Malicious/Suspicious Redirects
Request | Server response | Status |
URL: http://ventanaalinfinito.ustadistancia.edu.co/ (imitation of visitor from search engine) GET / HTTP/1.1 Host: ventanaalinfinito.ustadistancia.edu.co Referer: http://www.google.com/search?q=redirect+check1 | HTTP/1.1 302 Found Connection: close Date: Tue, 13 May 2014 17:18:51 GMT Location: http://ringostart.osa.pl/ Server: Apache/2.2.3 (CentOS) Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Powered-By: PHP/5.3.3 | malicious |
Scanned pages/files
Request | Server response | Status |
http://ventanaalinfinito.ustadistancia.edu.co/ | 200 OK Content-Length: 26123 Content-Type: text/html | clean |
http://ventanaalinfinito.ustadistancia.edu.co/media/system/js/caption.js | 200 OK Content-Length: 1963 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/plugins/content/highslide/highslide-full.js | 200 OK Content-Length: 70750 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/plugins/content/highslide/easing_equations.js | 200 OK Content-Length: 9387 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/plugins/content/highslide/swfobject.js | 200 OK Content-Length: 6880 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/hsconfig/js/highslide-sitesettings.js | 200 OK Content-Length: 2654 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/modules/mod_ariyuimenu/mod_ariyuimenu/js/yui.combo.js | 200 OK Content-Length: 136091 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) if(typeof YAHOO=="undefined"||!YAHOO){var YAHOO={};}YAHOO.namespace=function(){var A=arguments,E=null,C,B,D;for(C=0;C<A.length;C=C+1){D=(""+A[C]).split(".");E=YAHOO;for(B=(D[0]=="YAHOO")?1:0;B<D.length;B=B+1){E[D[B]]=E[D[B]]||{};E=E[D[B]];}}return E;};YAHOO.log=function(D,A,C){var B=YAHOO.widget.Logger;if(B&&B.log){return B.log(D,A,C);}else{return false;}};YAHOO.register=function(A,E,D){var I=YAHOO.env.modules,B,H,G,F,C;if(!I[A]){I[A]={versions:[],builds:[]};}B=I[A];H=D.version;G=D Antivirus reports:
| ||
http://ventanaalinfinito.ustadistancia.edu.co/plugins/system/plg_japopup/fancybox/js/jquery-1.3.2.min.js | 200 OK Content-Length: 57254 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/plugins/system/plg_japopup/fancybox/js/jquery.easing.1.3.js | 200 OK Content-Length: 8097 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/plugins/system/plg_japopup/fancybox/js/jquery.fancybox-1.2.1.js | 200 OK Content-Length: 15371 Content-Type: application/x-javascript | clean |
http://ventanaalinfinito.ustadistancia.edu.co/index.php?lang=es | 200 OK Content-Length: 26131 Content-Type: text/html | clean |
http://ventanaalinfinito.ustadistancia.edu.co/index.php?lang=en | 200 OK Content-Length: 26626 Content-Type: text/html | clean |
http://ventanaalinfinito.ustadistancia.edu.co/index.php?option=com_content&view=frontpage&Itemid=1&lang=en | 200 OK Content-Length: 26747 Content-Type: text/html | clean |
http://ventanaalinfinito.ustadistancia.edu.co/index.php?option=com_content&view=frontpage&Itemid=1&lang=es | 200 OK Content-Length: 26247 Content-Type: text/html | clean |
http://ventanaalinfinito.ustadistancia.edu.co/index.php?option=com_content&view=article&id=27&Itemid=89&lang=es | 200 OK Content-Length: 24356 Content-Type: text/html | clean |
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=ventanaalinfinito.ustadistancia.edu.co
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://ventanaalinfinito.ustadistancia.edu.co/
Result: ventanaalinfinito.ustadistancia.edu.co is not infected or malware details are not published yet.
Result: ventanaalinfinito.ustadistancia.edu.co is not infected or malware details are not published yet.