Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=westcomlending.com
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Result: The website is marked by Google as suspicious. - visiting this web site may harm your computer.
Details are available here.
Scanned pages/files
| Request | Server response | Status |
http://westcomlending.com/ | HTTP/1.1 200 OK Connection: close Date: Fri, 26 Sep 2014 21:30:31 GMT Accept-Ranges: bytes ETag: "61f02d-b6e-48fc39bbb9840" Server: Apache/2.2.22 (Unix) FrontPage/5.0.2.2635 Content-Length: 2926 Content-Type: text/html Last-Modified: Wed, 08 Sep 2010 18:23:21 GMT | clean |
http://westcomlending.com/index2.html | 200 OK Content-Length: 14016 Content-Type: text/html | clean |
http://westcomlending.com/./include/url.js | 404 Not Found Content-Length: 575 Content-Type: text/html | clean |
http://westcomlending.com/test404page.js | 404 Not Found Content-Length: 575 Content-Type: text/html | clean |
http://westcomlending.com/./include/swfobject.js | 404 Not Found Content-Length: 575 Content-Type: text/html | clean |
http://westcomlending.com/./include/sitetree.js | 200 OK Content-Length: 17660 Content-Type: application/javascript | malicious |
Malicious code - confirmed by antiviruses (see below) if (typeof(decodeURIComponent) == 'undefined') { decodeURIComponent = function(s) { return unescape(s); } } function jdecode(s) { s = s.replace(/\+/g, "%20") return decodeURIComponent(s); } var POS_NODENAME=0; var POS_ID=1; var POS_NAME=2; var POS_NAVIGATIONTEXT=3; var POS_HREF=4; var POS_ISNAVIGATION=5; var POS_CHILDS=6; var POS_TEMPLATENAME=7; var POS_TARGET=8; ...[4148 bytes skipped]... Antivirus reports:
| ||
http://from-aqp.com/cgi-bin/productos.php | 500 Can't connect to from-aqp.com:80 (Bad hostname) Content-Length: 156 Content-Type: text/plain | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: westcomlending.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Sep 2014 21:30:31 GMT
Accept-Ranges: bytes
ETag: "61f02d-b6e-48fc39bbb9840"
Server: Apache/2.2.22 (Unix) FrontPage/5.0.2.2635
Content-Length: 2926
Content-Type: text/html
Last-Modified: Wed, 08 Sep 2010 18:23:21 GMT
...2926 bytes of data.
GET / HTTP/1.1
Host: westcomlending.com
Result:
HTTP/1.1 200 OK
Connection: close
Date: Fri, 26 Sep 2014 21:30:31 GMT
Accept-Ranges: bytes
ETag: "61f02d-b6e-48fc39bbb9840"
Server: Apache/2.2.22 (Unix) FrontPage/5.0.2.2635
Content-Length: 2926
Content-Type: text/html
Last-Modified: Wed, 08 Sep 2010 18:23:21 GMT
...2926 bytes of data.
Second query (visit from search engine):
GET / HTTP/1.1
Host: westcomlending.com
Referer: http://www.google.com/search?q=westcomlending.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: westcomlending.com
Referer: http://www.google.com/search?q=westcomlending.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
