Scanned pages/files
Request | Server response | Status |
http://webservicios.cl/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Tue, 17 Mar 2015 02:47:58 GMT Location: http://www.webservicios.cl/ Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 X-Pingback: http://www.webservicios.cl/xmlrpc.php X-Powered-By: PHP/5.4.27 | clean |
http://www.webservicios.cl/ | 200 OK Content-Length: 15696 Content-Type: text/html | clean |
http://www.webservicios.cl/wp-content/themes/webservicios_V8/jquery.js?ver=3.9.3 | 200 OK Content-Length: 92629 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/plugins/jquery-image-lazy-loading/js/jquery.lazyload.min.js?ver=1.7.1 | 200 OK Content-Length: 3202 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/themes/webservicios_V8/jquery-migrate-1.1.1.js?ver=3.9.3 | 200 OK Content-Length: 16174 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) (function( jQuery, window, undefined ) { var warnedAbout = {}; jQuery.migrateWarnings = []; jQuery.migrateMute = true; if ( !jQuery.migrateMute && window.console && console.log ) { console.log("JQMIGRATE: Logging is active"); } if ( jQuery.migrateTrace === undefined ) { jQuery.migrateTrace = true; } jQuery.migrateReset = function() { warnedAbout = {}; jQuery.migrateWarnings.length = 0; }; function migrateWarn( msg) { jQuery.event.add( document, name + "." + jQuery.guid, function() { jQuery.event.trigger( name, null, elem, true ); }); jQuery._data( this, name, jQuery.guid++ ); } return false; }, teardown: function() { if ( this !== document ) { jQuery.event.remove( document, name + "." + jQuery._data( this, name ) ); } return false; } }; } ); })( jQuery, window ); Antivirus reports:
| ||
http://www.webservicios.cl/wp-content/themes/webservicios_V8/script.js?ver=3.9.3 | 200 OK Content-Length: 53373 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/themes/webservicios_V8/script.responsive.js?ver=3.9.3 | 200 OK Content-Length: 18394 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/plugins/anunciosdesplegables/scripts/swfobject_modified.js | 200 OK Content-Length: 22365 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/plugins/anunciosdesplegables/anunciosdesplegables.js | 200 OK Content-Length: 4280 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-includes/js/comment-reply.min.js?ver=3.9.3 | 200 OK Content-Length: 757 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/plugins/contact-form-7/includes/js/jquery.form.min.js?ver=3.51.0-2014.06.20 | 200 OK Content-Length: 15248 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/plugins/contact-form-7/includes/js/scripts.js?ver=3.9 | 200 OK Content-Length: 9630 Content-Type: application/javascript | clean |
http://www.webservicios.cl/wp-content/plugins/ml-slider/assets/sliders/coinslider/coin-slider.min.js?ver=2.9.1 | 200 OK Content-Length: 8662 Content-Type: application/javascript | clean |
http://webservicios.cl/test404page.js | HTTP/1.1 301 Moved Permanently Cache-Control: no-cache, must-revalidate, max-age=0 Connection: close Date: Tue, 17 Mar 2015 02:48:11 GMT Pragma: no-cache Location: http://www.webservicios.cl/test404page.js Server: Apache Content-Length: 0 Content-Type: text/html; charset=UTF-8 Expires: Wed, 11 Jan 1984 05:00:00 GMT X-Pingback: http://www.webservicios.cl/xmlrpc.php X-Powered-By: PHP/5.4.27 | clean |
http://www.webservicios.cl/test404page.js | 404 Not Found Content-Length: 8513 Content-Type: text/html | clean |
http://www.webservicios.cl/servicios-web/ | 200 OK Content-Length: 9373 Content-Type: text/html | clean |
http://www.webservicios.cl/servicios-web/actualizacion-de-contenidos/ | 200 OK Content-Length: 16535 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: webservicios.cl
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 17 Mar 2015 02:47:58 GMT
Location: http://www.webservicios.cl/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.webservicios.cl/xmlrpc.php
X-Powered-By: PHP/5.4.27
...0 bytes of data.
GET / HTTP/1.1
Host: webservicios.cl
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Tue, 17 Mar 2015 02:47:58 GMT
Location: http://www.webservicios.cl/
Server: Apache
Content-Length: 0
Content-Type: text/html; charset=UTF-8
X-Pingback: http://www.webservicios.cl/xmlrpc.php
X-Powered-By: PHP/5.4.27
...0 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: webservicios.cl
Referer: http://www.google.com/search?q=webservicios.cl
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: webservicios.cl
Referer: http://www.google.com/search?q=webservicios.cl
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=webservicios.cl
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://webservicios.cl/
Result: webservicios.cl is not infected or malware details are not published yet.
Result: webservicios.cl is not infected or malware details are not published yet.