Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=philwcpa.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://philwcpa.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://philwcpa.com/ | 200 OK Content-Length: 29308 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://ferienwohnungen-moeller.de/000000964612a782b/Q2ygnZwR.php?id=64889464" type="text/javascript"></script> | ||
http://philwcpa.com/home_page.html | 200 OK Content-Length: 1559 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://ferienwohnungen-moeller.de/000000964612a782b/Q2ygnZwR.php?id=64889462" type="text/javascript"></script> | ||
http://philwcpa.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://philwcpa.com/45th_annv_J&E.htm | 200 OK Content-Length: 2671 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://ferienwohnungen-moeller.de/000000964612a782b/Q2ygnZwR.php?id=64889454" type="text/javascript"></script> | ||
http://philwcpa.com/OlympicTorchOdysee.htm | 200 OK Content-Length: 2511 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://ferienwohnungen-moeller.de/000000964612a782b/Q2ygnZwR.php?id=64889455" type="text/javascript"></script> | ||
http://philwcpa.com/index.htm | 300 Multiple Choices Content-Length: 531 Content-Type: text/html | clean |
http://philwcpa.com/index.xml | 200 OK Content-Length: 25898 Content-Type: application/xml | clean |
http://philwcpa.com/index.html | 200 OK Content-Length: 29308 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://ferienwohnungen-moeller.de/000000964612a782b/Q2ygnZwR.php?id=64889464" type="text/javascript"></script> | ||
http://philwcpa.com/TheWeinbergerHolidayzPage.htm | 200 OK Content-Length: 1833 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://ferienwohnungen-moeller.de/000000964612a782b/Q2ygnZwR.php?id=64889459" type="text/javascript"></script> | ||
http://philwcpa.com/Otherfamilypage.htm | 200 OK Content-Length: 1682 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://ferienwohnungen-moeller.de/000000964612a782b/Q2ygnZwR.php?id=64889457" type="text/javascript"></script> | ||
http://philwcpa.com/index.mht | 200 OK Content-Length: 9653 Content-Type: text/plain | clean |
http://philwcpa.com/3D"file:///C:\Users\Dad%20&%20Mom\Website\= | 404 Not Found Content-Length: 365 Content-Type: text/html | clean |
http://philwcpa.com/3D"file:///C:\Users\Dad%20&%20Mom\Website\Janice%20Weinberger%20Re= | 404 Not Found Content-Length: 385 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: philwcpa.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 28 Jun 2014 21:51:20 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 29308
Content-Type: text/html
Last-Modified: Sat, 11 Jan 2014 15:47:58 GMT
...29308 bytes of data.
GET / HTTP/1.1
Host: philwcpa.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 28 Jun 2014 21:51:20 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 29308
Content-Type: text/html
Last-Modified: Sat, 11 Jan 2014 15:47:58 GMT
...29308 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: philwcpa.com
Referer: http://www.google.com/search?q=philwcpa.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: philwcpa.com
Referer: http://www.google.com/search?q=philwcpa.com
Result:
The result is similar to the first query. There are no suspicious redirects found.