Scanned pages/files
Request | Server response | Status |
http://posiphoto.com/ | 200 OK Content-Length: 3216 Content-Type: text/html | clean |
http://posiphoto.com/index2.php | 200 OK Content-Length: 4147 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) function setSize(img_w, img_h){ var img_ratio = img_w/img_h; var win_w; var win_h; var max_h = 500; var max_w = img_ratio * max_h; var browser = navigator.appName; if (browser == "Microsoft Internet Explorer"){ win_w = document.body.offsetWidth; win_h = document.body.offsetHeight; if (win_w > max_w){ window.document.getElementById("website").width = "100%"; } else { window.document.getElementBy window.document.website.height = "100%"; window.document.getElementById("content").height = "100%"; } else { window.document.website.height = max_h; window.document.getElementById("content").height = max_h; } } } var popUp; function openW(theURL,features) { popUp = window.open(theURL,'videoPopup',features); } function closeW() { popUp.close(); videoPopup.close(); } Antivirus reports:
| ||
http://posiphoto.com/flashobject.js | 200 OK Content-Length: 7609 Content-Type: application/javascript | clean |
http://posiphoto.com/swfobject/swfobject.js | 200 OK Content-Length: 6758 Content-Type: application/javascript | clean |
http://posiphoto.com/swfaddress/swfaddress.js | 200 OK Content-Length: 13041 Content-Type: application/javascript | clean |
http://posiphoto.com/test404page.js | 404 Not Found Content-Length: 506 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: posiphoto.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 28 Jun 2014 04:38:36 GMT
Server: Apache/2.2.24 (Unix) mod_ssl/2.2.24 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Type: text/html
X-Powered-By: PHP/5.2.17
GET / HTTP/1.1
Host: posiphoto.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sat, 28 Jun 2014 04:38:36 GMT
Server: Apache/2.2.24 (Unix) mod_ssl/2.2.24 OpenSSL/1.0.0-fips mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635
Content-Type: text/html
X-Powered-By: PHP/5.2.17
Second query (visit from search engine):
GET / HTTP/1.1
Host: posiphoto.com
Referer: http://www.google.com/search?q=posiphoto.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: posiphoto.com
Referer: http://www.google.com/search?q=posiphoto.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=posiphoto.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://posiphoto.com/
Result: posiphoto.com is not infected or malware details are not published yet.
Result: posiphoto.com is not infected or malware details are not published yet.