Scanned pages/files
Request | Server response | Status |
http://nl.linkedin.com/pub/dir/jeroen/van+den+heuvel | 200 OK Content-Length: 59949 Content-Type: text/html | clean |
https://www.linkedin.com/uas/authping?apps=seo&fname=jeroen&lname=van+den+heuvel®ionid=nl%3A0 | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
http://s.c.lnkd.licdn.com/scds/concat/common/js?h=dfoaudjrk6rbf82f45bz5crwi-e9rsfv7b5gx0bk0tln31dx3sq-b88qxy99s08xoes3weacd08uc-bymlr3eiytxzjg9or01ze5ia8-ac8pg92mfnb2j836ntpvg1fsi-8s85e76fq22lk42rfavbckpvb-czstax4e6y68hymdvqxpwe5so-eq875keqggun9hoxzfhbanjes | 200 OK Content-Length: 86042 Content-Type: text/javascript | clean |
http://s.c.lnkd.licdn.com/scds/concat/common/js?h=b0otj9zjsih2zu4s3gxjejik2 | 200 OK Content-Length: 7569 Content-Type: text/javascript | clean |
http://s.c.lnkd.licdn.com/scds/concat/common/js?h=al2tir103409kmp66k8h9ld63 | 200 OK Content-Length: 1264 Content-Type: text/javascript | clean |
http://nl.linkedin.com//edge.quantserve.com/quant.js/ | 404 Not Found Content-Length: 30561 Content-Type: text/html | clean |
http://nl.linkedin.com/home | HTTP/1.1 301 Moved Permanently Connection: keep-alive Date: Wed, 25 Jun 2014 11:59:18 GMT Location: https://nl.linkedin.com Server: Apache-Coyote/1.1 Vary: Accept-Encoding Content-Language: nl-NL Content-Length: 0 P3P: CP="CAO CUR ADM DEV PSA PSD OUR" Set-Cookie: _lipt=deleteMe; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: bcookie="v=2&657184da-6de4-4709-abe8-0dfe1a80ada6"; Version=1; Domain=linkedin.com; Max-Age=63072000; Expires=Fri, 24-Jun-2016 11:59:18 GMT; Path=/ Set-Cookie: leo_auth_token="GST:Ums-O8ji2kgHeFciRZsBFRIv5ZNHWOsbfCs4LFsMILNVu5_blJ9cvC:1403697558:87373a71d1046695d6efd752229c8730c5bbd6b7"; Version=1; Max-Age=1799; Expires=Wed, 25-Jun-2014 12:29:17 GMT; Path=/ Set-Cookie: sl="delete me"; Version=1; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: sl="delete me"; Version=1; Domain=.nl.linkedin.com; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: s_leo_auth_token="delete me"; Version=1; Max-Age=0; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/ Set-Cookie: JSESSIONID="ajax:8099948119189102736"; Version=1; Domain=.nl.linkedin.com; Path=/ Set-Cookie: visit="v=1&G"; Version=1; Max-Age=63072000; Expires=Fri, 24-Jun-2016 11:59:18 GMT; Path=/ Set-Cookie: lang="v=2&lang=nl-nl"; Version=1; Domain=linkedin.com; Path=/ Set-Cookie: lang="v=2&lang=nl-nl"; Version=1; Domain=linkedin.com; Path=/ Set-Cookie: lidc="b=LB38:g=101:u=1:i=1403697558:t=1403783958:s=3447162980"; Expires=Thu, 26 Jun 2014 11:59:18 GMT; domain=.linkedin.com; Path=/ X-FS-UUID: 68b00d1d7eef7a1310f866b4422b0000 X-Li-Fabric: PROD-ELA4 X-Li-Pop: PROD-ELA4 X-LI-UUID: aLANHX7vehMQ+Ga0QisAAA== | clean |
https://nl.linkedin.com/ | 200 OK Content-Length: 49458 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) YEvent.on( window, 'load', function() { (function () { var protocol = 'https:'; var d = new Image(1, 1); d.onerror = d.onload = function () { d.onerror = d.onload = null; }; d.src = [ protocol, "//secure-us.imrworldwide.com/cgi-bin/m?ci=us-603751h&cg=0&cc=1&si=", escape(window.location.href), "&ts=compact&rnd=", (new Date()).getTime() ].join(''); })(); }); Antivirus reports:
| ||
https://static.licdn.com:443/scds/common/u/lib/fizzy/fz-1.3.5-min.js | 200 OK Content-Length: 26523 Content-Type: text/javascript | clean |
https://static.licdn.com/scds/concat/common/js?h=3nuvxgwg15rbghxm1gpzfbya2-35e6ug1j754avohmn1bzmucat-mv3v66b8q0h1hvgvd3yfjv5f-14k913qahq3mh0ac0lh0twk9v&fc=1 | 200 OK Content-Length: 2744 Content-Type: text/javascript | clean |
https://static.licdn.com/scds/concat/common/js?h=dfoaudjrk6rbf82f45bz5crwi-e9rsfv7b5gx0bk0tln31dx3sq-b88qxy99s08xoes3weacd08uc-3eh5zbf8m3976frnzqqz8r2md-1l6r5aklcrehj1n7wy2v08xoy-8zc7dy7k0uqxxso1zmcx40mxo-4u94p4bxx04dc4qyt04hi6b7z-6qxi7j04m9bajw0tu0npnkexj-8s85e76fq22lk42rfavbckpvb-6b5tomv24hymqjdn9yh9vdxyg-95d8d303rtd0n9wj4dcjbnh2c&fc=1 | 200 OK Content-Length: 187078 Content-Type: text/javascript | clean |
https://static.licdn.com/scds/common/u/js/scds-hashes.js | 200 OK Content-Length: 186 Content-Type: text/javascript | clean |
https://static.licdn.com/scds/concat/common/js?h=25kaepc6rgo1820ap1rglmzr4-c19zsujfl1pg46iqy33ubhqc5-8dsj0i05aa9so2un8dmci2gmx-ascppxxu6dqpt5sppka77kdt0-39o2kw4renyd4i8pt5n9x0qaz-9cttgd1ueltkur8cb164nt1vt-35b6d44bfxo2cvy5hbzc0zsgl&fc=1 | 200 OK Content-Length: 84246 Content-Type: text/javascript | clean |
https://static.licdn.com/scds/concat/common/js?h=3qsk2peor188gw7gmh2irlhe5-78bwuml1uwwm9yb9sr3bw68qb-9xms7fd8xdfrly2skx89dmkyc&fc=1 | 200 OK Content-Length: 20133 Content-Type: text/javascript | clean |
https://www.linkedin.com/uas/authping | 200 OK Content-Length: 0 Content-Type: text/javascript | clean |
https://static.licdn.com/scds/concat/common/js?h=4gd308q7uhcsqx9gfzu9dv06p&fc=1 | 200 OK Content-Length: 343 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: nl.linkedin.com
Result:
GET / HTTP/1.1
Host: nl.linkedin.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: nl.linkedin.com
Referer: http://www.google.com/search?q=nl.linkedin.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: nl.linkedin.com
Referer: http://www.google.com/search?q=nl.linkedin.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=nl.linkedin.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://nl.linkedin.com/
Result: nl.linkedin.com is not infected or malware details are not published yet.
Result: nl.linkedin.com is not infected or malware details are not published yet.