Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=oilpatchliving.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.oilpatchliving.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Sun, 05 Oct 2014 17:24:34 GMT Location: http://oilpatchliving.com/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://oilpatchliving.com/xmlrpc.php | clean |
http://oilpatchliving.com/ | 200 OK Content-Length: 31465 Content-Type: text/html | clean |
http://oilpatchliving.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/sociable/js/sociable.js?ver=3.8.4 | 200 OK Content-Length: 1959 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/sociable/js/vuible.js?ver=3.8.4 | 200 OK Content-Length: 370 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/sociable/js/addtofavorites.js?ver=3.8.4 | 200 OK Content-Length: 602 Content-Type: application/javascript | clean |
https://maps.googleapis.com/maps/api/js?sensor=false&language=en&ver=3 | 200 OK Content-Length: 4950 Content-Type: text/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/WeatherSlider/js/jquery-animate-background-position.js?ver=2.5.0 | 200 OK Content-Length: 2101 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function($) { if(!document.defaultView || !document.defaultView.getComputedStyle){ var oldCSS = jQuery.css; jQuery.css = function(elem, name, force){ if(name === 'background-position'){ name = 'backgroundPosition'; } if(name !== 'backgroundPosition' || !elem.currentStyle || elem.currentStyle[ name ]){ return oldCSS.apply(this, arguments); } var style = elem.style; if ( !fo fx.start = [start[0],start[2]]; var end = toArray(fx.end); fx.end = [end[0],end[2]]; fx.unit = [end[1],end[3]]; fx.bgPosReady = true; } var nowPosX = []; nowPosX[0] = ((fx.end[0] - fx.start[0]) * fx.pos) + fx.start[0] + fx.unit[0]; nowPosX[1] = ((fx.end[1] - fx.start[1]) * fx.pos) + fx.start[1] + fx.unit[1]; fx.elem.style.backgroundPosition = nowPosX[0]+' '+nowPosX[1]; }; })(jQuery); Antivirus reports:
| ||
http://oilpatchliving.com/wp-content/plugins/WeatherSlider/js/jquery-easing-1.3.js?ver=1.3.0 | 200 OK Content-Length: 8101 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/WeatherSlider/js/weatherslider.kreaturamedia.jquery.js?ver=2.5.0 | 200 OK Content-Length: 26332 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/adrotate/library/jquery.clicktracker.js?ver=0.5 | 200 OK Content-Length: 830 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) jQuery(document).ready(function() { jQuery("a.gofollow").click(function(){ jQuery(this).each(function() { var tracker = jQuery(this).attr("data-track"); var debug = jQuery(this).attr("data-debug"); jQuery.post( '//' + location.host + '/wp-content/plugins/adrotate/library/clicktracker.php', { track: tracker } ); if(debug == 1) { alert('Tracker: ' + tracker + '\n\nTracker must be defined for clicktracking to work.'); } }); }); }); Antivirus reports:
| ||
http://apis.google.com/js/plusone.js | 200 OK Content-Length: 12509 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.50.0-2014.02.05 | 200 OK Content-Length: 16305 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.7.2 | 200 OK Content-Length: 8913 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/themes/genesis/lib/js/menu/superfish.min.js?ver=1.7.4 | 200 OK Content-Length: 4207 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: oilpatchliving.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 05 Oct 2014 17:24:37 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://oilpatchliving.com/xmlrpc.php
GET / HTTP/1.1
Host: oilpatchliving.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 05 Oct 2014 17:24:37 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-Pingback: http://oilpatchliving.com/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: oilpatchliving.com
Referer: http://www.google.com/search?q=oilpatchliving.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: oilpatchliving.com
Referer: http://www.google.com/search?q=oilpatchliving.com
Result:
The result is similar to the first query. There are no suspicious redirects found.