Scanned pages/files
Request | Server response | Status |
http://spymaniac.com/ | 200 OK Content-Length: 34653 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<a href="index.php" title="Decrease size" onclick="changeFontSize(-1); return false;" class="smaller"><img style="margin:0 padding:0;" src="modules/mod_fontsize/img/resizer_02.jpg" alt="Increase size" /></a>'); document.write('<a href="index.php" title="Reset font size to default" onclick="revertStyles(); return false;" class="reset"><img style="margin:0 padding:0;" src="modules/mod_fontsize/img/resizer_03.jpg" alt="Reset size" /></a>'); document.write('<a href="index.php" title="Increase size" onclick="changeFontSize(1); return false;" class="larger"><img style="margin:0 padding:0;" src="modules/mod_fontsize/img/resizer_01.jpg" alt="Increase size" /></a>'); Antivirus reports:
| ||
http://spymaniac.com/media/system/js/mootools-core.js | 200 OK Content-Length: 96888 Content-Type: application/x-javascript | clean |
http://spymaniac.com/media/system/js/core.js | 200 OK Content-Length: 4799 Content-Type: application/x-javascript | clean |
http://spymaniac.com//ajax.googleapis.com/ajax/libs/jquery/1.8/jquery.min.js/ | 404 Not Found Content-Length: 320 Content-Type: text/html | clean |
http://spymaniac.com/test404page.js | 404 Not Found Content-Length: 279 Content-Type: text/html | clean |
http://spymaniac.com/components/com_k2/js/k2.js?v2.6.6&sitepath=/ | 200 OK Content-Length: 8248 Content-Type: application/x-javascript | clean |
http://spymaniac.com/media/system/js/caption.js | 200 OK Content-Length: 733 Content-Type: application/x-javascript | clean |
http://spymaniac.com/media/system/js/mootools-more.js | 200 OK Content-Length: 239157 Content-Type: application/x-javascript | clean |
http://spymaniac.com/media/tabs/js/script.min.js | 200 OK Content-Length: 4430 Content-Type: application/x-javascript | clean |
http://spymaniac.com/plugins/system/shadowbox/shadowbox/min/index.php?g=sb&ad=base&lan=en&play=img-iframe | 200 OK Content-Length: 30456 Content-Type: application/x-javascript | clean |
http://spymaniac.com/modules/mod_AutsonSlideShow/js/jquery-1.5.2.min.js | 200 OK Content-Length: 85940 Content-Type: application/x-javascript | clean |
http://spymaniac.com/modules/mod_AutsonSlideShow/js/jquery.easing.1.3.js | 200 OK Content-Length: 8301 Content-Type: application/x-javascript | clean |
http://spymaniac.com/modules/mod_AutsonSlideShow/js/jquery.animate-colors-min.js | 200 OK Content-Length: 1745 Content-Type: application/x-javascript | clean |
http://spymaniac.com/modules/mod_AutsonSlideShow/js/jquery.skitter.min.js | 200 OK Content-Length: 89441 Content-Type: application/x-javascript | clean |
http://spymaniac.com/modules/mod_fontsize/js/md_stylechanger.js | 200 OK Content-Length: 4802 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: spymaniac.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Fri, 22 Aug 2014 04:33:31 GMT
Pragma: no-cache
Server: Apache/2.2
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: X-Mapping-feojnbhb=6652B3BAD9D36EC824EF95BEB8C1BDDB; path=/
Set-Cookie: af7ce30e0645d291faa8b57ef507935b=q995ucka08j8shgf2tuprkt1u3; path=/
X-Logged-In: False
GET / HTTP/1.1
Host: spymaniac.com
Result:
HTTP/1.1 200 OK
Cache-Control: no-cache
Connection: close
Date: Fri, 22 Aug 2014 04:33:31 GMT
Pragma: no-cache
Server: Apache/2.2
Content-Type: text/html; charset=utf-8
P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM"
Set-Cookie: X-Mapping-feojnbhb=6652B3BAD9D36EC824EF95BEB8C1BDDB; path=/
Set-Cookie: af7ce30e0645d291faa8b57ef507935b=q995ucka08j8shgf2tuprkt1u3; path=/
X-Logged-In: False
Second query (visit from search engine):
GET / HTTP/1.1
Host: spymaniac.com
Referer: http://www.google.com/search?q=spymaniac.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: spymaniac.com
Referer: http://www.google.com/search?q=spymaniac.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=spymaniac.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://spymaniac.com/
Result: spymaniac.com is not infected or malware details are not published yet.
Result: spymaniac.com is not infected or malware details are not published yet.