Scanned pages/files
Request | Server response | Status |
http://united-capital-of-philadelphia.unitedcp.com/ | 200 OK Content-Length: 14035 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/sites/default/files/js/js_641a0481f6ab043b94872b1493636177.js | 200 OK Content-Length: 300812 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){var l=this,g,y=l.jQuery,p=l.$,o=l.jQuery=l.$=function(E,F){return new o.fn.init(E,F)},D=/^[^<]*(<(.|\s)+>)[^>]*$|^#([\w-]+)$/,f=/^.[^:#\[\.,]*$/;o.fn=o.prototype={init:function(E,H){E=E||document;if(E.nodeType){this[0]=E;this.length=1;this.context=E;return this}if(typeof E==="string"){var G=D.exec(E);if(G&&(G[1]||!H)){if(G[1]){E=o.clean([G[1]],H)}else{var I=document.getElementById(G[3]);if(I&&I.id!=G[3]){return o().find(E)}var F=o(I||[]);F.context=document tl=term.length; if (match<0) { markup.push(escapeMarkup(text)); return; } markup.push(escapeMarkup(text.substring(0, match))); markup.push("<span class='select2-match'>"); markup.push(escapeMarkup(text.substring(match, match + tl))); markup.push("</span>"); markup.push(escapeMarkup(text.substring(match + tl, text.length))); } Antivirus reports:
| ||
http://united-capital-of-philadelphia.unitedcp.com/news | 200 OK Content-Length: 18153 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/sites/default/files/js/js_bb276e587288411ee31a80ed7cff5ee8.js | 200 OK Content-Length: 300812 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){var l=this,g,y=l.jQuery,p=l.$,o=l.jQuery=l.$=function(E,F){return new o.fn.init(E,F)},D=/^[^<]*(<(.|\s)+>)[^>]*$|^#([\w-]+)$/,f=/^.[^:#\[\.,]*$/;o.fn=o.prototype={init:function(E,H){E=E||document;if(E.nodeType){this[0]=E;this.length=1;this.context=E;return this}if(typeof E==="string"){var G=D.exec(E);if(G&&(G[1]||!H)){if(G[1]){E=o.clean([G[1]],H)}else{var I=document.getElementById(G[3]);if(I&&I.id!=G[3]){return o().find(E)}var F=o(I||[]);F.context=document el = $(el)[0]; var offset = 0; var length = 0; if ('selectionStart' in el) { offset = el.selectionStart; length = el.selectionEnd - offset; } else if ('selection' in document) { el.focus(); var sel = document.selection.createRange(); length = document.selection.createRange().text.length; sel.moveStart('character', -el.v Antivirus reports:
| ||
http://united-capital-of-philadelphia.unitedcp.com/contact | 200 OK Content-Length: 14632 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/client-links | 200 OK Content-Length: 12766 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/honest-conversations | 403 Forbidden Content-Length: 9008 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/what-we-do | 200 OK Content-Length: 18325 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/sites/all/themes/ucp_rd/js/Flowchart_Banner_edgePreload.js | 200 OK Content-Length: 18466 Content-Type: text/javascript | clean |
http://united-capital-of-philadelphia.unitedcp.com/about-us | 200 OK Content-Length: 18751 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/personnel | 200 OK Content-Length: 27091 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/signature-services | 200 OK Content-Length: 14078 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/event | 200 OK Content-Length: 12427 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/outreach | 200 OK Content-Length: 14171 Content-Type: text/html | clean |
http://united-capital-of-philadelphia.unitedcp.com/disclosures | 200 OK Content-Length: 11270 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: united-capital-of-philadelphia.unitedcp.com
Result:
HTTP/1.1 200 OK
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Fri, 03 Oct 2014 21:14:49 GMT
Server: Apache/2.2.25 (Amazon)
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Fri, 03 Oct 2014 21:14:50 GMT
Set-Cookie: SESS832a2d7e1bdefd53fe857533dcf9ff95=5hqn2kn5jsnlsg4a62m51qv1p1; expires=Mon, 27-Oct-2014 00:48:10 GMT; path=/; domain=.unitedcp.com
X-Powered-By: PHP/5.3.27
GET / HTTP/1.1
Host: united-capital-of-philadelphia.unitedcp.com
Result:
HTTP/1.1 200 OK
Cache-Control: store, no-cache, must-revalidate
Cache-Control: post-check=0, pre-check=0
Connection: close
Date: Fri, 03 Oct 2014 21:14:49 GMT
Server: Apache/2.2.25 (Amazon)
Vary: Accept-Encoding,User-Agent
Content-Type: text/html; charset=utf-8
Expires: Sun, 19 Nov 1978 05:00:00 GMT
Last-Modified: Fri, 03 Oct 2014 21:14:50 GMT
Set-Cookie: SESS832a2d7e1bdefd53fe857533dcf9ff95=5hqn2kn5jsnlsg4a62m51qv1p1; expires=Mon, 27-Oct-2014 00:48:10 GMT; path=/; domain=.unitedcp.com
X-Powered-By: PHP/5.3.27
Second query (visit from search engine):
GET / HTTP/1.1
Host: united-capital-of-philadelphia.unitedcp.com
Referer: http://www.google.com/search?q=united-capital-of-philadelphia.unitedcp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: united-capital-of-philadelphia.unitedcp.com
Referer: http://www.google.com/search?q=united-capital-of-philadelphia.unitedcp.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=united-capital-of-philadelphia.unitedcp.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://united-capital-of-philadelphia.unitedcp.com/
Result: united-capital-of-philadelphia.unitedcp.com is not infected or malware details are not published yet.
Result: united-capital-of-philadelphia.unitedcp.com is not infected or malware details are not published yet.