Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=stm.org
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: attorneygeneralericholderontwitter.com
Result:
GET / HTTP/1.1
Host: attorneygeneralericholderontwitter.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: attorneygeneralericholderontwitter.com
Referer: http://www.google.com/search?q=attorneygeneralericholderontwitter.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: attorneygeneralericholderontwitter.com
Referer: http://www.google.com/search?q=attorneygeneralericholderontwitter.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://stm.org/ | HTTP/1.1 302 Found Connection: close Date: Mon, 26 Jan 2015 09:26:33 GMT Location: http://ww1.stm.org/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.3-7+squeeze23 | malicious |
http://ww1.stm.org/ | 200 OK Content-Length: 22025 Content-Type: text/html | suspicious |
Page code contains blacklisted domain: stm.org ...[3489 bytes skipped]... 06/2']); (function() { var ga = document.createElement('script'); ga.type = 'text/javascript'; ga.async = true; ga.src = ('https:' == document.location.protocol ? 'https://ssl' : 'http://www') + '.google-analytics.com/ga.js'; var s = document.getElementsByTagName('script')[0]; s.parentNode.insertBefore(ga, s); })(); </script> <script type="text/javascript"> $.ajax({ url: 'http://ww1.stm.org/' + 's' + 'earch/tsc.php?&ses=142226439470fe277c315f7c6225af1bede0cdf0ed&200=MTA0MTI2MzEx&21=NzguMTU4LjExLjIyNg==&681=MTQyMjI2NDM5NDcwZmUyNzdjMzE1ZjdjNjIyNWFmMWJlZGUwY2RmMGVk&682=&616=&crc=b1815d9b22153fdc43179c861feea461018ea149&cv=1'}); </script> </body></html> | ||
http://ajax.googleapis.com/ajax/libs/jquery/1.4.2/jquery.min.js | 200 OK Content-Length: 72174 Content-Type: text/javascript | clean |
http://stm.org/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |