Scanned pages/files
Request | Server response | Status |
http://wyattjohnsonsubaru.com/ | HTTP/1.1 301 Moved Permanently Connection: close Connection: close Date: Tue, 11 Aug 2015 09:08:13 GMT Location: http://www.wyattjohnsonsubaru.com/ Server: Apache-Coyote/1.1 X-DDC-Arch-Trace: ,HttpResponse | clean |
http://www.wyattjohnsonsubaru.com/ | 200 OK Content-Length: 101139 Content-Type: text/html | malicious |
Malicious code - confirmed by antiviruses (see below) var axel = Math.random() + ""; var a = axel * 10000000000000; document.write('<iframe src="//fls.doubleclick.net/activityi;src=2550321;type=g1084305;cat=g1084331;ord=' + a + '?" width="1" height="1" frameborder="0" style="display:none"></iframe>'); Antivirus reports:
| ||
http://www.wyattjohnsonsubaru.com//static.dealer.com/v9/media/js/newrelic/newrelic.js?1433428392000/ | 404 Not Found Content-Length: 339 Content-Type: text/html | clean |
http://www.wyattjohnsonsubaru.com/test404page.js | 404 Not Found Content-Length: 303 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//static.dealer.com/v9/media/js/modernizr/v2.6.2/modernizr-2.6.2.min.js?1350965558000/ | 404 Not Found Content-Length: 354 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//cc2.dealer.com/off-platform/pxa.min.js/ | HTTP/1.1 301 Moved Permanently Connection: close Connection: close Date: Tue, 11 Aug 2015 09:08:16 GMT Location: http://www.wyattjohnsonsubaru.com//cc2.dealer.com/off-platform/pxa.min.js/ Server: Apache-Coyote/1.1 X-DDC-Arch-Trace: ,HttpResponse | clean |
http://www.wyattjohnsonsubaru.com//cc2.dealer.com/off-platform/pxa.min.js/ | 404 Not Found Content-Length: 56430 Content-Type: text/html | clean |
http://www.wyattjohnsonsubaru.com//static.dealer.com/v9/media/js/modernizr/v2.6.2/modernizr-2.6.2.min.js?1350965558000/ | 404 Not Found Content-Length: 358 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//cc2.dealer.com/off-platform/pixall.min.js/ | HTTP/1.1 301 Moved Permanently Connection: close Connection: close Date: Tue, 11 Aug 2015 09:08:18 GMT Location: http://www.wyattjohnsonsubaru.com//cc2.dealer.com/off-platform/pixall.min.js/ Server: Apache-Coyote/1.1 X-DDC-Arch-Trace: ,HttpResponse | clean |
http://www.wyattjohnsonsubaru.com//cc2.dealer.com/off-platform/pixall.min.js/ | 404 Not Found Content-Length: 56433 Content-Type: text/html | clean |
http://www.wyattjohnsonsubaru.com//static.dealer.com/dist/v9/media/js/ddc/v1/dist/ddc.jquery.min.js?1439229452000/ | 404 Not Found Content-Length: 353 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//static.dealer.com/dist/v9/media/js/ddc/v1/dist/ddc.min.js?1439229456000/ | 404 Not Found Content-Length: 342 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//static.dealer.com/dist/v9/widgets/links/list/v1/js/widget.min.js?1439229469000/ | 404 Not Found Content-Length: 349 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//static.dealer.com/dist/v9/media/js/bootstrap/v3.0/dropdown.min.js?1439229438000/ | 404 Not Found Content-Length: 350 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//static.dealer.com/dist/v9/widgets/navigation/default/v1/js/widget.min.js?1439229469000/ | 404 Not Found Content-Length: 357 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//static.dealer.com/dist/v9/widgets/mycars/default/v1/js/widget.min.js?1439229469000/ | 404 Not Found Content-Length: 353 Content-Type: text/html | clean |
http://wyattjohnsonsubaru.com//static.dealer.com/dist/v9/media/js/jquerytimeago/0.11.4/jquery.timeago.min.js?1439229438000/ | 404 Not Found Content-Length: 362 Content-Type: text/html | clean |
https://ssl.google-analytics.com/ga.js | 200 OK Content-Length: 41100 Content-Type: text/javascript | clean |
Malicious Redirects
First query (normal visit):
GET / HTTP/1.1
Host: wyattjohnsonsubaru.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Connection: close
Date: Tue, 11 Aug 2015 09:08:13 GMT
Location: http://www.wyattjohnsonsubaru.com/
Server: Apache-Coyote/1.1
X-DDC-Arch-Trace: ,HttpResponse
GET / HTTP/1.1
Host: wyattjohnsonsubaru.com
Result:
HTTP/1.1 301 Moved Permanently
Connection: close
Connection: close
Date: Tue, 11 Aug 2015 09:08:13 GMT
Location: http://www.wyattjohnsonsubaru.com/
Server: Apache-Coyote/1.1
X-DDC-Arch-Trace: ,HttpResponse
Second query (visit from search engine):
GET / HTTP/1.1
Host: wyattjohnsonsubaru.com
Referer: http://www.google.com/search?q=wyattjohnsonsubaru.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
GET / HTTP/1.1
Host: wyattjohnsonsubaru.com
Referer: http://www.google.com/search?q=wyattjohnsonsubaru.com
Result:
The result is similar to the first query. There are no suspicious redirects found.
Safe Browsing / Blacklists
Query: http://www.google.com/safebrowsing/diagnostic?site=wyattjohnsonsubaru.com
Result: This site is not currently listed as suspicious.
Result: This site is not currently listed as suspicious.
Query: http://yandex.com/infected?l10n=en&url=http://wyattjohnsonsubaru.com/
Result: wyattjohnsonsubaru.com is not infected or malware details are not published yet.
Result: wyattjohnsonsubaru.com is not infected or malware details are not published yet.