( function(){window.location=window.location.href;}, 900000); Antivirus reports:
Hidden iFrame found. size: 0x0 src: http://es.gmads.net/pct?gmtevt=8a8386853f7c657c013f9fc01ba62557&gmtcl=12 <iframe src="http://es.gmads.net/pct?gmtevt=8a8386853f7c657c013f9fc01ba62557&gmtcl=12" style="overflow:hidden" frameborder="0" width="0" height="0"> | ||
http://www.meristation.com.mx//www.googleadservices.com/pagead/conversion.js/ | 404 Not Found Content-Length: 5902 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var refreshTimer = setInterval( function(){window.location=window.location.href;}, 900000); Antivirus reports:
| ||
http://www.meristation.com.mx/analisis/448267 | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: meristation.mx
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=600
Connection: close
Date: Thu, 25 Sep 2014 15:30:25 GMT
Via: 1.1 varnish
Age: 0
Location: http://www.meristation.com.mx/
Server: Apache
Content-Length: 238
Content-Type: text/html; charset=iso-8859-1
Edge-Control: max-age=600s
X-Varnish: 1200964332 1200964309
...238 bytes of data.
GET / HTTP/1.1
Host: meristation.mx
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: max-age=600
Connection: close
Date: Thu, 25 Sep 2014 15:30:25 GMT
Via: 1.1 varnish
Age: 0
Location: http://www.meristation.com.mx/
Server: Apache
Content-Length: 238
Content-Type: text/html; charset=iso-8859-1
Edge-Control: max-age=600s
X-Varnish: 1200964332 1200964309
...238 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: meristation.mx
Referer: http://www.google.com/search?q=meristation.mx
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: meristation.mx
Referer: http://www.google.com/search?q=meristation.mx
Result:
The result is similar to the first query. There are no suspicious redirects found.