Scanned pages/files
Request | Server response | Status |
http://risk-informed.net/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:18:56 GMT Location: http://www.tssa.org Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/ | 200 OK Content-Length: 22651 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js | 200 OK Content-Length: 93868 Content-Type: text/javascript | clean |
http://risk-informed.net/scripts/formvalidation.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:19:00 GMT Location: http://www.tssa.org/scripts/formvalidation.js Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/scripts/formvalidation.js | 200 OK Content-Length: 8033 Content-Type: application/x-javascript | clean |
http://risk-informed.net/scripts/modernizr.custom.82188.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:19:01 GMT Location: http://www.tssa.org/scripts/modernizr.custom.82188.js Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/scripts/modernizr.custom.82188.js | 200 OK Content-Length: 15156 Content-Type: application/x-javascript | clean |
http://risk-informed.net/scripts/tssa.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:17:32 GMT Location: http://www.tssa.org/scripts/tssa.js Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/scripts/tssa.js | 200 OK Content-Length: 6762 Content-Type: application/x-javascript | clean |
http://risk-informed.net/scripts/coolfieldset/js/jquery.coolfieldset.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:19:05 GMT Location: http://www.tssa.org/scripts/coolfieldset/js/jquery.coolfieldset.js Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/scripts/coolfieldset/js/jquery.coolfieldset.js | 200 OK Content-Length: 1530 Content-Type: application/x-javascript | clean |
http://risk-informed.net/scripts/stylechanger.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:17:35 GMT Location: http://www.tssa.org/scripts/stylechanger.js Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/scripts/stylechanger.js | 200 OK Content-Length: 1632 Content-Type: application/x-javascript | clean |
http://w.sharethis.com/button/buttons.js | 200 OK Content-Length: 145774 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) if(typeof(stlib)=="undefined"){var stlib={}}if(!stlib.functions){stlib.functions=[];stlib.functionCount=0}stlib.global={};stlib.global.hash=document.location.href.split("#");stlib.global.hash.shift();stlib.global.hash=stlib.global.hash.join("#");stlib.dynamicOn=true;stlib.debugOn=false;stlib.debug={count:0,messages:[],debug:function(b,a){if(a&&(typeof console)!="undefined"){console.log(b)}stlib.debug.messages.push(b)},show:function(a){for(message in stlib.debug.messages){if((typeof conso Antivirus reports:
| ||
http://risk-informed.net/regulated/about/profile.aspx | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:19:07 GMT Location: http://www.tssa.org/regulated/about/profile.aspx Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/regulated/about/profile.aspx | 200 OK Content-Length: 27058 Content-Type: text/html | clean |
http://www.tssa.org/regulated/about/ | 403 Forbidden Content-Length: 5418 Content-Type: text/html | clean |
http://www.tssa.org/test404page.js | 404 Not Found Content-Length: 5170 Content-Type: text/html | clean |
http://risk-informed.net/regulated/contact/Default.aspx | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:17:40 GMT Location: http://www.tssa.org/regulated/contact/Default.aspx Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/regulated/contact/default.aspx | 200 OK Content-Length: 23676 Content-Type: text/html | clean |
http://www.tssa.org/scripts/calendar.js | 200 OK Content-Length: 12042 Content-Type: application/x-javascript | clean |
http://risk-informed.net/scripts/popupTips.js | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:19:14 GMT Location: http://www.tssa.org/scripts/popupTips.js Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/scripts/popuptips.js | 200 OK Content-Length: 1653 Content-Type: application/x-javascript | clean |
http://risk-informed.net/regulated/contact/ | HTTP/1.1 302 Moved Temporarily Connection: close Date: Wed, 24 Sep 2014 02:19:15 GMT Location: http://www.tssa.org/regulated/contact/ Server: Apache-Coyote/1.1 Content-Length: 0 | clean |
http://www.tssa.org/regulated/contact/ | 200 OK Content-Length: 23676 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: risk-informed.net
Result:
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Wed, 24 Sep 2014 02:18:56 GMT
Location: http://www.tssa.org
Server: Apache-Coyote/1.1
Content-Length: 0
...0 bytes of data.
GET / HTTP/1.1
Host: risk-informed.net
Result:
HTTP/1.1 302 Moved Temporarily
Connection: close
Date: Wed, 24 Sep 2014 02:18:56 GMT
Location: http://www.tssa.org
Server: Apache-Coyote/1.1
Content-Length: 0
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: risk-informed.net
Referer: http://www.google.com/search?q=risk-informed.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: risk-informed.net
Referer: http://www.google.com/search?q=risk-informed.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=risk-informed.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://risk-informed.net/
Result: risk-informed.net is not infected or malware details are not published yet.
Result: risk-informed.net is not infected or malware details are not published yet.