Scanned pages/files
Request | Server response | Status |
http://opex.com.tr/ | 200 OK Content-Length: 10592 Content-Type: text/html | clean |
http://opex.com.tr/scripts/jquery.min.js | 200 OK Content-Length: 94841 Content-Type: application/javascript | clean |
http://opex.com.tr/scripts/jquery.onebyone.min.js | 200 OK Content-Length: 4167 Content-Type: application/javascript | clean |
http://opex.com.tr/scripts/jquery.touchwipe.min.js | 200 OK Content-Length: 1552 Content-Type: application/javascript | clean |
http://opex.com.tr/scripts/js_func.js | 200 OK Content-Length: 2708 Content-Type: application/javascript | clean |
http://opex.com.tr/scripts/jquery.bxSlider.min.js | 200 OK Content-Length: 13973 Content-Type: application/javascript | clean |
http://opex.com.tr/scripts/jquery.prettyPhoto.js | 200 OK Content-Length: 10884 Content-Type: application/javascript | clean |
http://opex.com.tr/scripts/jquery.blackandwhite.min.js | 200 OK Content-Length: 2718 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(a){a.fn.extend({BlackAndWhite:function(o){var b=this,l=this,h={hoverEffect:true,webworkerPath:false,responsive:true,invertHoverEffect:false};o=a.extend(h,o);var d=o.hoverEffect,e=o.webworkerPath,j=o.invertHoverEffect,i=o.responsive;var g=!!document.createElement("canvas").getContext,c=a(window);var n=(function(){return(typeof(Worker)!=="undefined")?true:false}());var f=a.browser.msie&&+a.browser.version===7;var k=function(w,s,q,z){var A=s.getContext("2d"),u=w,v=0,x;A.drawImage( Antivirus reports:
| ||
http://opex.com.tr/js/jquery.simplemodal.1.4.1.min.js | 200 OK Content-Length: 10198 Content-Type: application/javascript | clean |
http://opex.com.tr/index.html | 200 OK Content-Length: 10592 Content-Type: text/html | clean |
http://opex.com.tr/hakkimizda.html | 200 OK Content-Length: 8795 Content-Type: text/html | clean |
http://opex.com.tr/hermatiksofben.html | 200 OK Content-Length: 25545 Content-Type: text/html | clean |
http://opex.com.tr/esnekbaglantihortumlar.html | 200 OK Content-Length: 12695 Content-Type: text/html | clean |
http://opex.com.tr/karbonmonoksitcihazi.html | 200 OK Content-Length: 13389 Content-Type: text/html | clean |
http://opex.com.tr/dogalgazsoba.html | 200 OK Content-Length: 14139 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: opex.com.tr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 May 2014 23:35:28 GMT
Accept-Ranges: bytes
ETag: "38b5e-2960-4e828d9aa5fc0"
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Length: 10592
Content-Type: text/html
Last-Modified: Mon, 07 Oct 2013 16:07:35 GMT
...10592 bytes of data.
GET / HTTP/1.1
Host: opex.com.tr
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 04 May 2014 23:35:28 GMT
Accept-Ranges: bytes
ETag: "38b5e-2960-4e828d9aa5fc0"
Server: Apache/2
Vary: Accept-Encoding,User-Agent
Content-Length: 10592
Content-Type: text/html
Last-Modified: Mon, 07 Oct 2013 16:07:35 GMT
...10592 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: opex.com.tr
Referer: http://www.google.com/search?q=opex.com.tr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: opex.com.tr
Referer: http://www.google.com/search?q=opex.com.tr
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=opex.com.tr
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://opex.com.tr/
Result: opex.com.tr is not infected or malware details are not published yet.
Result: opex.com.tr is not infected or malware details are not published yet.