Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=oilpatchsales.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: elite-locksmith.co.uk
Result:
GET / HTTP/1.1
Host: elite-locksmith.co.uk
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: elite-locksmith.co.uk
Referer: http://www.google.com/search?q=elite-locksmith.co.uk
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: elite-locksmith.co.uk
Referer: http://www.google.com/search?q=elite-locksmith.co.uk
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://oilpatchsales.com/ | HTTP/1.1 301 Moved Permanently Cache-Control: max-age=900 Connection: close Date: Thu, 25 Dec 2014 22:32:31 GMT Age: 1 Location: http://www.oilpatchliving.com Server: Microsoft-IIS/7.5 Content-Length: 0 Content-Type: text/html X-AspNet-Version: 4.0.30319 X-Powered-By: ASP.NET | malicious |
http://www.oilpatchliving.com/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 25 Dec 2014 22:32:33 GMT Location: http://oilpatchliving.com/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://oilpatchliving.com/xmlrpc.php | clean |
http://oilpatchliving.com/ | 200 OK Content-Length: 29827 Content-Type: text/html | clean |
http://oilpatchliving.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/sociable/js/sociable.js?ver=3.8.5 | 200 OK Content-Length: 1959 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/sociable/js/vuible.js?ver=3.8.5 | 200 OK Content-Length: 370 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/sociable/js/addtofavorites.js?ver=3.8.5 | 200 OK Content-Length: 602 Content-Type: application/javascript | clean |
https://maps.googleapis.com/maps/api/js?sensor=false&language=en&ver=3 | 200 OK Content-Length: 4221 Content-Type: text/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/WeatherSlider/js/jquery-animate-background-position.js?ver=2.5.0 | 200 OK Content-Length: 2101 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function($) { if(!document.defaultView || !document.defaultView.getComputedStyle){ var oldCSS = jQuery.css; jQuery.css = function(elem, name, force){ if(name === 'background-position'){ name = 'backgroundPosition'; } if(name !== 'backgroundPosition' || !elem.currentStyle || elem.currentStyle[ name ]){ return oldCSS.apply(this, arguments); } var style = elem.style; if ( !fo fx.start = [start[0],start[2]]; var end = toArray(fx.end); fx.end = [end[0],end[2]]; fx.unit = [end[1],end[3]]; fx.bgPosReady = true; } var nowPosX = []; nowPosX[0] = ((fx.end[0] - fx.start[0]) * fx.pos) + fx.start[0] + fx.unit[0]; nowPosX[1] = ((fx.end[1] - fx.start[1]) * fx.pos) + fx.start[1] + fx.unit[1]; fx.elem.style.backgroundPosition = nowPosX[0]+' '+nowPosX[1]; }; })(jQuery); Antivirus reports:
| ||
http://oilpatchliving.com/wp-content/plugins/WeatherSlider/js/jquery-easing-1.3.js?ver=1.3.0 | 200 OK Content-Length: 8101 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/WeatherSlider/js/weatherslider.kreaturamedia.jquery.js?ver=2.5.0 | 200 OK Content-Length: 26332 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/adrotate/library/jquery.clicktracker.js?ver=0.5 | 200 OK Content-Length: 830 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) jQuery(document).ready(function() { jQuery("a.gofollow").click(function(){ jQuery(this).each(function() { var tracker = jQuery(this).attr("data-track"); var debug = jQuery(this).attr("data-debug"); jQuery.post( '//' + location.host + '/wp-content/plugins/adrotate/library/clicktracker.php', { track: tracker } ); if(debug == 1) { alert('Tracker: ' + tracker + '\n\nTracker must be defined for clicktracking to work.'); } }); }); }); Antivirus reports:
| ||
http://apis.google.com/js/plusone.js | 200 OK Content-Length: 12797 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.50.0-2014.02.05 | 200 OK Content-Length: 16305 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.7.2 | 200 OK Content-Length: 8913 Content-Type: application/javascript | clean |
http://oilpatchliving.com/wp-content/themes/genesis/lib/js/menu/superfish.min.js?ver=1.7.4 | 200 OK Content-Length: 4207 Content-Type: application/javascript | clean |