Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=websiteworth.biz
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://websiteworth.biz/
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Yandex as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
Request | Server response | Status |
http://websiteworth.biz/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 10 Oct 2014 22:18:44 GMT Location: http://www.websiteworth.biz/ Server: Apache Vary: Accept-Encoding Content-Length: 236 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.websiteworth.biz/ | 200 OK Content-Length: 17619 Content-Type: text/html | clean |
https://ajax.googleapis.com/ajax/libs/jquery/1.9.0/jquery.min.js | 200 OK Content-Length: 93068 Content-Type: text/javascript | clean |
http://websiteworth.biz/templates/common_assets/js/bootstrap.min.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 10 Oct 2014 22:18:51 GMT Location: http://www.websiteworth.biz/templates/common_assets/js/bootstrap.min.js Server: Apache Vary: Accept-Encoding Content-Length: 279 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.websiteworth.biz/templates/common_assets/js/bootstrap.min.js | 200 OK Content-Length: 28631 Content-Type: application/javascript | clean |
http://websiteworth.biz/templates/default/assets/js/app.js | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 10 Oct 2014 22:18:53 GMT Location: http://www.websiteworth.biz/templates/default/assets/js/app.js Server: Apache Vary: Accept-Encoding Content-Length: 270 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.websiteworth.biz/templates/default/assets/js/app.js | 200 OK Content-Length: 648 Content-Type: application/javascript | clean |
http://adhitzads.com/671382 | 200 OK Content-Length: 452 Content-Type: application/x-javascript | clean |
http://websiteworth.biz//s7.addthis.com/js/300/addthis_widget.js/ | HTTP/1.1 301 Moved Permanently Connection: close Date: Fri, 10 Oct 2014 22:18:54 GMT Location: http://www.websiteworth.biz/s7.addthis.com/js/300/addthis_widget.js/ Server: Apache Vary: Accept-Encoding Content-Length: 276 Content-Type: text/html; charset=iso-8859-1 | clean |
http://www.websiteworth.biz/s7.addthis.com/js/300/addthis_widget.js/ | 404 Not Found Content-Length: 16831 Content-Type: text/html | clean |
http://www.websiteworth.biz//s7.addthis.com/js/300/addthis_widget.js/ | 404 Not Found Content-Length: 16831 Content-Type: text/html | clean |
http://www.websiteworth.biz/www/google.com | 200 OK Content-Length: 41554 Content-Type: text/html | clean |
http://www.websiteworth.biz/widget.php?type=stats&domain=google.com | 200 OK Content-Length: 1439 Content-Type: application/x-javascript | clean |
http://www.websiteworth.biz/widget.php?type=worth&domain=google.com | 200 OK Content-Length: 551 Content-Type: application/x-javascript | malicious |
Malicious code - confirmed by antiviruses (see below) document.write("<div style='width: 85px; height: 29px; display: inherit;'><a href='http://www.websiteworth.biz/www/google.com' target='_blank'><img style='vertical-align: middle; position: static;' src='http://www.websiteworth.biz/templates/default/assets/img/websiteworth.png' border='0' alt='google.com website worth'></a>"); document.write("<div style='text-align: right; font: 8px Verdana, sans-serif; color: #FFFFFF; margin-top: -8px; margin-right: 4px; line-height: 0;'>$8,729,145,083.52</div>"); document.write("</div>"); Antivirus reports:
| ||
http://www.websiteworth.biz/widget.php?type=pr&domain=google.com | 200 OK Content-Length: 201 Content-Type: application/x-javascript | clean |
http://maps.googleapis.com/maps/api/js?key=AIzaSyCbhg8zccUMeq_O2NoImEp6vixcdOP7HSI&sensor=false | 200 OK Content-Length: 5070 Content-Type: text/javascript | clean |
http://google-maps-utility-library-v3.googlecode.com/svn/tags/infobox/1.1.12/src/infobox.js | 200 OK Content-Length: 22948 Content-Type: text/javascript | clean |
https://www.google.com/jsapi | 200 OK Content-Length: 24553 Content-Type: text/javascript | clean |
http://www.websiteworth.biz/templates/default/assets/js/jquery.raty.min.js | 200 OK Content-Length: 8273 Content-Type: application/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: websiteworth.biz
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 10 Oct 2014 22:18:44 GMT
Location: http://www.websiteworth.biz/
Server: Apache
Vary: Accept-Encoding
Content-Length: 236
Content-Type: text/html; charset=iso-8859-1
...236 bytes of data.
GET / HTTP/1.1
Host: websiteworth.biz
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Date: Fri, 10 Oct 2014 22:18:44 GMT
Location: http://www.websiteworth.biz/
Server: Apache
Vary: Accept-Encoding
Content-Length: 236
Content-Type: text/html; charset=iso-8859-1
...236 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: websiteworth.biz
Referer: http://www.google.com/search?q=websiteworth.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: websiteworth.biz
Referer: http://www.google.com/search?q=websiteworth.biz
Result:
The result is similar to the first query. There are no suspicious redirects found.